Akto Integration with DefectDojo
Akto Integration with DefectDojo
Akto is an API security platform that builds an inventory of an organization's APIs, groups them into collections, and runs security tests against each endpoint, such as checks for broken object level authorization (BOLA). It is available as a SaaS platform and as a self-hosted deployment. DefectDojo imports Akto issues from a JSON export of the fetchIssuesFromCollections response, or pulls them directly with the DefectDojo Pro Akto connector.
Akto Integration with DefectDojo
We use Akto because our API surface grew faster than anyone could review it by hand, and Akto keeps testing every endpoint it knows about. The issue list it produces is long, and much of it belongs to different teams. Bringing Akto into DefectDojo turns each failed test on each endpoint into a Finding under the right Asset, with the method and path as the component, Akto's triage status carried over, and the same SLAs and reporting we apply to web and code findings.
Why Akto Matters
APIs expose business logic directly, and many of the worst API flaws are authorization problems that code scanners and generic web scanners miss.
- Akto runs its tests against live endpoints, which catches issues that only show up when a request is actually made.
- It tests every endpoint in a collection, so new routes get covered without someone writing a test plan for each one.
- Its tests map to CWE identifiers where available, which makes API findings comparable with the rest of an application's results.
- The same test failing on many endpoints creates a lot of rows. Those rows need owners, deadlines, and history, which is the job of a vulnerability management platform.
Advantages of This Integration
- Endpoint-level precision. The unique ID is
akto-<collection>-<method>-<url>-<test sub-category>, so the same test on two paths is two findings, and two tests on one path are two findings. - Triage carried over. Issues marked
IGNOREDin Akto import as inactive false positives.FIXEDissues import as inactive but are not flagged as false positives, since being fixed says nothing about whether the issue was real. - One identity for file and API data. The parser mirrors the Pro connector under the scan type
Akto Scan, so file imports and connector Syncs deduplicate against each other. - Useful filtering. Akto's test category and test tags become DefectDojo tags, so teams can filter by class of issue.
- Standard workflow. Findings get SLAs by severity, assignment, Jira pushes, risk acceptance, and metrics alongside every other tool.
How This Integration Works
Option 1: File import. This path is for teams that can't grant DefectDojo Akto API credentials. Save the JSON response of Akto's fetchIssuesFromCollections call. The parser reads issues from issueDetails and also accepts a bare array of issues.
In the UI, open an Engagement, choose Import Scan Results, select Akto Scan, and upload the file. For automation, use the API in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Akto Scan"
-F "file=@akto-issues.json"
-F "product_name=orders-api"
-F "engagement_name=Akto API Testing"
-F "auto_create_context=true"
DefectDojo Pro users can run Universal Importer from a pipeline:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Akto Scan"
--report-path "./akto-issues.json"
--product-name "orders-api"
--engagement-name "Akto API Testing"
--auto-create-context
Option 2: Akto connector (DefectDojo Pro). Create an Akto API key under Settings, Integrations, Akto APIs in the Akto dashboard. In the DefectDojo Pro UI, add the Akto connector, enter https://app.akto.io as the Location for Akto SaaS (or your own dashboard URL if you self-host), paste the API key, and optionally set a Minimum Severity. The connector creates a Record for each Akto API collection and imports only open issues, so issues resolved in Akto are reflected in DefectDojo on the next Sync.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Akto Issue | Notes |
|---|---|---|
| Title | testName |
Falls back to testSubCategory, then a generic label |
| Severity | severity |
CRITICAL, HIGH, MEDIUM, LOW map directly; INFO or unrecognized is Info; case-insensitive |
| Date | creationTime |
Unix seconds; zero keeps the import date |
| Description | Endpoint, testDescription, testImpact, testDetails |
Labeled lines |
| Mitigation | testRemediation |
Copied as text |
| References | issueUrl, then testReferences |
Akto issue link first |
| Component Name | apiMethod and apiUrl |
Formatted as <METHOD> <url> |
| CWE | testCwe |
Reads CWE-639 or 639; otherwise unset |
| Vulnerability IDs | testCve |
CVE, GHSA, GO, and RHSA IDs extracted and deduplicated |
| Unique ID from Tool | Collection, method, URL, test sub-category | One finding per endpoint per test |
| Vuln ID from Tool | testSubCategory |
Akto's test identity |
| Endpoint | apiUrl |
Only when it is an absolute URL with a valid host |
| Tags | testCategory, testTags |
For filtering |
| Active / False Positive | status |
IGNORED: inactive false positive. FIXED: inactive |
| Finding type | Dynamic | Tests run against a live API |
| Deduplication | Unique ID or hashcode | Unique ID from tool, falling back to title, severity, endpoints, vuln_id_from_tool |
Use Cases
Continuous API testing: Akto tests collections on its own schedule, and the Pro connector syncs open issues into DefectDojo. Product teams work API findings in the same queue as their SAST and SCA results, with Jira tickets created from DefectDojo.
Authorization reviews: A security engineer filters findings by Akto test category to review every BOLA-style issue across services, then assigns each one to the owner of the affected collection.
Restricted environments: A self-hosted Akto deployment sits in a network segment DefectDojo can't reach. The team exports issues to JSON on a schedule and imports the file, keeping the same scan type the connector would use.
Release tracking: Reimporting after each release shows which API issues were fixed, which are new, and which came back, per endpoint.
Operational Tips
- Akto's
apiUrlis often a relative path such as/v1/reports. The parser records an endpoint only for absolute URLs. The path still appears as the component and in the description. - Endpoints are one of the four hashcode fields. When an export carries only relative paths, the unique ID (which includes the method and path) does most of the matching work, so keep exports and connector Syncs feeding the same Asset.
- Mark false positives in Akto as
IGNOREDbefore export. They arrive in DefectDojo already flagged, which keeps triage in one place. - Use one Test per Akto collection and reimport into it, so fixed issues are mitigated and the history stays readable.
- Set
minimum_severityon file imports, or the connector's Minimum Severity, to start with Critical and High issues while teams get used to the volume. - Use the tags from Akto's test category to build SLA or reporting views by issue class.