Skip to main content

Skanyr

API endpoint discovery from JS bundles and network activity

3 min read


Skanyr discovers hidden API endpoints by parsing JavaScript bundles and intercepting network activity. Use it when you suspect a site has hidden APIs — it's often faster than scraping HTML.

After discovery, retrieve detected APIs and their data via dedicated data endpoints.

discover

result = client.skanyr.discover(
    "https://example.com",
    site_hierarchy_artifact_id=crawl.artifact_id,
)
for ep in result.endpoints:
    print(ep.method, ep.url, ep.confidence)

discover_all (auto-pagination)

for ep in client.skanyr.discover_all("https://example.com"):
    print(ep.method, ep.url)

discoverStream (SSE)

for await (const event of client.skanyr.discoverStream('https://example.com')) {
  console.log(event.type, event.endpoint?.path);
}

detected_apis

After running discovery, retrieve all detected API endpoints and their status across all 12 detectors.

apis = client.skanyr.detected_apis("https://example.com")
for detector in apis.detectors:
    print(detector.name, detector.status, detector.record_count)
const apis = await client.skanyr.detectedApis('https://example.com');
apis.detectors.forEach(d => console.log(d.name, d.status, d.recordCount));

DetectedAPIsResponse fields

| Field | Type | Description | |-------|------|-------------| | detectors | list | Results from each of the 12 detectors | | total_records | integer | Sum of records across all detectors | | page_url | string | The discovered page URL |

DetectorResult fields

| Field | Type | Description | |-------|------|-------------| | name | string | Detector name (e.g. rest_api, graphql, json_ld) | | status | string | found, empty, or error | | confidence | float | 0.0 to 1.0 | | record_count | integer | Number of data records extracted | | api_type | string | rest, graphql, websocket, etc. |

api_data (paginated)

Retrieve the actual extracted data for a specific API endpoint, with pagination.

data = client.kolektr.get_api_data_paginated(
    "https://example.com/api/v1/products",
    offset=0,
    limit=1000,
)
print(data)
const data = await client.kolektr.getApiDataPaginated('https://example.com/api/v1/products', {
  offset: 0,
  limit: 1000,
});
console.log(data);

Response fields

The API returns a dict with extracted data records and pagination metadata. Use client.kolektr.get_api_data(endpoint) for the full unpaginated response.

Data endpoints require a prior discovery run. If no cached results exist, the API returns 404. Discovery results are cached per-organization — each tenant sees only their own results.

ApiEndpoint fields

| Field | Type | Description | |-------|------|-------------| | method | string | HTTP method | | path | string | Endpoint path | | confidence | float | 0.0 to 1.0 | | source | string | js_bundle, network, or probe | | parameters | list | Detected request parameters |

Next steps

Was this page helpful?