Scan at scaleSites with a broken API catalog
Sites with a broken API catalog
A site-wide report: one row per host, over the api_catalog rows the crawl emitted.
What this report returns
An API catalog is a short index at /.well-known/api-catalog that lists a site's APIs and where each is described, so an agent finds every API from one address instead of guessing paths.
These sites publish one a client can't use as written: served in a format other than application/linkset+json, shaped in a way the linkset format doesn't allow (an extra top-level member, a relation that isn't a list, a link with no href), or linking to no API at all. Each of those breaks a requirement of the standard, so a client following it may skip the catalog entirely. Rows the Security Risk column marks list an API on plain http, so agents calling it send requests and credentials unencrypted, or on an internal host, publishing internal metadata RFC 9727 tells publishers to audit out.
How to fix it. Serve it as application/linkset+json, as {"linkset": [{"anchor": "https://example.com/.well-known/api-catalog", "item": [{"href": "https://api.example.com/v1"}]}]}, with one item link per API, each on https and none internal. API Catalog Missing Profile is informational and never fails the site: it notes the media type lacks the RFC 9727 profile parameter.
Spec: RFC 9727, with the linkset format from RFC 9264. Sites that publish no API catalog don't appear here, because absence is not a failure.
Security checks are provisional; precision has not yet been measured. A clean row is not a security assessment.
The columns it shows
Every defect this technology can carry is a column in the grid, worst first, so nothing is hidden behind a filter you have to know to apply.
- Host
host - API Catalog Valid
apiCatalogValid - API Catalog Conformance Issue Detected
apiCatalogConformanceIssueDetected - API Catalog Security Risk Detected
apiCatalogSecurityRiskDetected - API Catalog Findings
apiCatalogFindings - API Catalog Content Type
apiCatalogContentType - API Catalog Link Count
apiCatalogLinkCount - API Catalog Relations
apiCatalogRelations - API Catalog Malformed Linkset
apiCatalogMalformedLinkset - API Catalog No API Links
apiCatalogNoApiLinks - apiCatalog HTTPS Downgrade
apiCatalogInsecureRedirect - API Catalog Wrong Media Type
apiCatalogWrongMediaType - API Catalog Insecure Link
apiCatalogInsecureLink - API Catalog Internal Link
apiCatalogInternalLink - API Catalog Missing Profile
apiCatalogMissingProfile - Ruleset Version
rulesetVersion - Security Check Status
securityCheckStatus - Related Security Frameworks
securityFrameworkReferences
About API catalog
An index at /.well-known/api-catalog listing the site's APIs and their descriptions.
Read how API catalog is checked, including the specification it is validated against and a worked correct and broken example.
Running it
This report comes with Agentic Readiness in Lumar and appears on every crawl of any project that has it turned on. See the whole set, or check a single URL with the scanner on this site, which runs the same code with no account.