AI-Powered Insights for Every API Scan
Akto AI Overview delivers AI-generated summaries and insights directly in API testing results, speeding up triage.

API Discovery

Body Match Toggle
Control whether request bodies are compared during API endpoint merging. Enable or disable from the Settings page to adjust merge aggressiveness.

AI Powered Inventor Analysis
Get AI-generated analysis of your API collections, including risk distribution, sensitive data exposure, authentication coverage, and actionable security remediation steps.
Security Testing

Active & Inactive Test Tabs
Switch between Active and Inactive tests in separate tabs under Testing > Test Suites for better test lifecycle management and visibility.

Digest Authentication Support
Configure digest auth credentials in test roles with SHA-256 and MD5 algorithm options for comprehensive authentication testing coverage.

Post-Request Scripts
Configure custom JavaScript to execute after each API request in a test run, enabling advanced test automation and response validation workflows.

Webhook Callback Monitoring
Execute tests that trigger webhooks and track callback status in real-time during security testing directly from the test editor.

Multi-Module Testing
Run scans across multiple testing modules simultaneously in a single operation instead of sequential execution.

GitHub Sync for Test Libraries
Sync test libraries directly from GitHub via a Sync button in Settings. Keep your security test libraries up-to-date without waiting for platform releases.
API Threat Protection


Configurable WAF Threat Policies
Configure WAF threat policies during AWS WAF and Cloudflare WAF setup directly from the Integration settings page for tighter security policy control.
Platform

SSO-Only Login Restrictions
Enforce consistent authentication by restricting non-SSO logins for SSO-signed-up users across API and Agentic Security.

Okta Group-to-Role Mapping
Map Okta groups to Akto roles (Admin, Member, Developer, Guest) for automatic RBAC during SSO authentication and streamlined access control.