The 42Crunch API Security Platform homepage

42Crunch API Security Platform

Score7.3
Rank#1 of 28
From$9/mo
Free planYes
Free trialYes
Runs onAPI, Browser extension, Linux, macOS, Self-hosted, Web, Windows

Summary

42Crunch provides API security testing and runtime protection, and applies contract-driven governance to MCP servers used by AI agents. Its API tests are generated from OpenAPI definitions and map findings to the OWASP API Security Top 10. A runtime micro-firewall builds an allowlist from an API contract and blocks traffic not declared there, with stated sub-millisecond overhead. For MCP, the platform finds servers across registries, gateways, and repositories, then generates contracts for their advertised tools, resources, and prompts. It maps MCP security findings to NIST AI RMF, OWASP MCP Top 10, EU AI Act, ISO/IEC 42001, and CSA AICM controls. Integrations and CI/CD support span development environments, build services, and tools such as Kubernetes, Docker, Postman, and MuleSoft. Enterprise deployment options are cloud, on-premises, and hybrid. A free plan is listed; Individual costs $9 per month and Individual Pro costs $20 per month. A 14-day trial requires a corporate email and no credit card. The CI/CD documentation says GraphQL federation is unsupported in that integration, and Jenkins instructions say GraphQL scanning requires a separate subscription.

Who it is for

It suits teams securing APIs through OpenAPI-based testing and runtime traffic controls, as well as organizations governing MCP servers used by AI agents. Enterprise teams can choose cloud, on-premises, or hybrid deployment.

What is good

  • Generates API tests from OpenAPI definitions.
  • Maps API findings to the OWASP API Security Top 10.
  • Finds MCP servers and generates contracts for advertised capabilities.
  • Offers cloud, on-premises, and hybrid deployment.
  • Free plan and 14-day trial are listed.

What to know first

  • GraphQL federation is unsupported in CI/CD integration.
  • Jenkins GraphQL scanning requires a separate subscription.
  • Trial signup requires a corporate email.

Everything Xiaomi review

42Crunch API Security Platform: the full review

42Crunch combines contract-based API testing with runtime protection and MCP governance. Teams using GraphQL should note the stated CI/CD limitation and separate Jenkins scanning subscription requirement.

Overview

42Crunch API Security Platform combines API security testing with runtime protection. Its approach centers on API contracts: OpenAPI definitions drive security checks, while the contract also informs runtime traffic controls. The platform extends this contract-based governance to MCP servers used by AI agents.

Its listed capabilities include API discovery, API posture management, sensitive data detection, and specification governance. For APIs, it generates static and dynamic tests from OpenAPI definitions and maps findings to the OWASP API Security Top 10. At runtime, a micro-firewall builds an allowlist from the API contract and blocks traffic that is not declared there; 42Crunch states that this operates with sub-millisecond overhead.

For MCP, the platform discovers servers across registries, gateways, and repositories, then generates contracts for their advertised tools, resources, and prompts. Security findings can be mapped to NIST AI RMF, OWASP MCP Top 10, the EU AI Act, ISO/IEC 42001, and CSA AICM controls.

Key features

  • OpenAPI-based security testing: Static and dynamic tests use API definitions as their basis, with findings organized against the OWASP API Security Top 10.
  • Runtime micro-firewall: Contract-derived allowlisting is used to block undeclared traffic. The stated overhead is sub-millisecond.
  • MCP server discovery: The platform searches registries, gateways, and repositories for MCP servers and creates contracts covering their advertised tools, resources, and prompts.
  • MCP compliance mapping: Findings can be related to a range of AI, security, and governance frameworks, including NIST AI RMF, the EU AI Act, and ISO/IEC 42001.
  • Development workflow integrations: Named technology partners include Visual Studio Code, IntelliJ, Eclipse, Bitbucket, Bamboo, GitHub, GitLab, Jenkins, Microsoft Azure, Azure Sentinel, SonarQube, Kubernetes, Docker, Postman, and MuleSoft.
  • Security and privacy commitments: 42Crunch says it is ISO/IEC 27001 certified, with controls covering areas such as risk assessment, access, encryption, monitoring, and business continuity. It also says it commits to applicable privacy laws including GDPR, CCPA, UK GDPR, and Australia's APPs.

Pricing

42Crunch offers a free plan, paid individual plans, and enterprise pricing on request. The free trial lasts 14 days, requires a corporate email address, and does not require a credit card.

PlanPriceIncluded
Free0.00 USD per freeAI coding plugin, OpenAPI audit, vulnerability scans, automatic fixes, and enough tokens to try the product.
Individual9.00 USD per month (billed $9 / month)1,000 security tokens/month, 1 user, coding agents, API scans, IDE integration, email support, and extra tokens at +$0.03 per token.
Individual Pro20.00 USD per month (billed $20 / month)3,000 security tokens/month, 1 user, coding agents, API scans, IDE integration, community support, and extra tokens at +$0.025 per token.
EnterprisePrice not listedScoped to APIs, MCP servers, and users; dedicated encrypted tenant, SSO, unlimited context, dedicated support manager, and cloud, on-premises, or hybrid deployment.

Platforms

Listed platforms are API, extension, Linux, macOS, self-hosted, web, and Windows. Enterprise deployment options include cloud, on-premises, and hybrid.

CI/CD documentation names Azure Pipelines, Bamboo, Bitbucket Pipelines, GitHub Actions, GitLab Pipelines, Jenkins, and Tekton, as well as a generic Docker image for REST API static security testing. IDE integration documentation names Visual Studio Code, JetBrains IDEs, Eclipse, and Microsoft Visual Studio.

There are specific GraphQL constraints to note: GraphQL federation is not supported in CI/CD integration, and Jenkins instructions say GraphQL scanning requires a separate subscription.

Who it's for

42Crunch is aimed at teams that define APIs with OpenAPI and want security checks tied to those definitions, along with runtime controls based on the same contracts. Its MCP discovery and governance features may also suit organizations overseeing MCP servers used by AI agents. The plan structure ranges from a free option and single-user subscriptions to enterprise deployments scoped to APIs, MCP servers, and users.

Pros and cons

Pros

  • OpenAPI definitions inform both generated security tests and runtime allowlisting.
  • Findings map to named API and AI governance frameworks.
  • CI/CD and IDE integrations cover several commonly used development tools.
  • Enterprise deployment choices include cloud, on-premises, and hybrid.
  • The trial is 14 days and does not require a credit card.

Cons

  • Enterprise pricing is not listed.
  • GraphQL federation is not supported in CI/CD integration.
  • GraphQL scanning in Jenkins requires a separate subscription.
  • Support varies by plan: email for Individual, community support for Individual Pro, and a dedicated support manager for enterprise pricing.

Alternatives

Other products to consider include Akto API Security Platform, Wallarm API Security, APISec Platform, F5 BIG-IP APM, Palo Alto Networks Cortex Cloud API Security, Cisco Panoptica, APIPosture, and Onam Security API Security.

Verdict

42Crunch stands out for linking OpenAPI-based testing and runtime traffic controls, while extending contract governance to MCP server discovery. The listed free and individual plans provide clear entry points, although enterprise pricing is undisclosed. Teams with GraphQL workflows should account for the stated CI/CD and Jenkins limitations.

Explore the API Security Software and API Security Testing Software categories for more options.

42Crunch API Security Platform plans and pricing

All plans
Free Free AI coding plugin · OpenAPI audit · vulnerability scans · automatic fixes · enough tokens to try the product 42crunch.com · 30 Sept 2026
Individual $9/mo $9 / month 1,000 security tokens/month · 1 user · +$0.03 per extra token · coding agents · API scans · IDE integration · email support 42crunch.com · 30 Sept 2026
Individual Pro $20/mo $20 / month 3,000 security tokens/month · 1 user · +$0.025 per extra token · coding agents · API scans · IDE integration · community support 42crunch.com · 30 Sept 2026
Enterprise Not published Scoped to APIs, MCP servers, and users · dedicated encrypted tenant · SSO · unlimited context · dedicated support manager · cloud, on-prem, or hybrid 42crunch.com · 30 Sept 2026

Compared on API security software

Free plan
No42crunch.com
API discovery
Yes42crunch.com
Runtime protection
Yes42crunch.com
API posture management
Yes42crunch.com
Sensitive data detection
Yes42crunch.com
Specification governance
Yes42crunch.com
Deployment model
hybrid42crunch.com

Facts

Purpose
42Crunch provides API security testing and runtime protection and extends its contract-driven governance to MCP servers used by AI agents.42crunch.com · 30 Sept 2026
API testing
Its API security testing uses static and dynamic tests generated from OpenAPI definitions and maps findings to the OWASP API Security Top 10.42crunch.com · 30 Sept 2026
MCP discovery
The platform discovers MCP servers across registries, gateways, and repositories and generates contracts for their advertised tools, resources, and prompts.42crunch.com · 30 Sept 2026
Compliance
The platform maps MCP security findings to NIST AI RMF, OWASP MCP Top 10, EU AI Act, ISO/IEC 42001, and CSA AICM controls.42crunch.com · 30 Sept 2026
Integrations
The maker lists Visual Studio Code, IntelliJ, Eclipse, Bitbucket, Bamboo, GitHub, GitLab, Jenkins, Microsoft Azure, Azure Sentinel, SonarQube, Kubernetes, Docker, Postman, and MuleSoft as technology partners.42crunch.com · 30 Sept 2026
CI/CD support
The platform's CI/CD documentation lists Azure Pipelines, Bamboo, Bitbucket Pipelines, GitHub Actions, GitLab Pipelines, Jenkins, Tekton, and a generic Docker image for REST API static security testing.docs.42crunch.com · 30 Sept 2026
IDE support
The IDE integration documentation names Visual Studio Code, JetBrains IDEs, Eclipse, and Microsoft Visual Studio.docs.42crunch.com · 30 Sept 2026
Security certification
42Crunch states that it is ISO/IEC 27001 certified and describes controls covering vulnerability and incident management, risk assessment, access control, encryption, continuous monitoring, and business continuity.42crunch.com · 30 Sept 2026
Privacy
The company says it commits to applicable privacy laws including GDPR, CCPA, UK GDPR, and Australia's APPs.42crunch.com · 30 Sept 2026
Deployment
Enterprise deployment options listed by the maker are cloud, on-premises, and hybrid.42crunch.com · 30 Sept 2026
Support
The Individual plan includes email support, Individual Pro includes community support, and enterprise pricing includes a dedicated support manager.42crunch.com · 30 Sept 2026
Trial terms
The free trial signup page says the 14-day trial requires a corporate email and no credit card.42crunch.com · 30 Sept 2026
Notable limitation
The CI/CD documentation says GraphQL federation is not supported in CI/CD integration, and the Jenkins instructions state GraphQL scanning requires a separate subscription.docs.42crunch.com · 30 Sept 2026
Company
The current website identifies the company as 42Crunch Ltd. and its leadership page names Jacques Declas and Philippe Leothaud as co-founders.42crunch.com · 30 Sept 2026

Company

Headquarters
London, United Kingdom42crunch.com · 28 Sept 2026

Best 42Crunch API Security Platform alternatives

See all 12

Where it ranks on Everything Xiaomi

Is 42Crunch API Security Platform yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources