Free Tools · Open source
X-Security
One API security policy, compiled to every WAF and gateway.
- gateway and WAF targets from one spec
- 7
- policy categories per route
- 17+
- OWASP API Top 10 mapped, coverage per class
- API1–10
- open source, deterministic, no API keys
- Apache-2.0
Overview
X-Security is a universal schema for writing API security policy as code. You declare security once per route, as an extension of the OpenAPI spec you already have, and a deterministic compiler turns it into enforceable rules for the WAFs and API gateways you run: Cloudflare, AWS API Gateway and WAFv2, Kong, Coraza and ModSecurity, BunkerWeb, Check Point Open AppSec and Envoy. Layer them for defence in depth, switch gateways without rewriting a line of policy, and fail CI when policy and API drift apart. Battle-tested and fully open source under Apache-2.0.
How it works
From setup to enforcement
- Step 01
Write one policy per route
Add an x-security block to each route in your OpenAPI file, by hand or with the visual policy builder. Start from a profile such as auth-endpoint, standard-crud, file-upload, webhook-receiver or admin-panel.
- Step 02
Compile deterministically
xsecurity generate --target <gateway> produces the native artifact for each gateway, with no LLM and no API keys in the compiler.
- Step 03
Verify before it ships
Every generated rule cites the file and line it came from and is byte-verified against your code. Anything unproven goes to review and is never enforced.
- Step 04
Deploy safely, gate drift
Rules land in log or shadow mode where the gateway supports it, promote one at a time, and roll back automatically within 60 seconds on a regression. A CI drift gate fails the build when policy and API diverge.
Features
Key features
Universal schema
Authentication, authorisation (RBAC, ownership rules, ABAC), rate limits, body caps, property allow-lists, response redaction, CORS, mTLS and more, in one portable format.
Compile to many targets
The same spec compiles to Cloudflare, AWS API Gateway and WAFv2, Kong, Coraza and ModSecurity (including an NGINX preset), BunkerWeb, Open AppSec and Envoy.
Defence in depth
Layer gateway, WAF and a host-firewall egress adjunct for SSRF, all from the same policy, for a multi-layered enforceable defence.
OWASP API Top 10 coverage
Full perimeter coverage for broken object-level authorisation (API1), broken function-level authorisation (API5) and SSRF (API7), with every partial gap named instead of rounded up.
Injection and prompt-injection guards
SQL, NoSQL, OS command, XPath, LDAP, code eval, XSS and deserialisation guards, plus an AI prompt-injection guard for LLM endpoints.
Byte-verified citations
Every rule points to the exact file and line it protects, and is checked against your code before compiling.
Shadow mode and auto-rollback
Log before block, promote per rule, and roll back automatically if error rate or latency regresses after a promote.
Signed audit chain
Append-only, hash-chained and signed with your organisation key, exportable as evidence for SOC 2 and customer audits.
Honest about limits
Logic flaws, races and valid-input DoS need code fixes; the coverage report flags them instead of pretending a WAF rule patches them.
Who it's for
Built for how teams actually work
Teams running more than one gateway
Keep one source of truth for API security across Cloudflare, AWS and self-hosted gateways, instead of hand-writing each vendor's config.
Switching or adding gateways
Move from one WAF to another, or add a second layer, without rewriting policy.
Closing the OWASP API Top 10 at the edge
Enforce object- and function-level authorisation, SSRF allow-lists and injection guards at the perimeter while code fixes land.
Security as code review
Policy lives in git, diffs like code, is reviewed in pull requests, and fails CI when it drifts from the API.
Technical details
Works with your stack
- Targets
- Cloudflare (GA, hosted), AWS API Gateway and WAFv2 (beta, hosted), Kong (beta), Coraza and ModSecurity with NGINX preset (beta), BunkerWeb (beta), Check Point Open AppSec (beta), Envoy (alpha), iptables egress for SSRF
- Format
- x-security extension to OpenAPI, validated by JSON Schema
- Profiles
- auth-endpoint, standard-crud, file-upload, webhook-receiver, public-read-only, admin-panel, server-rendered-page, graphql-resolver and more
- CLI
- npm i -g @chain305/x-security, then xsecurity generate, test and verify
- Editors
- Plugins for Claude Code, Cursor and Codex
- Deployment safety
- Log-first by default, per-rule promote, 60-second auto-rollback window (30 to 600 s)
- Licence
- Apache-2.0, 100% open source
Pricing
Plans
Free and open source under Apache-2.0.
Open source
The schema, CLI and every compile target.
- Universal x-security schema
- Deterministic compiler for all targets
- Test, verify and CI drift gate
- Editor plugins
FAQ
Questions teams ask
Does it replace fixing the code?
No. A perimeter layer narrows your attack surface. Logic flaws, race conditions and expensive-but-valid requests need code fixes, and the coverage report names them.
Does the compiler use an LLM?
No. Compilation is deterministic and needs no API keys. Every rule is byte-verified against your code before it is emitted.
What if a rule blocks real traffic?
Rules start in log or shadow mode where the gateway supports it, are promoted one at a time, and roll back automatically if errors or latency regress after a promote.
Products