
42Crunch API Security Platform
Summary
42Crunch provides API security testing and runtime protection, and applies contract-driven governance to MCP servers used by AI agents. Its API tests are generated from OpenAPI definitions and map findings to the OWASP API Security Top 10. A runtime micro-firewall builds an allowlist from an API contract and blocks traffic not declared there, with stated sub-millisecond overhead. For MCP, the platform finds servers across registries, gateways, and repositories, then generates contracts for their advertised tools, resources, and prompts. It maps MCP security findings to NIST AI RMF, OWASP MCP Top 10, EU AI Act, ISO/IEC 42001, and CSA AICM controls. Integrations and CI/CD support span development environments, build services, and tools such as Kubernetes, Docker, Postman, and MuleSoft. Enterprise deployment options are cloud, on-premises, and hybrid. A free plan is listed; Individual costs $9 per month and Individual Pro costs $20 per month. A 14-day trial requires a corporate email and no credit card. The CI/CD documentation says GraphQL federation is unsupported in that integration, and Jenkins instructions say GraphQL scanning requires a separate subscription.
Who it is for
It suits teams securing APIs through OpenAPI-based testing and runtime traffic controls, as well as organizations governing MCP servers used by AI agents. Enterprise teams can choose cloud, on-premises, or hybrid deployment.
What is good
- Generates API tests from OpenAPI definitions.
- Maps API findings to the OWASP API Security Top 10.
- Finds MCP servers and generates contracts for advertised capabilities.
- Offers cloud, on-premises, and hybrid deployment.
- Free plan and 14-day trial are listed.
What to know first
- GraphQL federation is unsupported in CI/CD integration.
- Jenkins GraphQL scanning requires a separate subscription.
- Trial signup requires a corporate email.
Everything Xiaomi review
42Crunch API Security Platform: the full review
42Crunch combines contract-based API testing with runtime protection and MCP governance. Teams using GraphQL should note the stated CI/CD limitation and separate Jenkins scanning subscription requirement.
Overview
42Crunch API Security Platform combines API security testing with runtime protection. Its approach centers on API contracts: OpenAPI definitions drive security checks, while the contract also informs runtime traffic controls. The platform extends this contract-based governance to MCP servers used by AI agents.
Its listed capabilities include API discovery, API posture management, sensitive data detection, and specification governance. For APIs, it generates static and dynamic tests from OpenAPI definitions and maps findings to the OWASP API Security Top 10. At runtime, a micro-firewall builds an allowlist from the API contract and blocks traffic that is not declared there; 42Crunch states that this operates with sub-millisecond overhead.
For MCP, the platform discovers servers across registries, gateways, and repositories, then generates contracts for their advertised tools, resources, and prompts. Security findings can be mapped to NIST AI RMF, OWASP MCP Top 10, the EU AI Act, ISO/IEC 42001, and CSA AICM controls.
Key features
- OpenAPI-based security testing: Static and dynamic tests use API definitions as their basis, with findings organized against the OWASP API Security Top 10.
- Runtime micro-firewall: Contract-derived allowlisting is used to block undeclared traffic. The stated overhead is sub-millisecond.
- MCP server discovery: The platform searches registries, gateways, and repositories for MCP servers and creates contracts covering their advertised tools, resources, and prompts.
- MCP compliance mapping: Findings can be related to a range of AI, security, and governance frameworks, including NIST AI RMF, the EU AI Act, and ISO/IEC 42001.
- Development workflow integrations: Named technology partners include Visual Studio Code, IntelliJ, Eclipse, Bitbucket, Bamboo, GitHub, GitLab, Jenkins, Microsoft Azure, Azure Sentinel, SonarQube, Kubernetes, Docker, Postman, and MuleSoft.
- Security and privacy commitments: 42Crunch says it is ISO/IEC 27001 certified, with controls covering areas such as risk assessment, access, encryption, monitoring, and business continuity. It also says it commits to applicable privacy laws including GDPR, CCPA, UK GDPR, and Australia's APPs.
Pricing
42Crunch offers a free plan, paid individual plans, and enterprise pricing on request. The free trial lasts 14 days, requires a corporate email address, and does not require a credit card.
| Plan | Price | Included |
|---|---|---|
| Free | 0.00 USD per free | AI coding plugin, OpenAPI audit, vulnerability scans, automatic fixes, and enough tokens to try the product. |
| Individual | 9.00 USD per month (billed $9 / month) | 1,000 security tokens/month, 1 user, coding agents, API scans, IDE integration, email support, and extra tokens at +$0.03 per token. |
| Individual Pro | 20.00 USD per month (billed $20 / month) | 3,000 security tokens/month, 1 user, coding agents, API scans, IDE integration, community support, and extra tokens at +$0.025 per token. |
| Enterprise | Price not listed | Scoped to APIs, MCP servers, and users; dedicated encrypted tenant, SSO, unlimited context, dedicated support manager, and cloud, on-premises, or hybrid deployment. |
Platforms
Listed platforms are API, extension, Linux, macOS, self-hosted, web, and Windows. Enterprise deployment options include cloud, on-premises, and hybrid.
CI/CD documentation names Azure Pipelines, Bamboo, Bitbucket Pipelines, GitHub Actions, GitLab Pipelines, Jenkins, and Tekton, as well as a generic Docker image for REST API static security testing. IDE integration documentation names Visual Studio Code, JetBrains IDEs, Eclipse, and Microsoft Visual Studio.
There are specific GraphQL constraints to note: GraphQL federation is not supported in CI/CD integration, and Jenkins instructions say GraphQL scanning requires a separate subscription.
Who it's for
42Crunch is aimed at teams that define APIs with OpenAPI and want security checks tied to those definitions, along with runtime controls based on the same contracts. Its MCP discovery and governance features may also suit organizations overseeing MCP servers used by AI agents. The plan structure ranges from a free option and single-user subscriptions to enterprise deployments scoped to APIs, MCP servers, and users.
Pros and cons
Pros
- OpenAPI definitions inform both generated security tests and runtime allowlisting.
- Findings map to named API and AI governance frameworks.
- CI/CD and IDE integrations cover several commonly used development tools.
- Enterprise deployment choices include cloud, on-premises, and hybrid.
- The trial is 14 days and does not require a credit card.
Cons
- Enterprise pricing is not listed.
- GraphQL federation is not supported in CI/CD integration.
- GraphQL scanning in Jenkins requires a separate subscription.
- Support varies by plan: email for Individual, community support for Individual Pro, and a dedicated support manager for enterprise pricing.
Alternatives
Other products to consider include Akto API Security Platform, Wallarm API Security, APISec Platform, F5 BIG-IP APM, Palo Alto Networks Cortex Cloud API Security, Cisco Panoptica, APIPosture, and Onam Security API Security.
Verdict
42Crunch stands out for linking OpenAPI-based testing and runtime traffic controls, while extending contract governance to MCP server discovery. The listed free and individual plans provide clear entry points, although enterprise pricing is undisclosed. Teams with GraphQL workflows should account for the stated CI/CD and Jenkins limitations.
Explore the API Security Software and API Security Testing Software categories for more options.
42Crunch API Security Platform plans and pricing
All plansCompared on API security software
- Free plan
- No42crunch.com
- API discovery
- Yes42crunch.com
- Runtime protection
- Yes42crunch.com
- API posture management
- Yes42crunch.com
- Sensitive data detection
- Yes42crunch.com
- Specification governance
- Yes42crunch.com
- Deployment model
- hybrid42crunch.com
Facts
- Purpose
- 42Crunch provides API security testing and runtime protection and extends its contract-driven governance to MCP servers used by AI agents.42crunch.com · 30 Sept 2026
- API testing
- Its API security testing uses static and dynamic tests generated from OpenAPI definitions and maps findings to the OWASP API Security Top 10.42crunch.com · 30 Sept 2026
- MCP discovery
- The platform discovers MCP servers across registries, gateways, and repositories and generates contracts for their advertised tools, resources, and prompts.42crunch.com · 30 Sept 2026
- Compliance
- The platform maps MCP security findings to NIST AI RMF, OWASP MCP Top 10, EU AI Act, ISO/IEC 42001, and CSA AICM controls.42crunch.com · 30 Sept 2026
- Integrations
- The maker lists Visual Studio Code, IntelliJ, Eclipse, Bitbucket, Bamboo, GitHub, GitLab, Jenkins, Microsoft Azure, Azure Sentinel, SonarQube, Kubernetes, Docker, Postman, and MuleSoft as technology partners.42crunch.com · 30 Sept 2026
- CI/CD support
- The platform's CI/CD documentation lists Azure Pipelines, Bamboo, Bitbucket Pipelines, GitHub Actions, GitLab Pipelines, Jenkins, Tekton, and a generic Docker image for REST API static security testing.docs.42crunch.com · 30 Sept 2026
- IDE support
- The IDE integration documentation names Visual Studio Code, JetBrains IDEs, Eclipse, and Microsoft Visual Studio.docs.42crunch.com · 30 Sept 2026
- Security certification
- 42Crunch states that it is ISO/IEC 27001 certified and describes controls covering vulnerability and incident management, risk assessment, access control, encryption, continuous monitoring, and business continuity.42crunch.com · 30 Sept 2026
- Privacy
- The company says it commits to applicable privacy laws including GDPR, CCPA, UK GDPR, and Australia's APPs.42crunch.com · 30 Sept 2026
- Deployment
- Enterprise deployment options listed by the maker are cloud, on-premises, and hybrid.42crunch.com · 30 Sept 2026
- Support
- The Individual plan includes email support, Individual Pro includes community support, and enterprise pricing includes a dedicated support manager.42crunch.com · 30 Sept 2026
- Trial terms
- The free trial signup page says the 14-day trial requires a corporate email and no credit card.42crunch.com · 30 Sept 2026
- Notable limitation
- The CI/CD documentation says GraphQL federation is not supported in CI/CD integration, and the Jenkins instructions state GraphQL scanning requires a separate subscription.docs.42crunch.com · 30 Sept 2026
- Company
- The current website identifies the company as 42Crunch Ltd. and its leadership page names Jacques Declas and Philippe Leothaud as co-founders.42crunch.com · 30 Sept 2026
Company
- Headquarters
- London, United Kingdom42crunch.com · 28 Sept 2026
Best 42Crunch API Security Platform alternatives
See all 12Where it ranks on Everything Xiaomi
Is 42Crunch API Security Platform yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- 42crunch.com/platform-overview.html· checked 30 Sept 2026
- 42crunch.com/partners.html· checked 30 Sept 2026
- docs.42crunch.com/latest/content/tasks/integrate_ci_cd_wi· checked 30 Sept 2026
- docs.42crunch.com/latest/content/concepts/ide_integration· checked 30 Sept 2026
- 42crunch.com/why-trust-42crunch.html· checked 30 Sept 2026
- 42crunch.com/pricing.html· checked 30 Sept 2026
- 42crunch.com/upgrade_subscription.html· checked 30 Sept 2026
- 42crunch.com/freemium.html· checked 30 Sept 2026
- 42crunch.com/leadership.html· checked 30 Sept 2026
- 42crunch.com· checked 28 Sept 2026


