API documentation

Draft reference. Endpoints are not live yet — this page tracks the shape of the v1 API.

Authentication

All requests are authenticated with an API key issued from your dashboard. Send it as a bearer token. Keys are scoped to a single account and can be revoked at any time.

curl https://api.cooltechtools.com/v1/jwt/simulate \
  -H "Authorization: Bearer $CTT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"token":"eyJhbGciOi...","attacks":["alg-none","weak-secret"]}'

Endpoints

POST/v1/jwt/simulate

Run attack simulations against a supplied token.

POST/v1/cookies/analyze

Audit a raw Set-Cookie header.

POST/v1/cors/probe

Probe a target for CORS misconfiguration. Requires authorization attestation.

POST/v1/oauth/inspect

Inspect an authorization request for common misconfigurations.

GET/v1/results

List stored results for the authenticated account.

GET/v1/results/{id}

Fetch a single stored result.

Example request

POST /v1/cookies/analyze
{
  "header": "Set-Cookie: sid=1001; Path=/"
}

Example response

200 OK
{
  "id": "res_8f21",
  "findings": [
    { "level": "critical", "code": "missing_httponly" },
    { "level": "warn", "code": "predictable_value" }
  ]
}

Rate limits & errors

Limits are enforced per key and returned in X-RateLimit-Remaining. Exceeding them returns 429. Validation failures return 422 with a machine-readable code field.