| Flag | Description |
|---|---|
| -u, --url | Base URL of the target API (required) |
| -e, --endpoints | Comma-separated paths to test (e.g., /users,/orders) |
| -H, --header | Custom HTTP header — repeatable (e.g., "Authorization: Bearer token") |
| --tests | Specific OWASP categories to run (e.g., API1,API4,API8) |
| --timeout | Request timeout in seconds (default: 10) |
| --no-verify | Skip TLS certificate verification |
| --version | Display version and exit |
Structured data with full metadata, per-test findings, severity levels, and remediation steps. Designed for CI/CD pipeline integration, SIEM ingestion, and GRC platform import.
Visual report with color-coded severity, compliance score, and finding details. Suitable for management review, audit evidence, and stakeholder communication.