All integrations

Akto Integration with DefectDojo

Akto Integration with DefectDojo

Akto is an API security platform that builds an inventory of an organization's APIs, groups them into collections, and runs security tests against each endpoint, such as checks for broken object level authorization (BOLA). It is available as a SaaS platform and as a self-hosted deployment. DefectDojo imports Akto issues from a JSON export of the fetchIssuesFromCollections response, or pulls them directly with the DefectDojo Pro Akto connector.

Akto Integration with DefectDojo

We use Akto because our API surface grew faster than anyone could review it by hand, and Akto keeps testing every endpoint it knows about. The issue list it produces is long, and much of it belongs to different teams. Bringing Akto into DefectDojo turns each failed test on each endpoint into a Finding under the right Asset, with the method and path as the component, Akto's triage status carried over, and the same SLAs and reporting we apply to web and code findings.

Why Akto Matters

APIs expose business logic directly, and many of the worst API flaws are authorization problems that code scanners and generic web scanners miss.

  • Akto runs its tests against live endpoints, which catches issues that only show up when a request is actually made.
  • It tests every endpoint in a collection, so new routes get covered without someone writing a test plan for each one.
  • Its tests map to CWE identifiers where available, which makes API findings comparable with the rest of an application's results.
  • The same test failing on many endpoints creates a lot of rows. Those rows need owners, deadlines, and history, which is the job of a vulnerability management platform.

Advantages of This Integration

  • Endpoint-level precision. The unique ID is akto-<collection>-<method>-<url>-<test sub-category>, so the same test on two paths is two findings, and two tests on one path are two findings.
  • Triage carried over. Issues marked IGNORED in Akto import as inactive false positives. FIXED issues import as inactive but are not flagged as false positives, since being fixed says nothing about whether the issue was real.
  • One identity for file and API data. The parser mirrors the Pro connector under the scan type Akto Scan, so file imports and connector Syncs deduplicate against each other.
  • Useful filtering. Akto's test category and test tags become DefectDojo tags, so teams can filter by class of issue.
  • Standard workflow. Findings get SLAs by severity, assignment, Jira pushes, risk acceptance, and metrics alongside every other tool.

How This Integration Works

Option 1: File import. This path is for teams that can't grant DefectDojo Akto API credentials. Save the JSON response of Akto's fetchIssuesFromCollections call. The parser reads issues from issueDetails and also accepts a bare array of issues.

In the UI, open an Engagement, choose Import Scan Results, select Akto Scan, and upload the file. For automation, use the API in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Akto Scan" 
  -F "file=@akto-issues.json" 
  -F "product_name=orders-api" 
  -F "engagement_name=Akto API Testing" 
  -F "auto_create_context=true"

DefectDojo Pro users can run Universal Importer from a pipeline:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Akto Scan" 
  --report-path "./akto-issues.json" 
  --product-name "orders-api" 
  --engagement-name "Akto API Testing" 
  --auto-create-context

Option 2: Akto connector (DefectDojo Pro). Create an Akto API key under Settings, Integrations, Akto APIs in the Akto dashboard. In the DefectDojo Pro UI, add the Akto connector, enter https://app.akto.io as the Location for Akto SaaS (or your own dashboard URL if you self-host), paste the API key, and optionally set a Minimum Severity. The connector creates a Record for each Akto API collection and imports only open issues, so issues resolved in Akto are reflected in DefectDojo on the next Sync.

Data Granularity: What Gets Imported

DefectDojo Field Source in Akto Issue Notes
Title testName Falls back to testSubCategory, then a generic label
Severity severity CRITICAL, HIGH, MEDIUM, LOW map directly; INFO or unrecognized is Info; case-insensitive
Date creationTime Unix seconds; zero keeps the import date
Description Endpoint, testDescription, testImpact, testDetails Labeled lines
Mitigation testRemediation Copied as text
References issueUrl, then testReferences Akto issue link first
Component Name apiMethod and apiUrl Formatted as <METHOD> <url>
CWE testCwe Reads CWE-639 or 639; otherwise unset
Vulnerability IDs testCve CVE, GHSA, GO, and RHSA IDs extracted and deduplicated
Unique ID from Tool Collection, method, URL, test sub-category One finding per endpoint per test
Vuln ID from Tool testSubCategory Akto's test identity
Endpoint apiUrl Only when it is an absolute URL with a valid host
Tags testCategory, testTags For filtering
Active / False Positive status IGNORED: inactive false positive. FIXED: inactive
Finding type Dynamic Tests run against a live API
Deduplication Unique ID or hashcode Unique ID from tool, falling back to title, severity, endpoints, vuln_id_from_tool

Use Cases

Continuous API testing: Akto tests collections on its own schedule, and the Pro connector syncs open issues into DefectDojo. Product teams work API findings in the same queue as their SAST and SCA results, with Jira tickets created from DefectDojo.

Authorization reviews: A security engineer filters findings by Akto test category to review every BOLA-style issue across services, then assigns each one to the owner of the affected collection.

Restricted environments: A self-hosted Akto deployment sits in a network segment DefectDojo can't reach. The team exports issues to JSON on a schedule and imports the file, keeping the same scan type the connector would use.

Release tracking: Reimporting after each release shows which API issues were fixed, which are new, and which came back, per endpoint.

Operational Tips

  • Akto's apiUrl is often a relative path such as /v1/reports. The parser records an endpoint only for absolute URLs. The path still appears as the component and in the description.
  • Endpoints are one of the four hashcode fields. When an export carries only relative paths, the unique ID (which includes the method and path) does most of the matching work, so keep exports and connector Syncs feeding the same Asset.
  • Mark false positives in Akto as IGNORED before export. They arrive in DefectDojo already flagged, which keeps triage in one place.
  • Use one Test per Akto collection and reimport into it, so fixed issues are mitigated and the history stays readable.
  • Set minimum_severity on file imports, or the connector's Minimum Severity, to start with Critical and High issues while teams get used to the volume.
  • Use the tags from Akto's test category to build SLA or reporting views by issue class.