Skip to content
Browser-local-first · EU-built · audited boundaries

One workbench for the API lifecycle, with boundaries you can inspect.

Design, mock, map, test and govern APIs in a keyboard-driven workbench. Workspace state is browser-local by default; explicit and configured remote operations are disclosed in the Trust manifest.

No account or installation is required. The demo workspace includes bundled TMF examples; exact inventory, version and licence provenance remain under release audit. Browser storage is not application-level encrypted at rest.

20modules — one lifecycle
ExamplesTMF examples · inventory under release audit
11audited outbound and browser-boundary records
trust manifest — audited boundariesverify the record set

$ Open the Trust Center.
> Audited outbound and browser-boundary records: 11. Explicit, configured and host-conditional paths are disclosed.

Browser-local workspace by defaultManifest-backed boundary disclosureNo required vendor account
The workbench

Eight modules deep, one keyboard away.

Mapped 1:1 to what ships in the app today — nothing on this grid is a mock-up of the future.

Catalog \ ImportImport that audits your specPull OpenAPI/Swagger from file, URL, SwaggerHub or Postman collections. The weakness classifier flags missing enums, absent examples and vague descriptions before they become integration bugs.Import a specAPI ExplorerAn explorer that knows your schemaAuth auto-detected from the spec. Requests validated against the schema before they leave. Mock responses per status code, and spec watch that diffs upstream changes.Open ExplorerMapping Studio · ReviewsMapping is a first-class citizenMap fields across APIs with live preview and a transform engine. Reviews gate every change; production locks mean only owners touch what is live.Open Mapping StudioMock ForgeMocks with a memoryForge mock artefacts per endpoint and status, then drive whole scenarios against them — happy paths, failures, malformed JSON and rate-limit cases included.Forge a mockPrevalidation · ExecutionTraces, not guessesRule-based prevalidation gates the call; the Execution Console records every step as a trace. When a call fails you read the trace, not the tea leaves.Run an executionGateway SmokeGateway hand-off, smoke-testedExport gateway config as vendor-neutral JSON or Kong declarative YAML, then smoke-test it in place — before a deploy window does it for you.Export configScheduled RunsBrowser-open scheduled rehearsalsRecurring scenario runs use the open browser runtime. Background throttling, sleep or closing the tab can pause execution; this is not a hosted 24/7 runner.Schedule a runAudit Log · Schema DiffAudit that writes your evidenceEvery governance action lands in an append-only audit log. Schema-diff impact reports export to PDF for the evidence file.Open the audit log
How it works

Spec to gateway in three moves.

01
Import

Drop an OpenAPI or Swagger file, or pull from URL, SwaggerHub or a Postman collection. The weakness report scores what you received before you build on it.

02
Rehearse

Forge mocks, author scenarios from data packs and the error library, map fields across APIs, and run everything with prevalidation and step-by-step traces.

03
Hand off

Export gateway configuration as JSON or Kong YAML, smoke-test it, schedule browser-open runs and keep the audit trail as review evidence.

Trust boundaries, documented

Browser-local by default, with every audited boundary visible.

APIMaster Integration Workbench stores application-managed workspace state in the current browser profile by default. Explicit API, URL import, GraphQL, realtime and Companion actions can contact destinations the user selects; configured webhooks can transmit summaries while the browser runtime is active. The host-provided error callback remains an unresolved deployment boundary, disclosed in the Trust manifest.

  • Workspace state is browser-local by default
  • 11 audited outbound and browser-boundary records
  • Encrypted bundle export is separate from localStorage at-rest protection
TMF / Telco

Start TMF contract exploration from bundled examples.

Bundled TM Forum Open API examples can be imported into the local catalogue and explored with the existing mapping tools. Exact inventory, version and licence provenance remain a release-audit gate; this catalogue does not imply certification or official endorsement.

Product ordering exampleService ordering exampleTrouble ticket exampleCustomer exampleParty exampleAdditional bundled examples
Owner-approved proposal

Requestable ContractRadar 14-day pilot

The owner-approved requestable proposal covers an indicative 10–50 contracts over 14 days, using existing local engines and evidence exports. Scope and price are confirmed separately; no fee, customer or outcome is guaranteed here.

Create pilot Pilot scope is owner-approved, but the APIMaster sales mailbox is UNVERIFIED/HOLD and the public mail action remains disabled until delivery is proved.Review enterprise capability truth
FAQ

The questions reviews actually ask.

Engineering answers — the same ones we give your security and procurement teams.