vespasian
API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs
File Explorer
Download Latest Version (.zip)- settings.json
- bug.yml
- config.yml
- feature.yml
- question.yml
- ci.yml
- claude-code.yml
- claude-md-drift.yml
- codex-code.yml
- external-contribution.yml
- gemini-code.yml
- graphify-graph.yml
- leaderboard-metrics.yml
- live-tests.yml
- release.yml
- secrets-scan.yml
- security.yml
- verify-pins.yml
- dependabot.yml
- PULL_REQUEST_TEMPLATE.md
- crawl_jsstatic_test.go
- display.go
- display_test.go
- generate_jsstatic_test.go
- main.go
- main_test.go
- scan_jsstatic_smoke_test.go
- scan_jsstatic_test.go
- crawler-comparison.md
- banner.png
- crawler.md
- grpc.md
- doc.go
- frame.go
- frame_test.go
- apitype.go
- apitype_regression_test.go
- apitype_test.go
- augment.go
- augment_test.go
- determinism_test.go
- doc.go
- grpc_enrich.go
- grpc_enrich_test.go
- grpc_gateway_e2e_test.go
- pipeline.go
- pipeline_test.go
- probe_origin_gate.go
- probe_origin_gate_internal_test.go
- probe_origin_gate_test.go
- reasons.go
- reasons_test.go
- resolve_generate.go
- resolve_generate_test.go
- static_asset.go
- static_asset_test.go
- wsdl_probe.go
- wsdl_probe_internal_test.go
- wsdl_probe_test.go
- doc.go
- tnetenc.go
- tnetenc_test.go
- doc.go
- extractor.go
- extractor_test.go
- jsstatic.go
- jsstatic_test.go
- nextroute.go
- nextroute_test.go
- normalize.go
- normalize_test.go
- sourcemap.go
- sourcemap_test.go
- synthesize.go
- synthesize_test.go
- users_connect.js
- users_grpc_web_pb.js
- users_pb_service.js
- doc.go
- forms.go
- forms_test.go
- grpc_web_bindings.go
- grpc_web_bindings_test.go
- classifier.go
- classifier_test.go
- doc.go
- graphql.go
- graphql_test.go
- grpc.go
- grpc_test.go
- rest.go
- rest_test.go
- scopeexemption_test.go
- types.go
- types_test.go
- wsdl.go
- wsdl_test.go
- bench_test.go
- browser.go
- browser_integration_test.go
- browser_test.go
- capture.go
- capture_test.go
- checkpoint.go
- checkpoint_test.go
- contract_test.go
- cookies.go
- cookies_test.go
- crawler.go
- crawler_test.go
- doc.go
- engine.go
- engine_integration_test.go
- engine_test.go
- fake.go
- fake_test.go
- forms.go
- forms_test.go
- frontier.go
- frontier_test.go
- headers.go
- headers_test.go
- htmlextract.go
- htmlextract_test.go
- http_crawler.go
- http_crawler_test.go
- interact.go
- interact_test.go
- jsextract.go
- jsextract_test.go
- jsreplay.go
- jsreplay_test.go
- links.go
- links_test.go
- network.go
- network_test.go
- rod_crawler.go
- rod_crawler_test.go
- scope.go
- scope_test.go
- scopefilter_test.go
- spa_integration_test.go
- types.go
- types_test.go
- doc.go
- infer.go
- sdl.go
- sdl_test.go
- doc.go
- generator.go
- generator_test.go
- synthesize.go
- synthesize_test.go
- doc.go
- form.go
- form_test.go
- normalize.go
- normalize_test.go
- openapi.go
- openapi_test.go
- schema.go
- schema_test.go
- doc.go
- generator.go
- generator_test.go
- infer.go
- infer_test.go
- parse.go
- parse_test.go
- soapbody.go
- soapbody_test.go
- types.go
- doc.go
- generator.go
- registry.go
- registry_test.go
- doc.go
- proxy_client.go
- proxy_client_test.go
- burp.go
- burp_test.go
- doc.go
- har.go
- har_test.go
- helpers.go
- helpers_test.go
- importer.go
- importer_test.go
- mitmproxy.go
- mitmproxy_fixture_test.go
- mitmproxy_test.go
- options.go
- options_test.go
- registry.go
- registry_test.go
- testhelpers_test.go
- tnetstring.go
- tnetstring_test.go
- doc.go
- mediatype.go
- mediatype_test.go
- plain_rest.json
- swagger.json
- doc.go
- graphql.go
- graphql_test.go
- grpc.go
- grpc_test.go
- grpcgateway.go
- grpcgateway_internal_test.go
- grpcgateway_test.go
- options.go
- options_test.go
- prober.go
- prober_test.go
- proxy_internal_test.go
- proxy_test.go
- schema.go
- schema_test.go
- types.go
- validate.go
- validate_test.go
- wsdl.go
- wsdl_test.go
- capability.go
- capability_test.go
- doc.go
- doc.go
- ssrf.go
- ssrf_test.go
- check-unreachability-claims.sh
- check-unreachability-claims_test.sh
- expected-paths.json
- main.go
- main.go
- empty-burp.xml
- empty-har.json
- expected-burp-base64-capture.json
- expected-burp-capture.json
- expected-burp-unicode-capture.json
- expected-empty-capture.json
- expected-from-burp.json
- expected-from-har.json
- expected-har-capture.json
- expected-har-duplicates-capture.json
- expected-mitmproxy-capture.json
- google-linux-signing-key.asc
- LICENSE.mitmproxy
- malformed-burp.xml
- malformed-har.json
- merge-slugs-capture.json
- not-google-signing-key.asc
- README.md
- real-mitmproxy.mitm
- sample-auth.har
- sample-burp-base64.xml
- sample-burp-export.xml
- sample-burp-unicode.xml
- sample-capture.har
- sample-har-duplicates.json
- sample-mitmproxy.json
- sample-mitmproxy.mitm
- expected-paths.json
- main.go
- expected-paths.json
- expected-spec.graphql
- package-lock.json
- package.json
- reference-capture.json
- server.js
- test-burp.xml
- test-traffic.har
- lab.pb.go
- lab.proto
- lab_grpc.pb.go
- doc.go
- expected-paths.json
- main.go
- Makefile
- README.md
- doc.go
- target.go
- target_test.go
- expected-paths.json
- reference-capture.json
- expected-paths.json
- expected-spec.yaml
- main.go
- reference-capture.json
- scan-expected-paths.json
- expected-paths.json
- expected-spec.xml
- main.go
- matrix-capture.json
- matrix-expected-paths.json
- matrix-expected-spec.xml
- reference-capture.json
- service.wsdl
- package-lock.json
- package.json
- validate-graphql.mjs
- validate-openapi.mjs
- assert-chrome-install.sh
- check-docs.py
- common.sh
- form-spec-asserts.sh
- install-chrome-selftest.sh
- install-chrome.sh
- live-test-gaps.md
- preflight-selftest.sh
- README.md
- run-live-tests.sh
- setup-live-targets.sh
- setup-live-targets_test.sh
- test-runner-args.sh
- validate.sh
- validate_test.sh
- .gitignore
- .golangci.yml
- .goreleaser.yml
- .graphifyignore
- .mailmap
- AGENTS.md
- CLAUDE.md
- CODE_OF_CONDUCT.md
- CODEOWNERS
- CONTRIBUTING.md
- Dockerfile
- go.mod
- go.sum
- GOVERNANCE.md
- LICENSE
- Makefile
- README.md
- SECURITY.md
- SUPPORT.md
# Installation Guide
git clone https://github.com/praetorian-inc/vespasian
Downloads the entire project code from GitHub to your computer.
cd vespasian
Moves into the project folder you just downloaded.
2. Official Install Script
Easy Recommended- Go Go is required to use go install.
go install github.com/praetorian-inc/vespasian/cmd/vespasian@latest
Downloads and installs the specified version directly β no need to clone the repo yourself.
Pulled directly from this repo's README.
3. Docker
Easy- Git Needed to download the project code from GitHub.
- Docker Desktop Needed to build and run containers. Install it and keep it running in the background.
docker build -t vespasian .
Builds a runnable image based on the Dockerfile.
docker run -p 8080:80 vespasian
Runs the built image as an actual container.
4. Go
Mediumgo install github.com/praetorian-inc/vespasian/cmd/vespasian@latest
Downloads and installs the specified version directly β no need to clone the repo yourself.
Pulled directly from this repo's README.
5. Make
Medium- Git Needed to download the project code from GitHub.
- Make Usually pre-installed on Linux/macOS. On Windows, install separately (e.g. via MSYS2 or WSL).
make build
Compiles the code based on the generated build configuration to produce an executable.
make build # Build the binary to bin/vespasian
Compiles the code based on the generated build configuration to produce an executable.
make test # Run tests with race detection
Compiles the code based on the generated build configuration to produce an executable.
make lint # Run golangci-lint (gocritic, misspell, revive)
Compiles the code based on the generated build configuration to produce an executable.
make check # Run all checks (fmt, vet, lint, test)
Compiles the code based on the generated build configuration to produce an executable.
Pulled directly from this repo's README.
