dast_api

Last updated: Sep 9, 2026


dast_api is Fluid Attacks' native binary for API security testing. It reads the endpoints from a Postman collection, sends requests and crafted variants of them to your API, and reports the vulnerabilities it finds. Unlike the Docker-based scanners, dast_api is a single self-contained binary that runs without Docker. It authenticates every run, so a scan without a credential is refused.

Installation

Linux and macOS

Run the one-line installer:

curl -fsSL https://public.fluidattacks.com/dast_api/install.sh | sh

This installs the dast_api binary to /usr/local/bin by default.

Verify the installation

dast_api --version

Scan with a configuration file

dast_api scans from a YAML configuration file, which you pass with --config:

dast_api scan --config dast-api-config.yaml

Each entry under dast.api needs the API's base_url and at least one Postman collection in api_specs:

dast:
  api:
    - base_url: https://api.example.com
      api_specs:
        - postman/collection.json

An entry that declares no api_specs stops the scan with an error, rather than reporting a target it never probed.

Authenticate

dast_api refuses to scan without a credential. Every run is attributed to whoever ran it.

Running it yourself, on your own machine? Sign in through your browser instead — dast_api login once, and nothing to store.

Authenticate with your group's Group token, supplied either way:

  • Long-lived secret: set the INTEGRATES_API_TOKEN environment variable to a Group token from Organization → Groups → GroupName → DevSecOps → Manage token in the platform.
  • Short-lived, via OIDC: from any system that can issue OpenID Connect tokens (CI/CD, AWS, GCP, Kubernetes, and more), pass --group <your-group> and dast_api obtains one per run with no stored secret. On GitHub Actions it is fetched automatically; on any other system, expose it as the INTEGRATES_OIDC_TOKEN environment variable.

INTEGRATES_API_TOKEN takes precedence over both. Where a CI OIDC source is present, --group is required and a browser login is not used.

See Authentication for the full guide (including OIDC federation setup).

The token is used only to identify the caller; it is never printed or written to logs.

Common scenarios

Send credentials to the API under test

The credentials the scanner sends to your API are separate from your Fluid Attacks group token. key is the header name and value is the bare secret. The bearer, oauth1 and oauth2 types add their own prefix, so do not include one. You can read the value from an environment variable:

dast:
  api:
    - base_url: https://api.example.com
      api_specs:
        - postman/collection.json
      authentication:
        - type: bearer
          key: Authorization
          value: ${API_TOKEN}

The accepted types are bearer, apikey, oauth1 and oauth2.

Scan several APIs

dast:
  api:
    - base_url: https://api.example.com
      api_specs:
        - postman/public-api.json
        - postman/admin-api.json
    - base_url: https://payments.example.com
      api_specs:
        - postman/payments.json

Block the pipeline on findings

For pipeline gating with strict mode, see Distributed binaries. dast_api enables it from the configuration file only.

Troubleshooting

For common installation troubleshooting (permission denied, PATH issues), see Distributed binaries.

No output file is produced

With no output.file_path, the report is written to FluidAttacksDastApiResults in the directory you ran the scan from, carrying the extension of the configured format (.sarif by default), so check there before changing the configuration. ALL writes two reports, .csv and .sarif. output.format must be SARIF, CSV or ALL; any other value causes an error.

Environment variable referenced in the scan config is not set

A credential whose whole value is ${API_TOKEN} requires that variable to be exported before the scan; the scanner stops rather than sending an empty credential. A placeholder embedded in longer text is substituted with an empty string instead, and the scan continues.

On this page