Receives tools
An agent is connected to operations defined by an API surface.
AI agent API security
Map exposed API capabilities. Find agent-readiness gaps. Gate risky capability changes—from the OpenAPI contract, before integration.
Speculynx turns the API contract into structured evidence for agent builders, security teams, and CI. The facts come from deterministic analysis; your team makes the final decision.
Declared operations and security metadata
Static, deterministic, local-first
Structured terminal and JSON evidence
It may simply inherit an API operation with more capability than the team intended. The declared contract can expose that blast radius before the integration is wired.
An agent is connected to operations defined by an API surface.
GET /customers · POST /refunds · DELETE /users
Write, financial, privileged, destructive, or sensitive-data access.
Speculynx makes the documented surface visible before integration.
Map what the API exposes, review whether the documented surface is appropriate for agent access, and gate security-relevant changes before they ship.
What could an AI agent do through this API?
What needs review before agent integration?
Did this change introduce dangerous capability?
Need all three decision layers? Agent Security Suite grants exactly Capability Mapper, Agent API Readiness, and Integration Gate.
Explore Agent Security Suite →The OpenAPI Security scanner is the lower-friction entry point: four Free controls, ten additional Pro heuristics, deterministic output, and explicit coverage.
Review four high-signal controls. A no-finding Free result remains indeterminate because Pro rules were not executed.
Explore OpenAPI Security →Add ten heuristics, PDF output, and bounded live checks. Pro does not grant Agent Security products.
Compare product families →Each team sees the same deterministic contract facts through the decision it owns.
Understand which operations become agent actions.
↗APPSECFind sensitive capability and authorization signals.
↗DEVSECOPSTurn capability deltas into CI policy.
↗API TEAMSMake intended access clearer before integration.
↗Technical trust
OpenAPI files stay on your machine during static analysis. Outputs are deterministic and structured. Runtime reachability, effective IAM, and safe agent execution still require runtime evidence and human judgment.
The source OpenAPI file is not uploaded for static analysis or entitlement verification.
Product access is verified independently. Signed Stripe webhooks activate billing records and grants.
Findings and verdicts describe the declared contract, not production enforcement.
OpenAPI Security Free and Pro are separate from the four one-time Agent Security offers. Checkout remains authoritative for the final total and applicable taxes.
Start with local Free checks. Upgrade separately for the monthly Pro scanner feature set.
Open pricingCapability Mapper $99, Agent API Readiness $199, Integration Gate $249, or the exact three-product Suite $399.
Compare Agent SecurityThe scope is static and contract-level by design.
Speculynx is a local-first security CLI for AI-connected APIs. It analyzes declared OpenAPI 3.0 and 3.1 contracts to map agent-accessible capabilities, surface readiness signals, compare risky capability changes, and review OpenAPI security signals.
No. Static analysis runs locally. License and entitlement verification does not send the source OpenAPI document to Speculynx. Optional audit synchronization sends a bounded result, not the source file.
No. Speculynx analyzes declared contract information. It does not prove runtime reachability, IAM enforcement, prompt-injection resistance, or safe agent execution.
Exactly Capability Mapper, Agent API Readiness, and Integration Gate. The Suite grants those three product entitlements and no hidden fourth capability.
No. Pro is the OpenAPI Security subscription. Agent Security products are separate one-time purchases with separate entitlements.
Start with local analysis. Move into Agent Security when you need capability mapping, readiness review, or change gating.