Fortinet black logo

Handbook

API Discovery

API Discovery

Under the API Protection sub-menu, the API Discovery page contains the features that allow you to protect your application against malicious APIs through discovered API endpoints.

Through API Discovery policies, FortiADC is enabled to automatically discover external API endpoints from HTTP/HTTPS requests and responses that have passed through API validity checks, wherein the API is parsed for information including the Host, Paths, parameters and their schemas from query requests or entity bodies, as well as classify parameters that match PII (Personal Identifiable Information) signatures. API Discovery also supports manually imported OAS files compliant with OpenAPI 3.0 and Swagger 2.0 standard to parse and discover as internal API endpoints that can also be matched by incoming API requests or responses.

This section includes the following:

API Discovery

Under the API Protection sub-menu, the API Discovery page contains the features that allow you to protect your application against malicious APIs through discovered API endpoints.

Through API Discovery policies, FortiADC is enabled to automatically discover external API endpoints from HTTP/HTTPS requests and responses that have passed through API validity checks, wherein the API is parsed for information including the Host, Paths, parameters and their schemas from query requests or entity bodies, as well as classify parameters that match PII (Personal Identifiable Information) signatures. API Discovery also supports manually imported OAS files compliant with OpenAPI 3.0 and Swagger 2.0 standard to parse and discover as internal API endpoints that can also be matched by incoming API requests or responses.

This section includes the following: