Live Demo: Bolt, MCP Audit & Automated API Testing | Jesse Freeman & Dan Barahona
In this intermission session from APISECCON 2026, APISEC Product Implementation Engineer Jesse Freeman demos the full suite of tools the APISEC team has been building — live and unscripted. First up is Web Bolt, APISEC's free browser extension (available on Chrome and Firefox). Jesse shows how it captures API traffic directly from your browser without a proxy setup, organizes endpoints, and flags potential BOLA targets — then demonstrates the Manipulator tool, which lets you modify parameters and replay requests right in the browser. Think lightweight Burp Suite with one click, no proxy configuration required. Next is MCP Audit, APISEC's open-source tool for scanning GitHub repositories to discover which MCP servers your developers are already using — and whether any of them carry risk flags like file system access, shell access, or database access. This is the tool that answers the #1 question security teams are asking right now: "What MCPs are we actually running?" Jesse then previews Code Bolt, a CLI tool that analyzes your code repositories (currently supporting Python and Java frameworks including Spring Boot, FastAPI, and others) and auto-generates OpenAPI specifications from them — enabling you to onboard previously undiscovered endpoints directly into APISEC for testing. The session closes with a walkthrough of the APISEC automated testing platform itself: how it builds an app model from your OAS, infers sensitive parameters, configures auth flows, and runs comprehensive attack scenarios covering unauthenticated access, BOLA, rate limiting, role-based access control, and more. 🔗 Try the tools: Browser Bolt (Chrome): https://chromewebstore.google.com/det... Browser Bolt (Firefox): https://addons.mozilla.org/en-US/fire... MCP Audit (open source): https://apisec-inc.github.io/mcp-audit/ APISEC platform (free tier): https://apisec.ai #APISecurity #APISEC #BrowserExtension #MCP #APITesting #DAST #APISECCON

What makes a secure SDLC? | AppSec 101

Attacking AI - Jason Haddix - NDC Security 2026

AI First Engineering Native Agentic Course Demo video on 15th June 2026. +91-9133190573 to enroll.

Model Context Protocol (MCP) Explained for Beginners: AI Flight Booking Demo!

My First API Bug Bounty Bugs: GraphQL & Broken Access Control | Abraham Gonzalez

Why Your IoT Devices Are More Exposed Than You Think

Harnesses in AI: A Deep Dive — Tejas Kumar, IBM

MCP Security Fundamentals Workshop 12 2025

Is Bug Bounty Dead? How AI Changed Security Research Forever | Dr. Katie Paxton-Fear

AI Agents Are Eating APIs: Security in the Agentic Era | Darren Schulsky

How Meta Went From Open Source Hero to AI's Biggest Villain

How Generative AI Uses APIs: A Developer's Mental Model | Ryan Day

Why The Best Software Engineers Focus On System Design

MCP Security Fundamentals Launch

Full Walkthrough: Workflow for AI Coding — Matt Pocock

Become Cloud Security Engineer FASTER

May 2026 Ottawa Salesforce User Group - COPADO - Salesforce Testing Works Better With Context

SecDevOps for API Security: Shift-Left with BDD + DDD (w/ Iwan Eising)

Powering Up Django Development With Claude Code

