API Security
FortiADC provides comprehensive API security and management through Schema Validation, API Gateway, and API Discovery. It combines validation, control, and visibility to secure APIs end-to-end.
-
Schema Validation
-
Supports JSON, XML, and OpenAPI schema validation
-
Enforces strict request/response structure and data types
-
Detects malformed requests, missing fields, and parameter abuse
-
Helps prevent injection, data leakage, and unauthorized access
-
-
API Gateway
-
Controls API access, routing, and policy enforcement
-
Supports authentication, authorization, and rate limiting
-
Manages API users, keys, and traffic rules
-
Enables centralized control of API traffic across applications
-
-
API Discovery
-
Automatically identifies and maps API endpoints
-
Builds an inventory of APIs and their usage patterns
-
Provides visibility into unknown or shadow APIs
-
Helps baseline normal behavior for security monitoring
-
For more information, see API Protection in FortiADC Administration Guide.