Free local workbench · Preview

Review what an AWS REST import could miss.

Check a release set, trace root-security inheritance, and compare declared security before and after a change. Your JSON and YAML files stay in your browser.

Check a release set locally

Select up to 8 JSON/YAML files. Each is checked independently; references between files are not bundled.

1 MiB per file · 4 MiB total · sequential processing · no persistence after reload

Files stay in this tab. No AWS connection, external reference fetching, or automatic changes. Privacy details

Make a security copy you can explain

AWS API Gateway REST ignores root-level security. The workbench shows which directly declared operations inherit it and which have explicit overrides. The single-file checker can preview only the eligible copies, with your selection.

Try the guarded security-copy preview · Read the rule and AWS source

Repeat the same bounded checks in CI

The offline CLI uses the same parser, pinned schema and AWS rules. Export a summary JSON report or SARIF, select a warning policy, and compare security requirements without uploading a definition.

Download and try the local CLI preview

What this review proves

The comparison normalizes the order of security alternatives, scheme names and scopes. It distinguishes a declaration-only change from new anonymous access, changed requirements, or a changed security-scheme definition. The security review is limited to 200 operations and 1 MiB of expanded security detail. Referenced Path Items and callbacks make coverage partial. It does not decide whether a change is safe to deploy.

No AWS import, integration, authorizer, IAM or runtime check is performed. A quiet report does not guarantee import success or secure access. Replay the synthetic examples · Read all limits