Continuous API security scanning,
hosted for you.

Barbel runs the OWASP API Top 10 against your APIs on demand or on a schedule — no agents to install, no CI to wire up. Findings are tracked over time, so regressions surface the moment they appear.

Free to start — no credit card required.

app.barbel.dev — findings
CRIT

Wildcard CORS + credentials

api.acme.com

NEW
HIGH

/admin reachable without auth

api.acme.com

STILL OPEN
HIGH

HSTS not set

checkout.acme.com

STILL OPEN
MED

No rate-limit headers

api.acme.com

RESOLVED
How it works

Set up once, scan continuously

Barbel is the hosted layer on top of Sentinel, our open-source scan engine — you get results history and trend detection without running anything yourself.

01

Register a target

Point Barbel at your API's base URL. No agents, no code changes, no CI wiring.

02

We scan it

On demand or on a schedule, Barbel runs Sentinel's full OWASP API Top 10 suite against your target and stores the results.

03

Track findings over time

Every finding gets a stable fingerprint. New regressions surface immediately; fixed issues are marked resolved automatically.

Under the hood

Built on Sentinel, our open-source scanner

Sentinel is a free, MIT-licensed CLI that checks the OWASP API Top 10 — headers, CORS, auth, rate limiting, inventory exposure, and injection. Barbel runs it for you, hosted and on a schedule; you can also run it yourself, standalone, for free.

Explore Sentinel →