Fortinet white logo
Fortinet white logo
8.0.3

API Security

API Security

FortiADC provides comprehensive API security and management through Schema Validation, API Gateway, and API Discovery. It combines validation, control, and visibility to secure APIs end-to-end.

  • Schema Validation

    • Supports JSON, XML, and OpenAPI schema validation

    • Enforces strict request/response structure and data types

    • Detects malformed requests, missing fields, and parameter abuse

    • Helps prevent injection, data leakage, and unauthorized access

  • API Gateway

    • Controls API access, routing, and policy enforcement

    • Supports authentication, authorization, and rate limiting

    • Manages API users, keys, and traffic rules

    • Enables centralized control of API traffic across applications

  • API Discovery

    • Automatically identifies and maps API endpoints

    • Builds an inventory of APIs and their usage patterns

    • Provides visibility into unknown or shadow APIs

    • Helps baseline normal behavior for security monitoring

For more information, see API Protection in FortiADC Administration Guide.

API Security

API Security

FortiADC provides comprehensive API security and management through Schema Validation, API Gateway, and API Discovery. It combines validation, control, and visibility to secure APIs end-to-end.

  • Schema Validation

    • Supports JSON, XML, and OpenAPI schema validation

    • Enforces strict request/response structure and data types

    • Detects malformed requests, missing fields, and parameter abuse

    • Helps prevent injection, data leakage, and unauthorized access

  • API Gateway

    • Controls API access, routing, and policy enforcement

    • Supports authentication, authorization, and rate limiting

    • Manages API users, keys, and traffic rules

    • Enables centralized control of API traffic across applications

  • API Discovery

    • Automatically identifies and maps API endpoints

    • Builds an inventory of APIs and their usage patterns

    • Provides visibility into unknown or shadow APIs

    • Helps baseline normal behavior for security monitoring

For more information, see API Protection in FortiADC Administration Guide.