Feature docs · Website security · Module: api-response
API Response Scanner is a Guardbee scan module under website security. Loads the site in a headless browser, captures every fetch/XHR the page fires, then checks responses for leaks and CORS.
What does it check?
Loads the site in a headless browser, captures every fetch/XHR the page fires, then checks responses for leaks and CORS. Results appear in the dashboard and scan detail as score, findings, and recommended actions.
Business impact
API leaks can be more critical than HTML issues.
Guardbee presents risk, impact, and priority — so product, legal, and engineering share one screen.
How to run it
- Create a Guardbee account (25 credits for new accounts)
- Add a brand / URL
- Select API Response Scanner under Website security
- Run the scan; optionally explain findings with BeeAI
Related docs
Run this module now
Use API Response Scanner with credits. New accounts get 25 credits.
Frequently asked questions
Is API Response Scanner required?
No. Pick modules as needed; you only spend credits on what you run.
Is scanning destructive?
No. Guardbee uses controlled, read-only, limited requests.
Does it work with BeeAI?
Yes. After a scan, BeeAI can summarize findings in business language.