Talk to us
by AkamaiTechBag Intel Page

Akamai API Security

Your attackers already have a list of your APIs. Your security team should have a better one — Akamai API Security finds every API you run — from traffic, code, specs and cloud accounts — tests it in CI/CD, and flags abuse in production, as SaaS, hybrid or on-prem, with no Akamai CDN required.

One inventory from traffic, code and specs200+ tests in CI/CDSaaS, hybrid or on-prem

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Akamai prints no API Security price; the free attack-surface assessment comes before any quote
Quote
Analysts
KuppingerCole Leadership Compass for API Security & Management, published July 2025
Overall Leader
Testing
Akamai’s count of API security tests that run in CI/CD and preproduction pipelines
200+ tests
India
No Indian SaaS region is documented; hybrid or on-prem keeps the traffic copy on your side
Your choice

Quick answer

Akamai API Security builds an inventory of your APIs from traffic, code, specs and cloud accounts — shadow, zombie and MCP endpoints included — scores their posture against OWASP API, PCI DSS and five other frameworks, runs 200+ tests in CI/CD and flags abuse in production. It grew out of the Noname Security acquisition (2024), needs no other Akamai product, runs as SaaS, hybrid or on-prem, and is quote-only. Read more ↓ Show less ↑
Part 01 · Orient

The Akamai platform family

This page covers Akamai API Security — discovery, posture, testing and runtime detection, from the Noname Security acquisition. The rest:

Quick facts

30-second orientation
Product
API discovery, posture management, CI/CD testing and runtime abuse detection in one product
Maker
Akamai Technologies, Cambridge, Massachusetts; NASDAQ: AKAM; CEO Tom Leighton
Origin
The Noname Security acquisition, closed 25 June 2024; sold today as Akamai API Security
Price
Quote-only; a free, nonintrusive attack-surface assessment is offered first
Deployment
SaaS, hybrid or on-premises; analyses a copy of traffic out of band, not inline
Sources
Akamai’s edge via a native connector, or 40+ other WAFs, CDNs, gateways and clouds
Analysts
Overall Leader, KuppingerCole Leadership Compass API Security & Management 2025
Customers
Godrej in India; Commerzbank and Novant Health named on Akamai’s product page
India
No India dashboard region documented; the on-prem option keeps traffic analysis in your site
In India via
TechBag — attack-surface assessment, connector plan, quote in INR with GST
Part 02 · Learn

Understand API security before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is API security?

Finding every API you run, testing it before release, and spotting abuse in production.

A gateway list and a yearly pen test vs a living API inventory — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA gateway list and a yearly pen testAkamai API Security
Knowing which APIs existA gateway list and a wiki pageOne inventory from traffic, code, specs and clouds
Shadow and zombie endpointsFound by an attacker or a pen testFlagged as soon as traffic or code reveals them
Testing before releaseA yearly pen test on a few APIs200+ automated tests inside CI/CD
Abuse in productionSignature WAF rules, request by requestBehaviour baselines that spot logic abuse
Audit evidenceScreenshots gathered by handFindings mapped to PCI DSS, HIPAA, NIST and more
What it is NOT—An inline WAF, an API gateway, or a priced plan

The cheapest test is the free assessment: see which of your APIs are exposed today before anyone talks price.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where the API data comes from

Sources

Traffic, code and cloud connectors

Out-of-band connectors copy API traffic from Akamai’s edge or from 40-plus other sources — third-party WAFs, CDNs, gateways and clouds — and read code repositories and specs too.

02
What exists, and how exposed it is

Inventory

API inventory and posture engine

Each endpoint found, shadow, zombie, MCP and AI-linked ones included, is catalogued with the data it carries and scored against OWASP API, PCI DSS, HIPAA, NIST and more.

03
Where flaws are caught before release

Testing

Active tests in the pipeline

More than 200 API security tests run inside CI/CD and preproduction, so a broken authorisation check or an over-sharing response is caught before the API ships.

04
How abuse is caught in production

Runtime

Behavioural detection and response

Runtime analysis learns normal use, flags abuse and business-logic attacks, and hands each finding to a SIEM, ITSM, CMDB, WAAP or gateway that can block or ticket it.

Copies of API traffic, code and specs feed one inventory — tested in CI/CD, watched in production, enforced by your WAAP.

Part 03 · Evaluate

Nine capabilities. Discover, test, protect.

Akamai API Security gives every API one record, from first commit to production traffic.

Discover
Inventory

Every API, registered or not

One inventory built from traffic, code, specs, gateways and cloud accounts, with the shadow and zombie endpoints nobody listed.

Discover
AI-linked

MCP servers on the list

APIs tied to GenAI apps, LLM services and MCP servers are found and marked, so the unmanaged ones get an owner and a review.

Discover
Connectors

Forty-plus traffic sources

Reads traffic copies from third-party WAFs, CDNs, API gateways and clouds, or from Akamai’s own edge through a native connector.

Test
CI/CD

200+ tests before release

More than 200 API security tests run in CI/CD and preproduction, so flaws reach a developer while the fix is still cheap.

Test
Posture

Seven frameworks mapped

Findings map to OWASP API, PCI DSS, HIPAA, ISO 27001, GDPR, HITRUST and NIST, which turns a scan into audit evidence.

Test
Sensitive data

Where personal data flows

Endpoints that expose sensitive data in requests or responses are flagged, so data owners can see which APIs carry it.

Protect
Runtime

Business-logic abuse

Learns how each API is normally called and flags abuse and logic attacks that request-by-request signature rules let through.

Protect
Out of band

No hop added to calls

Analysis runs on a copy of the traffic, so API calls take no extra hop and the network needs no rework to switch it on.

Protect
Workflows

Findings in your own tools

Results flow to SIEM, ITSM, ticketing, CMDB, WAAP, gateway and developer workflows, where the block or the fix is made.

See it, don’t just read it

Watch Akamai API Security in action

Why AI security starts with APIs, discovering APIs from source code, and Akamai’s demo of finding and protecting APIs.

Akamai (official)·Explainer, 2026

You Can’t Secure AI Without Securing APIs

Akamai’s case that securing AI apps and agents starts with the APIs they call.

Akamai (official)·Demo, 2026

Akamai API Security: APIs from Code Demo

Akamai’s demo of discovering APIs from source code rather than from traffic.

Akamai (official)·Demo, 2025

Demo: Discover and protect your APIs | Akamai API Security

Akamai’s own demo of finding APIs and then protecting them, from mid-2025.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Akamai API Security

APIs multiply faster than anyone registers them. Akamai API Security keeps the list, and watches it.

Here’s what genuinely sets it apart — and exactly where it stops.

01

An inventory that does not rely on one feed

Most API tools see only what passes their own proxy. Akamai API Security combines traffic copies from more than 40 sources with code, specs, gateways and cloud accounts, so an endpoint missing from the gateway still shows up. MCP servers and AI-linked APIs are listed alongside the rest, which matters as agents start calling internal services.

02

Testing and runtime share one picture

The same inventory drives 200+ tests in CI/CD and behavioural detection in production, so a flaw found before release and an abuse pattern seen afterwards land against the same endpoint record. Posture findings map to OWASP API, PCI DSS, HIPAA, ISO 27001, GDPR, HITRUST and NIST, which helps when an auditor asks for evidence.

03

No Akamai edge required, but a shortcut if you have it

Akamai states the product does not require its other products and runs as SaaS, hybrid or on-prem. Customers already on Akamai’s edge can send a traffic copy through a native connector that Akamai said in 2024 carries no ongoing cost. On analyst standing, KuppingerCole’s July 2025 Leadership Compass ranked the product line an Overall Leader.

04

Where it stops

There is no public price, only a free assessment and a quote. Detection runs out of band, so blocking happens in a WAAP, gateway or other tool you connect, not in the product itself. Akamai documents no Indian SaaS dashboard region, so in-country analysis means the hybrid or on-prem route. Licensing units are not published.

The idea
One API inventory, from code to runtime
The residency
Hybrid or on-prem keeps data in India
The price
Quote-only, after a free assessment
Proof, not promises

The numbers behind the platform

200+ tests
API security tests Akamai says run in CI/CD and preproduction pipelines
— Vendor
40+ sources
third-party WAFs, CDNs, gateways and clouds the product can take traffic from (2024)
— Vendor
7 frameworks
OWASP API, PCI DSS, HIPAA, ISO 27001, GDPR, HITRUST and NIST, for posture findings
— Vendor
6B calls
monthly API calls Commerzbank secures, as named on Akamai’s product page
— Customer
300+ apps
applications Godrej protected in six months across Akamai products, per its CISO
— Customer
$293M
FY2025 revenue Akamai reported for Guardicore Segmentation and API Security, up 43%
— Earnings release

What your Akamai API Security rollout looks like

Week 1Model

Take the free assessment

Run Akamai’s nonintrusive attack-surface assessment to see which public APIs and assets are exposed today.

Week 2Decide

Pick traffic sources

List the CDNs, WAFs, gateways and clouds carrying API traffic, and choose SaaS, hybrid or on-prem for each copy.

Week 3Pilot

Connect and build the inventory

Switch on the native connector or third-party sources, add code repositories, and review shadow and MCP findings.

Month 2Prove

Put tests in one pipeline

Add the API security tests to one team’s CI/CD, tune out noise, and agree who fixes a failed check before release.

Month 3Commit

Wire runtime to enforcement

Send runtime findings to the SIEM and ITSM, and decide which WAAP or gateway blocks an abusive client.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
47+ reviews*
85% would recommend
API discovery4.6
Runtime detection4.3
CI/CD testing4.1
Ease of rollout4.0
Value for money3.7
5★
48%
4★
35%
3★
11%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“The first inventory showed nearly twice the endpoints our gateway team had registered, most of them old mobile-app versions.”
AppSec Lead
BFSI
E-commerce
“We already ran Akamai’s edge, so the native connector had traffic flowing into the console on the first afternoon.”
Security Architect
E-commerce
Payments
“Mapping findings to PCI DSS saved a week of spreadsheet work before our assessor arrived for the card-data review.”
GRC Manager
Payments
SaaS
“It found an MCP server a product team had stood up for an agent pilot, with no auth review. That alone justified the trial.”
CISO
SaaS
Telecom
“Runtime alerts go to our SIEM, but blocking still happens in the WAF; plan that hand-off before you go live.”
SOC Manager
Telecom
Insurance
“The CI tests were noisy at first on our legacy SOAP services and needed tuning, and the quote took a while to arrive.”
DevSecOps Engineer
Insurance
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the API security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag API Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Akamai API SecurityThis page

KuppingerCole Overall Leader 2025; quote-only.

Grid 02 · The architecture

Deployment Choice × Lifecycle Coverage

The grid nobody publishes — how many ways the tool can be deployed and keep data on your side vs how much of the API lifecycle it covers.

Deep but tied to one edgeFull-lifecycle, deploy anywhereEdge add-onsFlexible point tools
Akamai API SecurityThis page

SaaS, hybrid or on-prem; discover, test, detect, MCP.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Akamai API Security vs the API security field

Against Salt Security, Traceable by Harness, Cloudflare API Shield, Wallarm and Levo.ai — on deployment, discovery, testing, runtime, AI coverage, price and India data.

DimensionAkamai API SecuritySalt SecurityTraceable by HarnessCloudflare API ShieldWallarmLevo.ai
What it isFull-lifecycle API toolAPI + agent protectionAPI security inside WAAPCloudflare WAAP add-onAPI security + WAAPDeveloper-first newcomer
DeploymentSaaS, hybrid, on-premSaaS or Hybrid ServerSaaS, agent, or on-premCloudflare edge onlyOwn nodes or EdgeeBPF sensors in your env
Discovery sourcesTraffic, code, specsMirrored traffic + cloudFive API stylesOnly Cloudflare trafficPlan-dependent discoveryeBPF plus auto-specs
Posture and complianceSeven frameworksAI Act, NIST, SOC 2Sensitive-data mappingSchema enforcementSpec enforcementDPDPA among mappings
Pre-release testing200+ tests in CI/CDSalt Code for AI codersXAST and DASTNot in API ShieldSchema-based DASTShift-left DAST
Runtime protectionDetect, then hand offOut of band, no latencyWAF, API and bot rulesInline at the edgeInline or asyncNewer at runtime
AI and MCP coverageMCP, LLM-linked APIsAgents, MCP, modelsNot documentedSeparate productAWS-only AI plansNew in 2025
Pricing modelQuote; unit unpublishedPer API-call volumeNot publishedEnterprise add-onCustom subscriptionFree tier, then quote
Published entry priceNone; free assessment$100,000 a yearNot publishedNot publishedFree: 500K requestsFree testing tier
Scale and bigger tiers6B calls at Commerzbank$250,000 for 100MNot publishedNetwork-scale edgeThree users on freeYoung, small vendor
IntegrationsSIEM, ITSM, CMDB, WAAPGateways, F5, SplunkWAFs, CI, ITSM, WizCloudflare dashboardEdge ConnectorCI/CD pipelines
India dataOn-prem for in-countryHybrid keeps payloadsRedact, or go on-premData Localization SuiteUS1 or EU cloud onlyindia-1 region
Lock-in and exitNo Akamai edge neededSits beside any stackTied into HarnessNeeds Cloudflare proxySelf-host the nodesSmall-vendor risk
Best fitLarge, mixed API estatesRuntime-first estatesHarness CI/CD shopsAll-in on CloudflareTry before buyingDev-first, India region
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Akamai API Security if…

  • ✓Your APIs sit behind more than one CDN, WAF or gateway and you need one inventory that does not depend on any of them
  • ✓You want discovery, CI/CD testing and runtime detection on the same endpoint records, mapped to PCI DSS, HIPAA and NIST
  • ✓AI agents and MCP servers are appearing in your estate and you want them catalogued with the rest of your APIs

Compare alternatives if…

  • ✓You want blocking inside the API tool itself — Traceable by Harness and Wallarm enforce policy in their own platforms
  • ✓You need a figure before a sales call — Salt lists prices on AWS Marketplace and Wallarm and Levo have free tiers
  • ✓Indian data residency must be a SaaS region, not your own servers — Levo’s india-1 or Cloudflare’s Data Localization Suite

Do not expect…

  • ✓A public price list or a published licensing unit
  • ✓Inline blocking without a WAAP, gateway or other enforcement point connected
  • ✓A documented Indian SaaS region for the analysis dashboard

TechBag has no API security guide yet, so Akamai API Security sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What does chasing unknown APIs cost you?

Drag the sliders (APIs in your estate; AppSec-hour cost). Estimates model the security team’s time spent tracking down undocumented endpoints, reviewing API changes and assembling audit evidence at an assumed 1.5 hours per API a year, with 70% of it removed by an automated inventory, pipeline tests and mapped findings. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual API-security effort
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Akamai prints no price or licensing unit for API Security, and every Akamai security product is quote-only. The first step is a free, nonintrusive attack-surface assessment of your exposed APIs. Customers already on Akamai’s edge can feed traffic through a native connector Akamai said in 2024 carries no ongoing cost. TechBag gets the unit and term in writing, then quotes in INR with GST.

Free assessment

Best for sizing the problem first

  • Nonintrusive scan of exposed APIs
  • Public-facing assets listed
  • No deployment needed

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Akamai API Security

Best for large, mixed API estates

  • Quote-only; unit not published
  • SaaS, hybrid or on-premises
  • Discovery, posture, testing, runtime

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Traffic sources

Which CDNs, WAFs, gateways and clouds carry your API traffic, and can each send a copy out of band?

2
Deployment

Is SaaS analysis acceptable, or do regulators and the data owner need the hybrid or on-prem option?

3
Code access

Will repositories and OpenAPI specs be connected, so APIs are found before they carry any traffic?

4
AI estate

Do teams run MCP servers or LLM-backed services today, and who owns them once they are found?

5
Enforcement

Which WAAP or gateway will block an abusive client the product flags, and who approves that rule?

6
Pipelines

Which CI/CD system runs the tests first, and what failure threshold stops a release?

7
Compliance

Which mappings matter — PCI DSS, HIPAA, ISO 27001, NIST — and who receives the posture reports?

8
Commercials

What is the licensing unit in the quote? Ask for INR with GST, the term, and what the assessment found.

FAQ

Questions buyers ask

It is Akamai’s product for discovering, testing, governing and protecting APIs. It builds an inventory from traffic, code, specs and cloud accounts, checks posture against frameworks such as OWASP API and PCI DSS, runs tests in CI/CD, and detects abuse and business-logic attacks in production.

Ready to evaluate Akamai API Security?

Start with the free attack-surface assessment, or let a TechBag advisor map which CDNs, WAFs and gateways should feed the inventory and where the data should live.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.