Cloud Shield / API Security
Bring your API surface into view.
An API inventory gives your team a clearer starting point for protection. Cloud Shield brings API discovery, scans and endpoint organization into the same application context as your CDN and security policies.
Capabilities
API Security in practice.
API discovery
Review discovered API endpoints associated with the protected domain and use that inventory to understand the application surface.
Endpoint organization
Work with endpoint groups to organize related parts of your API and keep the inventory easier to review.
API protection controls
Use the available API-specific controls alongside managed policies and custom rules for the protected application.
Configuration & visibility
Connect inventory with protection.
Review the endpoints your application exposes and the security controls that apply to their traffic.
- Discovered endpoints
- Inspect the API endpoints visible to Cloud Shield for your protected domain.
- Discovery scans
- Review available scans and their status as you maintain the application inventory.
- Endpoint groups
- Organize endpoints into groups that reflect the structure of your application.
- Security context
- Investigate requests through Cloud Shield analytics and use policy or rule controls to address the traffic you find.
How it works
Build an inventory you can act on.
- 01
Enable API Security
Use the Business plan and arrange activation of the separately priced API Security add-on.
- 02
Review discovery
Inspect the discovered endpoints and scan information for the protected application.
- 03
Organize and protect
Review endpoint groups, configure supported protection controls and revisit the inventory as your API changes.
Optional add-on for Business. Priced separately. Compare plans
Frequently asked questions
API Security is a separately priced Business add-on. It is not included in the Business base price or available on Basic and Advanced.
API discovery is available in the API Security area of a protected domain after the capability has been enabled.
Cloud Shield uses the existing Cloud CDN distribution. The API must be delivered through the protected distribution so its traffic reaches Cloud Shield.
Explore Cloud Shield