Metlo logo

Metlo

Claim

Metlo is an open source API security product that discovers API inventory from traffic and helps detect and block malicious requests. It also supports custom tests, OpenAPI spec generation, and integrations across common runtimes and infrastructure.

Metlo preview

Overview

Metlo is an API security product that uses observed API traffic to help teams discover their API surface and detect malicious activity. The homepage positions it as open source API security software for setting up in less than 15 minutes.

The product combines discovery, testing, and protection workflows. It can inventory endpoints, hosts, and sensitive data, identify unauthenticated endpoints, run custom tests, and block malicious requests in real time using detections built from request patterns.

The site also describes a deployment model built around connectors and agents, with support for common stacks such as Node, Python, Golang, Java, Nginx, Kubernetes, AWS, GCP, Docker, Express, Koa, and Fastify. The homepage states that discovery metadata is sent to Metlo’s cloud while the agent performs discovery locally.

Features

Traffic-based attack detection

Metlo passively listens to API traffic to build a model of how the API behaves, then uses that model to flag malicious requests and bad actors.

Built-in and custom detections

The product calls out built-in detections for SQLi, XSS, SSRF, RCE, login brute force, account takeover, and more, with support for custom detections.

IP, session, and user-level analysis

Metlo distinguishes detection at the IP, session, and user level, which helps identify attacks that move beyond a single request or address.

API inventory discovery

It creates an inventory of endpoints, hosts, and sensitive data from observed traffic, including unauthenticated endpoints and data fields.

Agent-based discovery and alerts

Discovery runs in the agent, with only metadata sent to Metlo’s cloud, and the product can send webhooks when new endpoints or data fields are found.

Testing and spec generation

Metlo supports custom tests for finding different kinds of vulnerabilities and can autogenerate OpenAPI specs from discovered API activity.

Use cases

  • API inventory and endpoint discovery

    Use Metlo to map your API surface from live traffic, including hosts, endpoints, sensitive data, and unauthenticated routes, so teams can understand what is actually exposed.

  • Attack detection and blocking

    Use the built-in detections to watch for common attack patterns such as SQLi, XSS, SSRF, RCE, brute force, and account takeover, then block or review malicious requests.

  • Security testing with custom checks

    Use custom tests to probe for different kinds of vulnerabilities during API security checks and development workflows.

  • Integration into existing stacks

    Use the connectors and runtime support to add Metlo to existing services and infrastructure that run on Node, Python, Golang, Java, Nginx, Kubernetes, AWS, GCP, or Docker.

  • Documentation and change monitoring

    Use the discovered API activity and metadata to generate OpenAPI specs or send alerts when new endpoints and data fields are identified.

Pros and Cons

Pros

  • Combines API discovery, testing, and protection in one product.
  • Supports both built-in detections and custom detections/tests.
  • Can identify issues at the IP, session, and user level, not just by individual request.
  • Supports a broad set of common runtimes and deployment environments.
  • States that discovery runs in the agent while only metadata is sent to the cloud.

Cons

  • The pricing page is unavailable, so the public site does not confirm plan names, pricing, or limits.
  • Several areas are described at a high level on the homepage only, so deeper documentation is needed to verify implementation details and integration behavior.

FAQ

What does Metlo do?

Metlo discovers API endpoints, hosts, sensitive data, and unauthenticated endpoints from API traffic, and it can also detect and block malicious requests and bad actors.

How is Metlo deployed and connected to an app?

The homepage says Metlo can be set up in less than 15 minutes and integrates with Node, Python, Golang, Java, Nginx, Kubernetes, AWS, GCP, Docker, and common frameworks such as Express, Koa, and Fastify.

What kinds of security checks does Metlo support?

Metlo includes built-in detections such as SQLi, XSS, SSRF, RCE, login brute force, and account takeover, and it also supports custom detections and custom tests.

Does Metlo publish pricing on the site?

The pricing page at `/pricing` is not available, so the site text does not confirm current pricing or plan structure.

Quick Facts

Category
API Security
Product type
Open source software
Deployment model
Agent plus cloud metadata
Primary workflow
Discovery, testing, and request blocking
Source domain
metlo.com
Pricing
Not available on the public pricing URL