dast_api
Last updated: Sep 9, 2026
dast_api is Fluid Attacks' native binary for API security testing.
It reads the endpoints from a Postman collection,
sends requests and crafted variants of them to your API,
and reports the vulnerabilities it finds.
Unlike the Docker-based scanners, dast_api is a single self-contained binary
that runs without Docker.
It authenticates every run, so a scan without a credential is refused.
Installation
Linux and macOS
Run the one-line installer:
curl -fsSL https://public.fluidattacks.com/dast_api/install.sh | shThis installs the dast_api binary to /usr/local/bin by default.
Verify the installation
dast_api --versionScan with a configuration file
dast_api scans from a YAML configuration file,
which you pass with --config:
dast_api scan --config dast-api-config.yamlEach entry under dast.api needs the API's base_url
and at least one Postman collection in api_specs:
dast:
api:
- base_url: https://api.example.com
api_specs:
- postman/collection.jsonAn entry that declares no api_specs stops the scan with an error,
rather than reporting a target it never probed.
Authenticate
dast_api refuses to scan without a credential.
Every run is attributed to whoever ran it.
dast_api requires authentication. Without a credential the scan does not run
and exits with code 1.
Running it yourself, on your own machine?
Sign in through your browser
instead — dast_api login once, and nothing to store.
Authenticate with your group's Group token, supplied either way:
- Long-lived secret: set the
INTEGRATES_API_TOKENenvironment variable to a Group token from Organization → Groups → GroupName → DevSecOps → Manage token in the platform. - Short-lived, via OIDC: from any system that can issue OpenID Connect tokens
(CI/CD, AWS, GCP, Kubernetes, and more), pass
--group <your-group>anddast_apiobtains one per run with no stored secret. On GitHub Actions it is fetched automatically; on any other system, expose it as theINTEGRATES_OIDC_TOKENenvironment variable.
INTEGRATES_API_TOKEN takes precedence over both.
Where a CI OIDC source is present, --group is required
and a browser login is not used.
See Authentication for the full guide (including OIDC federation setup).
The token is used only to identify the caller; it is never printed or written to logs.
Common scenarios
Send credentials to the API under test
The credentials the scanner sends to your API are separate from your Fluid
Attacks group token.
key is the header name and value is the bare secret.
The bearer, oauth1 and oauth2 types add their own prefix,
so do not include one.
You can read the value from an environment variable:
dast:
api:
- base_url: https://api.example.com
api_specs:
- postman/collection.json
authentication:
- type: bearer
key: Authorization
value: ${API_TOKEN}The accepted types are bearer, apikey, oauth1 and oauth2.
Scan several APIs
dast:
api:
- base_url: https://api.example.com
api_specs:
- postman/public-api.json
- postman/admin-api.json
- base_url: https://payments.example.com
api_specs:
- postman/payments.jsonBlock the pipeline on findings
For pipeline gating with strict mode,
see Distributed binaries.
dast_api enables it from the configuration file only.
Troubleshooting
For common installation troubleshooting (permission denied, PATH issues), see Distributed binaries.
No output file is produced
With no output.file_path, the report is written to
FluidAttacksDastApiResults in the directory you ran the scan from,
carrying the extension of the configured format (.sarif by default),
so check there before changing the configuration.
ALL writes two reports, .csv and .sarif.
output.format must be SARIF, CSV or ALL; any other value causes an error.
Environment variable referenced in the scan config is not set
A credential whose whole value is ${API_TOKEN} requires that variable to be
exported before the scan; the scanner stops rather than sending an empty
credential.
A placeholder embedded in longer text is substituted with an empty string
instead, and the scan continues.