Send a request like any client. Then get a verdict on the testing behind it: coverage gaps, missing auth paths, assertions that only check a status code. Self-hosted, on your own infrastructure.
The part no other API tool does. Grade what you have, enforce standards, keep them alive, fill the gaps, prove it.
Upload a file, pick an existing project, fetch from a URL, or compare two collections. 33 analyzers grade what they find and group every issue by impact: Blockers, Reliability, Correctness, Completeness and Quality.

Rules that auto-apply to every test during execution. Pick a ready-made preset, or switch to Custom Selection for control over every assertion type, operator and value. Click any category below to see its rules.

Applied at project level, so every test inherits them. Or switch to Custom Mode for full control over all 12 categories and 37 individual rules. Separately, the test editor offers 6 one-click assertion bundles — Quick Check, Standard, Thorough, Contract, Security and Performance — for adding assertions to a single test.
Build by clicking, or drop into custom JavaScript. Multiple operators per type across the ten categories.
Fields get renamed, moved, split or retyped. The healing engine detects the change, proposes the corrected assertion, and applies it automatically only when it is confident enough.

Upload a CSV, or generate data across ten categories including injection, unicode, boundary and type violation. Every row runs as its own case.

Each answers a different question, all generated from the same run data. Pick a type, scope it to one project or all projects, choose a format and generate.
Per-test pass/fail with failure grouping, error messages and stack traces.
Response time percentiles, throughput and k6 load-test output with AI bottleneck analysis.
Passive OWASP findings, active payload results and ZAP deep-scan output by CWE category.
Schema violations against OpenAPI specs, with $ref resolution and version diffing.
Overall project health with AI-written narrative summary across runs.
Coverage scoring, assertion depth and the five-tier issue classification.
JUnit XML, JSON and TAP output for pipeline integration with GitHub Actions, GitLab CI and Jenkins.
Pass-rate trend, response percentiles, failure grouping and regression detection across every suite.
Everything you need to construct a request, chain it, script it and execute it — across four protocols.
Point-and-click assertions, headers, auth and body configuration with instant visual feedback. No code required.
Params, Headers, Body, Auth, Scripts, Tests, Cookies and AI Analysis. Eight body types: JSON, form-urlencoded, form-data, XML, HTML, text, raw and none.
Dedicated surface with proto loading, alongside REST, GraphQL and WebSocket. Four protocols, one platform.
Introspection, type-name resolution, query depth and fragment-reuse analysis built into the analyzers.
Full tester with auto-reconnect and 1,245 lines of dedicated UI. Nine auth selectors, with bearer, basic and API key wired into the connect handshake.
Projects → Suites → Tests with categories, drag-and-drop ordering and nested navigation.
Bearer, Basic, API Key, OAuth 2.0, Digest, Hawk, NTLM, AWS Signature V4, plus none. Project-to-test inheritance with 401 auto-refresh and token caching.
Builtins → chained → suite → environment → global. Narrowest wins. Auto-extract tokens from responses; dynamic values always beat the store.
Dev, Staging, Production variables per project. Switch instantly without editing tests.
Postman-compatible pm.* API with CryptoJS, lodash, dateFns, uuid, pm.sendRequest() and pm.execution.setNextRequest().
Full cookie lifecycle across requests, with its own dedicated test suite.
Run a single test, a whole suite, or batch across suites. SSE streaming shows each result as it lands, with dependsOn chains and skipIfDepFailed.
Built-in companion API with 142 endpoints and 13 modules. Learn, test and demo with no external dependency.
Capture and keep responses for comparison, mocking and later inspection.
Every import is graded before it lands. AI pre-analysis, auto-detect, script extraction and a four-step wizard.
One platform instead of six.
CRUD, validation, error handling, pagination, filtering, sorting
Injection, auth bypass, data exposure, rate limiting
Response time, throughput, concurrency, spike profiles
Schema validation, backward compatibility, type checking
Health checks, availability, latency tracking
Multi-step workflows, data passing, dependency ordering
Four transports, one test model
Pipelines, scheduled runs, webhook triggers
Analysis is deterministic and repeatable. AI adds explanation, suggestion and conversation on top — never in place of the verdict.
Every failed test gets root cause analysis, severity rating, category tags and step-by-step fix suggestions.
Reviews entire responses holistically, not just assertions, catching subtle issues rules miss.
Per-field data quality: anomalies, missing values, format inconsistencies, unexpected patterns.
Recommends additional cases based on API structure, response patterns and coverage gaps.
Chat that knows your projects, runs and results. Contextual answers from your own data, with sources.
Pre-analyses imported collections: quality score, coverage gaps, auth detection, recommendations.
Datasets across ten categories including injection, unicode, boundary and type violation.
Proposes assertion repairs when response structure drifts, with before and after.
Written summaries on Health and Quality reports, generated from run data.
Reads k6 output and explains where the bottleneck is.
Interprets scanner findings and ranks real risk over noise.
Detects available models per provider so configuration stays current.
Seven providers. Switch per feature, or chain them with automatic fallback.
Self-hosting is table stakes. This is what makes it mean something: when a cloud provider is in the chain, sensitive values are masked before the prompt leaves your server, then restored in the response.

Three-level execution: single test, suite, or batch across suites. SSE streaming shows every result as it lands, with dependsOn chains and skipIfDepFailed for ordering.
Upload your company’s API docs as PDF, DOCX or MD. The RAG pipeline chunks, indexes and makes them searchable via AI chat, with source citations.
Full Postman-compatible pm.* API. pm.test(), pm.expect(), CryptoJS, lodash, dateFns, uuid, pm.sendRequest() for auxiliary calls, pm.execution.setNextRequest() for dynamic flow.
Scheduling, monitoring, security scanning, load testing, contracts, access control and audit — everything needed to run this in production.
Cron-based runs with timezone support and in-app notifications when something breaks.
Trigger runs from GitHub Actions, GitLab CI, Jenkins or any webhook, with token-scoped access.
Validate against OpenAPI specs with $ref resolution, AJV, five violation types and versioned contract schemas.
Three engines: passive OWASP checks, active payload probing with 44 payloads across 6 CWE categories, and ZAP deep scan in its own container.
k6-driven load testing with six profiles, live SSE dashboards, thresholds and checks captured per run.
Uptime and SLA tracking, four alert types, 90-day timeline, per-monitor trend and check history.
Database-backed roles at global and project scope, fully configurable permissions, cascade-safe deletes.
Every create, update and delete logged with user, timestamp, entity type and action.
Configurable retention policy with scheduled maintenance to keep history bounded.
Three commands, five reporters: Console, JUnit XML, JSON, HTML and TAP.
In-app notification centre with deep links straight to the failing run.
SSRF guards with permanent cloud-metadata blocking (169.254.169.254), an Allow Private URLs toggle, a 10-hop redirect cap, CSRF protection, rate limiting, JWT secret management and script sandboxing.
Extensibility, collaboration, portability and the stack it all runs on.
Extend execution with your own logic through a registered plugin executor and registry.
See who else is online and which test or suite they are viewing. SSE-powered presence indicators with automatic stale-session cleanup.
Git-friendly project export and import, so suites can live in your repository.
Build your own dashboard from the metrics you care about.
Upload API docs as PDF, DOCX or MD. RAG indexing makes them searchable and answerable in chat.
Generate runnable code in 8 languages from any request: cURL, JavaScript (fetch), Python (requests), Java (HttpClient), Go (net/http), Ruby (Net::HTTP), PHP (cURL) and C# (HttpClient).
109 built-in articles across 12 categories, searchable, with AI chat over the whole corpus.
Six services via Docker Compose: Postgres, Ollama, ZAP, app, nginx, certbot. Persistent volumes, health checks, auto-restart.
Deploy with Docker Compose on any VPS. Six services, persistent volumes, health checks, auto-restart. Nothing leaves your network.
Runs entirely on your own infrastructure. Nothing leaves your server.