See what your AI agents can access. Scan MCP configs for exposed secrets, shadow APIs, and AI models. Generate AI-BOMs for compliance.
-
Updated
Aug 18, 2026 - Python
See what your AI agents can access. Scan MCP configs for exposed secrets, shadow APIs, and AI models. Generate AI-BOMs for compliance.
Know every endpoint and whether you meant to expose it. Static, deterministic, local. Part of Stelnyx.
Zero-dependency Python CLI for authorized REST API inventory, OpenAPI discovery and local documentation export
API inventory from real traffic — no gateway, no database, no servers. Just a Cloudflare Worker and a Google Sheet.
Automatically discover APIs behind NGINX / NGINX Plus from access logs — shadow API detection, live API inventory, and ML anomaly detection. Self-hosted, Docker-ready.
Shadow API discovery from web server logs: finds endpoints that answer but are not in your OpenAPI spec (shadow), and endpoints documented but no longer answering (zombie). Offline, no telemetry, Rust.
To associate your repository with the api-inventory topic, visit your repo's landing page and select "manage topics."