Agent Breach Studio
A local desktop suite for your own APIs — import OpenAPI, find issues, replay traffic, and ship with confidence. Free core forever; optional cloud AI coach when you want it.
API security on your machine — before you ship
Studio is built for developers and appsec engineers who need a focused, offline-friendly toolkit: OpenAPI-aware scanning, findings triage, Repeater, and a local proxy. No browser extension farm. No forced cloud scanners. Engines run on your device.
Why teams pick Studio
- Free forever core — no account required to scan and triage locally
- First-party engines only — no SaaS scanners or third-party CLIs embedded in your workflow
- Maps to how you already work: OpenAPI → findings → replay → fix
- Optional Studio AI coach when you want help explaining or prioritizing findings
How it works
From OpenAPI to actionable findings in a few steps — all on your desktop.
- 01
Import your API
Load an OpenAPI 3.x spec, create a project, and keep encrypted local storage on disk.
- 02
Scan and triage
Run passive and active first-party checks, then review findings with likely-public classification.
- 03
Replay and fix
Use HTTP history, Repeater, auth profiles, and scope rules to validate issues before you ship.
What you get in the free core
Everything maps to the desktop sidebar. Open the user guide when you want a deeper walkthrough of each area.
OpenAPI & projects
Import specs and keep work organized locally.
- OpenAPI 3.x import
- Project files on disk
- Encrypted local storage
Findings & detection
First-party rules that stay on your device.
- Passive and active checks
- Findings triage workspace
- Likely-public auto-classification
Traffic & Repeater
Inspect and replay requests without leaving Studio.
- HTTP history
- Repeater for manual testing
- Lightweight local proxy
Auth, scope & BOLA
Model how real users hit your API.
- Auth profiles
- Scope rules
- BOLA-oriented checks
Checklist & reporting
Export progress without a cloud dashboard.
- Testing checklist
- Local report exports
- Stay on your machine
Local-first by design
Your traffic and tokens stay with you by default.
- No account for core features
- Engines on-device
- AI context is opt-in
Optional Studio AI coach
When you want help understanding or prioritizing findings, sign in with Cognito and use cloud credits from Studio Account. The free core never requires a subscription.
See Studio AI pricingDifferent from Agent Breach cloud
Agent Breach (SaaS) is continuous org pentesting in the cloud. Studio is a local desktop suite for developers before ship — separate product and Cognito identity.
Privacy
Proxy traffic stays on your machine unless you opt into AI context. Cookies and tokens are stripped from AI prompts by default.
New to Studio? Read the user guide