Desktop product

Agent Breach Studio

A local desktop suite for your own APIs — import OpenAPI, find issues, replay traffic, and ship with confidence. Free core forever; optional cloud AI coach when you want it.

Read the user guide

API security on your machine — before you ship

Studio is built for developers and appsec engineers who need a focused, offline-friendly toolkit: OpenAPI-aware scanning, findings triage, Repeater, and a local proxy. No browser extension farm. No forced cloud scanners. Engines run on your device.

Why teams pick Studio

  • Free forever core — no account required to scan and triage locally
  • First-party engines only — no SaaS scanners or third-party CLIs embedded in your workflow
  • Maps to how you already work: OpenAPI → findings → replay → fix
  • Optional Studio AI coach when you want help explaining or prioritizing findings

How it works

From OpenAPI to actionable findings in a few steps — all on your desktop.

  1. 01

    Import your API

    Load an OpenAPI 3.x spec, create a project, and keep encrypted local storage on disk.

  2. 02

    Scan and triage

    Run passive and active first-party checks, then review findings with likely-public classification.

  3. 03

    Replay and fix

    Use HTTP history, Repeater, auth profiles, and scope rules to validate issues before you ship.

What you get in the free core

Everything maps to the desktop sidebar. Open the user guide when you want a deeper walkthrough of each area.

OpenAPI & projects

Import specs and keep work organized locally.

  • OpenAPI 3.x import
  • Project files on disk
  • Encrypted local storage

Findings & detection

First-party rules that stay on your device.

  • Passive and active checks
  • Findings triage workspace
  • Likely-public auto-classification

Traffic & Repeater

Inspect and replay requests without leaving Studio.

  • HTTP history
  • Repeater for manual testing
  • Lightweight local proxy

Auth, scope & BOLA

Model how real users hit your API.

  • Auth profiles
  • Scope rules
  • BOLA-oriented checks

Checklist & reporting

Export progress without a cloud dashboard.

  • Testing checklist
  • Local report exports
  • Stay on your machine

Local-first by design

Your traffic and tokens stay with you by default.

  • No account for core features
  • Engines on-device
  • AI context is opt-in

Optional Studio AI coach

When you want help understanding or prioritizing findings, sign in with Cognito and use cloud credits from Studio Account. The free core never requires a subscription.

See Studio AI pricing

Different from Agent Breach cloud

Agent Breach (SaaS) is continuous org pentesting in the cloud. Studio is a local desktop suite for developers before ship — separate product and Cognito identity.

Privacy

Proxy traffic stays on your machine unless you opt into AI context. Cookies and tokens are stripped from AI prompts by default.

New to Studio? Read the user guide