API Security Built for Developers
Drop in G8KEPR and get SQL injection protection, rate limiting, JWT validation, and 85,000+ threat patterns across 24 categories blocked automatically. No security expertise required.
Security that gets out of your way so you can focus on building
Every API you ship is a potential attack surface. But you shouldn't need a security degree to protect it. G8KEPR gives you enterprise-grade security that works out of the box.
POST /api/usersSQL injection blockedJWT verified automatically1000 req/min defaultYour API is live. Users are signing up. And attackers are probing every endpoint. Here's what they're trying:
Three deployment options — choose what works for your stack
85,000+ threat patterns across 24 categories blocked out of the box — zero configuration
GET /api/users?id=1; DROP TABLE users;--POST /api/comments body: {text: "<script>..."}GET /api/admin -H "Authorization: Bearer [tampered]"POST /api/login (10,000 attempts, brute force)Security that integrates with how you already build
SQL injection, XSS, CSRF, and 85,000+ threat patterns across 24 categories blocked automatically. No rules to write. No policies to configure.
85,000+ attack patternsInstall SDK, wrap your app, done. Works with FastAPI, Flask, Express, NestJS, Gin, and every major framework.
3 lines of codePoint G8KEPR at your OpenAPI spec. Auto-generate security policies, validate schemas, and document coverage.
Swagger 3.0 supportTest in production without blocking traffic. Shadow mode logs threats and validates policies without enforcement.
Zero-risk testingIntelligent defaults that protect your API from abuse without blocking legitimate users. Per-IP, per-key, per-endpoint.
Adaptive thresholdsBuilding AI features? Route LLM requests through G8KEPR for cost tracking, automatic failover, and unified billing.
Claude, GPT-4, GeminiSame protection on every endpoint, MCP tool call, and LLM proxy. Target: Sub-5ms gateway proxy overhead on cached, single-region paths.
Not in Anthropic's MCP spec. Not in API gateways. Not in WAFs. Platform-level additions you can drop in with three lines of code.
Subprocess MCP tools execute inside a hardened Linux sandbox. RLIMIT_CPU/AS/NOFILE/NPROC, setsid() process-group isolation, capability dropping, per-tool egress filtering, and shell binaries removed.
SHA-256 hash of every tool definition pinned at tools/list. On every tools/call, the cached definition is re-hashed and compared. Drift raises MCPRugPullDetectedError, blocks execution, publishes a CRITICAL event.
Statistical, not threshold-based. Z-score > 3.0 against per-hour time-of-day baselines. 4 overlapping sliding windows (1m/5m/15m/1h). Progressive recovery (10→25→50→100%).
Every event linked across all four pillars via shared correlation ID. One query: "Show me everything that happened from request X — across MCP + API + Gateway + Verification." Architecturally impossible when layers are separate products.
SHA-256 genesis block, each entry signing the previous. Three verification levels (full / single / last-N). Tamper-evident — exportable for SOC 2 audit observation, customer attestations, and incident forensics.
Cross-session attack detection: 6-dimension risk score (max 110) across tool sensitivity, data volume, burst, denials, prior detections, and tool diversity. Catches coordinated attacks and 24h slow-and-low patterns.
A single user request traces forward to the AI agent it spawned, the downstream API call, and the verification check that caught any drift — all under one correlation ID.
mcp_contexts for parent-child replay • Causal chain reconstruction in one query • Hash-chain entries are tamper-evidentOfficial SDKs for every major language and framework
Your customers ask for SOC 2 evidence, you have it. Cross-framework sync means a SOC 2 control automatically contributes evidence toward GDPR and ISO 27001 where they overlap — no duplicate work.
"-Ready" / "aligned" reflect capability posture. SOC 2 Type II observation in progress with external audit H2 2026. PCI DSS certification requires a Qualified Security Assessor (QSA) engagement on the customer's side.
Common questions from developers getting started
Need help getting started?
Read the full documentation →Free tier with 10,000 requests/month. No credit card required.
No credit card required • Free forever tier • Full feature access