API documentation
Draft reference. Endpoints are not live yet — this page tracks the shape of the v1 API.
Authentication
All requests are authenticated with an API key issued from your dashboard. Send it as a bearer token. Keys are scoped to a single account and can be revoked at any time.
curl https://api.cooltechtools.com/v1/jwt/simulate \
-H "Authorization: Bearer $CTT_API_KEY" \
-H "Content-Type: application/json" \
-d '{"token":"eyJhbGciOi...","attacks":["alg-none","weak-secret"]}'Endpoints
POST
/v1/jwt/simulateRun attack simulations against a supplied token.
POST
/v1/cookies/analyzeAudit a raw Set-Cookie header.
POST
/v1/cors/probeProbe a target for CORS misconfiguration. Requires authorization attestation.
POST
/v1/oauth/inspectInspect an authorization request for common misconfigurations.
GET
/v1/resultsList stored results for the authenticated account.
GET
/v1/results/{id}Fetch a single stored result.
Example request
POST /v1/cookies/analyze
{
"header": "Set-Cookie: sid=1001; Path=/"
}Example response
200 OK
{
"id": "res_8f21",
"findings": [
{ "level": "critical", "code": "missing_httponly" },
{ "level": "warn", "code": "predictable_value" }
]
}Rate limits & errors
Limits are enforced per key and returned in X-RateLimit-Remaining. Exceeding them returns 429. Validation failures return 422 with a machine-readable code field.