Escape Beta API
Beta These endpoints are in beta and are subject to change.
Beta These endpoints are in beta and are subject to change.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/escape-beta-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
version: 3.0.0
title: Escape Public Asm Beta API
description: 'This API enables you to operate [Escape](https://escape.tech/) programmatically.
All requests must be authenticated with a valid API key, provided in the `X-ESCAPE-API-KEY` header.
For example: `X-ESCAPE-API-KEY: YOUR_API_KEY`.
You can find your API key in the [Escape dashboard](https://app.escape.tech/user/).'
servers:
- url: https://public.escape.tech/v3
security:
- apiKey: []
tags:
- name: Beta
description: 'Beta
These endpoints are in beta and are subject to change.'
paths:
/profiles/ai-pentesting/rest:
post:
tags:
- Beta
summary: Create an Automated Pentest REST profile
operationId: createPentestRestProfile
description: Create an Automated Pentest REST profile.
requestBody:
description: Body of the request to create an asset
content:
application/json:
schema:
type: object
properties:
assetId:
type: string
format: uuid
description: The asset ID for the profile
example: 00000000-0000-0000-0000-000000000000
configuration:
type: string
description: The scan configuration encoded as a JSON string (legacy public API contract).
examples:
- '{"authentication":{"users":[{"name":"public"}]}}'
- '{"mode":"read_only"}'
example: '{"authentication":{"users":[{"name":"public"}]}}'
configurationObject:
type: object
properties:
public_location_ids:
type:
- array
- 'null'
items:
type: string
private_location_ids:
type:
- array
- 'null'
items:
type: string
scope:
type:
- object
- 'null'
properties:
use_defaults:
type:
- boolean
- 'null'
allowlist:
type:
- array
- 'null'
items:
oneOf:
- type: object
properties:
type:
type: string
enum:
- domain
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
required:
- type
- value
- type: object
properties:
type:
type: string
enum:
- ip
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
required:
- type
- value
- type: object
properties:
type:
type: string
enum:
- web_page_url
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
required:
- type
- value
- type: object
properties:
type:
type: string
enum:
- rest_api_path
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
method:
type:
- string
- 'null'
enum:
- CONNECT
- DELETE
- GET
- HEAD
- OPTIONS
- PATCH
- POST
- PUT
- TRACE
- null
domain:
type:
- string
- 'null'
required:
- type
- value
- type: object
properties:
type:
type: string
enum:
- rest_api_url
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
method:
type:
- string
- 'null'
enum:
- CONNECT
- DELETE
- GET
- HEAD
- OPTIONS
- PATCH
- POST
- PUT
- TRACE
- null
required:
- type
- value
- type: object
properties:
type:
type: string
enum:
- graphql_operation
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
required:
- type
- value
- type: object
properties:
type:
type: string
enum:
- web_page_element_selector
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
required:
- type
- value
blocklist:
type:
- array
- 'null'
items:
oneOf:
- type: object
properties:
type:
type: string
enum:
- domain
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
required:
- type
- value
- type: object
properties:
type:
type: string
enum:
- ip
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
required:
- type
- value
- type: object
properties:
type:
type: string
enum:
- web_page_url
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
required:
- type
- value
- type: object
properties:
type:
type: string
enum:
- rest_api_path
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
method:
type:
- string
- 'null'
enum:
- CONNECT
- DELETE
- GET
- HEAD
- OPTIONS
- PATCH
- POST
- PUT
- TRACE
- null
domain:
type:
- string
- 'null'
required:
- type
- value
- type: object
properties:
type:
type: string
enum:
- rest_api_url
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
method:
type:
- string
- 'null'
enum:
- CONNECT
- DELETE
- GET
- HEAD
- OPTIONS
- PATCH
- POST
- PUT
- TRACE
- null
required:
- type
- value
- type: object
properties:
type:
type: string
enum:
- graphql_operation
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
required:
- type
- value
- type: object
properties:
type:
type: string
enum:
- web_page_element_selector
value:
type: string
operation:
type:
- string
- 'null'
enum:
- equals
- starts_with
- ends_with
- contains
- regex
- wildcard
- null
required:
- type
- value
exploration_scope:
type:
- array
- 'null'
items:
type: string
api_custom_rule_ids:
type:
- array
- 'null'
items:
type: string
frontend_custom_rule_ids:
type:
- array
- 'null'
items:
type: string
mode:
type:
- string
- 'null'
enum:
- read_only
- read_write
- null
authentication:
type:
- object
- 'null'
properties:
$schema:
type: string
lifetime:
type:
- number
- 'null'
procedures:
type: array
items:
type: object
properties:
name:
type: string
operations:
type: array
items:
oneOf:
- type: object
properties:
tech:
type: string
enum:
- http
parameters:
type: object
properties:
proxy_override:
type:
- string
- 'null'
url:
type: string
method:
type: string
enum:
- CONNECT
- DELETE
- GET
- HEAD
- OPTIONS
- PATCH
- POST
- PUT
- TRACE
headers:
type: array
items:
type: object
properties:
name:
type: string
values:
type: array
items:
type: string
required:
- name
- values
cookies:
type: array
items:
type: object
properties:
name:
type: string
domain:
type:
- string
- 'null'
path:
type:
- string
- 'null'
http_only:
type:
- boolean
- 'null'
secure:
type:
- boolean
- 'null'
same_site:
type:
- string
- 'null'
enum:
- Strict
- Lax
- None
- null
values:
type: array
items:
type: string
required:
- name
- values
queryParameters:
type: array
items:
type: object
properties:
name:
type: string
values:
type: array
items:
type: string
required:
- name
- values
body: {}
timeout:
type: number
insecure:
type: boolean
follow_redirects:
type: number
required:
- url
- method
- headers
- cookies
- queryParameters
extractions:
type: array
items:
type: object
properties:
location:
type: string
enum:
- header
- cookie
- body
- query
key:
type: string
regex:
type: string
name:
type: string
required:
- location
- key
- name
required:
- tech
- parameters
- extractions
- type: object
properties:
tech:
type: string
enum:
- oauth_authz_code_browser
parameters:
type: object
properties:
proxy_override:
type:
- string
- 'null'
login_url:
type: string
auto_extraction_urls:
type:
- array
- 'null'
items:
type: string
logged_in_detector_text:
type:
- string
- 'null'
logged_in_detector_timeout:
type:
- number
- 'null'
stealth_mode:
type:
- boolean
- 'null'
logout_detection:
type:
- object
- 'null'
properties:
enabled:
type:
- boolean
- 'null'
instructions:
type:
- string
- 'null'
authorization_url:
type: string
token_url:
type: string
redirect_uri:
type: string
client_id:
type: string
client_secret:
type: string
use_pkce:
type: boolean
login_timeout:
type: number
required:
- login_url
- authorization_url
- token_url
- redirect_uri
- client_id
- client_secret
- use_pkce
- login_timeout
extractions:
anyOf:
- type: array
items:
type: object
properties:
location:
type: string
enum:
- header
- cookie
- body
- query
# --- truncated at 32 KB (2978 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/escape/refs/heads/main/openapi/escape-beta-api-openapi.yml