AppSecNews
API Security Commercial Established

Akamai API Security (Noname)

by Akamai

API discovery, posture management and runtime threat detection built on the Noname platform, analyzing traffic out of band across gateways and clouds.

Visit akamai.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Akamai API Security (Noname) in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
  • Degree of integration with Akamai edge delivery and App and API Protector after the acquisition: confirm
  • Current connector and integration list: verify against vendor docs
  • Product and edition naming following the rebrand: confirm

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

This is the Noname Security platform under Akamai ownership. It works primarily out of band: rather than sitting in the request path, it ingests copies of API traffic from wherever that traffic already passes through infrastructure you control. Connectors pull from load balancers, API gateways, service meshes, cloud traffic mirroring and log streams. From that stream it reconstructs endpoints, parameters and response shapes, producing an inventory that includes internal, partner facing and forgotten endpoints that never appeared in any specification. Payload inspection classifies the data moving through each route.

On top of the inventory sit three functions. Posture management evaluates configuration against a rule set: missing authentication, weak transport settings, endpoints returning more data than their role requires, drift between a published specification and observed behavior. Runtime detection builds behavioral baselines per endpoint and per caller, then alerts on deviations that suggest enumeration, credential abuse or authorization probing. Active testing generates and runs security tests against an API in a pre production environment, driven by the discovered inventory rather than by a hand written suite.

Where it fits

Discovery and posture are security team functions, running continuously against production and staging traffic. The active testing component moves into the pipeline as a pre release check. Remediation lands on API owning development teams, so ticket routing and ownership mapping matter as much as detection quality. The prerequisite is infrastructure access: someone has to configure mirroring or connectors across every environment where APIs live, and gaps in that coverage become gaps in the inventory.

Strengths

  • Broad connector coverage across clouds, gateways and load balancers, suiting estates spread over heterogeneous infrastructure.
  • Out of band deployment means no component in the request path and no added latency.
  • Inventory, posture, detection and testing share one data model, so a finding traces from endpoint to test case to alert.
  • Parameter level data classification ties exposure findings to specific fields rather than to services.

Limitations

  • Out of band analysis detects but does not block. Enforcement requires a separate inline control such as a WAF or gateway policy.
  • Coverage depends entirely on which traffic you mirror. APIs on infrastructure without a connector stay invisible.
  • Behavioral detection needs a learning period, produces noise during it, and requires ongoing per endpoint tuning.
  • Post acquisition packaging and roadmap are still settling, worth confirming before a long commitment.

Who it suits

Large enterprises with sprawling API estates, existing Akamai infrastructure, and a security team able to operate a detection platform. Small teams with a handful of documented services will find the deployment and tuning burden out of proportion to the return.

Used Akamai API Security (Noname)? Recommend it under your own name and title.

Recommend this tool