APIClarity
APIClarity is an open source (Apache-2.0) API security and observability tool that captures API traffic in a Kubernetes environment, reconstructs OpenAPI specifications from what it observes, and detects shadow APIs, zombie APIs, specification drift and broken function-level authorization. It integrates with Istio, Kong, Tyk, Kuma, a tap DaemonSet and an OpenTelemetry Collector as traffic sources, and ships as a Helm chart you deploy into your own cluster — there is no hosted service, no vendor account and no vendor API host. It was part of the OpenClarity project. APIClarity has reached end of life: the source repository was archived read-only by its owner on 2026-05-29, the last release was v0.14.5 on 2023-05-05, and both project websites (openclarity.io and apiclarity.io) now return HTTP 404. The source, the eleven published specifications, the Helm chart repository and the container images all remain publicly readable, which is what this profile is built from.
APIClarity publishes 11 APIs on the APIs.io network, including API Events API, API Inventory API, Control API, and 8 more. Tagged areas include API Observability, API Security, API Traffic Analysis, Cisco, and Kubernetes.
The APIClarity catalog on APIs.io includes 1 event-driven AsyncAPI specification.
APIClarity’s developer surface includes changelog, sandbox, getting-started guide, API reference, support, authentication, documentation, and 22 more developer resources.
Kin Score
APIs 11
Individual APIs this provider publishes, each with its own machine-readable definition.
APIClarity API Events API
Captured API traffic events.
APIClarity API Inventory API
Discovered APIs and their reconstructed specifications.
APIClarity Control API
Control-plane endpoints for trace sources and discovered APIs.
APIClarity Features API
Enabled features in the deployment.
APIClarity BFLA Module API
Broken Function Level Authorization detection. Learns an authorization model from observed API interactions — which callers are supposed to invoke which operations — then flags ...
APIClarity Fuzzer Module API
Active security testing. Drives generated traffic at an API based on its specification to find implementation flaws, then returns a severity-ranked report and a specification an...
APIClarity Trace Analyzer Module API
Analyzes the path, headers and body of observed requests and responses for weak authentication, exposure of sensitive information and potential broken object level authorization...
APIClarity Spec Differ Module API
Compares observed API traces against the provided or reconstructed specification to surface shadow APIs (observed but undocumented), zombie APIs (observed but marked deprecated)...
APIClarity Spec Reconstructor Module API
Controls reconstruction of an OpenAPI specification from live traffic for a discovered API. Served under /api/modules/specreconstructor.
APIClarity Plugins Telemetry API
The Swagger 2.0 contract every APIClarity traffic-source plugin implements to push captured traffic into a deployment — POST /telemetry, GET /hostsToTrace and POST /control/newD...
APIClarity Notifications API
An inverted contract — the endpoint a registered listener must implement, which APIClarity POSTs to. Six notification types share one polymorphic envelope discriminated on notif...
Scroll for all 11
Open Collections 6
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
API Collection
OPEN COLLECTIONAPIClarity API Events API
OPEN COLLECTIONAPIClarity API Events API Inventory API
OPEN COLLECTIONAPIClarity API Events Control API
OPEN COLLECTIONAPIClarity API Events Features API
OPEN COLLECTIONAPIClarity API
OPEN COLLECTIONPricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Apiclarity Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Apiclarity Finops
FINOPSFeatures 7
Notable capabilities this provider offers.
OpenAPI Spec Reconstruction
Automatically reconstruct OpenAPI specifications from observed live API traffic without code instrumentation.
Shadow API Detection
Identify undocumented shadow APIs being called in production that are not reflected in official specifications.
Zombie API Detection
Detect deprecated or decommissioned API endpoints still receiving traffic in production.
API Diff Analysis
Compare observed API behavior against documented specifications to identify drifts, changes, and violations.
API Security Alerts
Generate security findings and alerts based on API traffic analysis and specification violations.
Kubernetes Integration
Deploy as a sidecar or via Helm charts for integration with Kubernetes service meshes and API gateways.
API Inventory
Automatically build and maintain an inventory of all APIs discovered in the environment.
Scroll for all 7
Event Specifications 1
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Security Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 5
What developers build with this provider.
API Discovery
Discover all APIs running in a Kubernetes environment including undocumented and shadow APIs.
API Security Posture Assessment
Assess API security by detecting shadow APIs, spec violations, and suspicious traffic patterns.
API Specification Generation
Generate OpenAPI specifications from live traffic for APIs that lack formal documentation.
API Governance
Enforce API consistency by detecting deviations between actual API behavior and official specifications.
Incident Response
Investigate API security incidents using traffic analysis, API inventory, and spec diff data.
Resources
Get Started 2
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 4
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 6
Pagination, idempotency, versioning, errors, and events
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 2
Authentication, authorization, and security posture
Operate 6
Status, limits, changes, and where to get help
Commercial 2
Pricing, plans, and the legal terms of use
Company 1
The organization behind the API
Source (apis.yml)
Work with this as data
Every provider here is available over the APIs.io API and to AI agents over MCP.