# Akto: an open source API security platform you can start in one docker-compose command

> Akto builds an API inventory from real traffic and runs business logic tests against it. Here is how the docker-compose install works, what the testing engine actually does with traffic data, and where the open source edition stops.

**akto-api-security/akto** — Akto is the fastest growing AI Security platform for your teams to secure AI agents, MCPs, LLMs, Agent skills, Gen AI apps in your organization.

- Repository: https://github.com/akto-api-security/akto
- Website: https://www.akto.io/
- Stars: 1,521 · Forks: 294
- Language: Java
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/akto-api-security-akto

## What Akto solves, and who it is actually for

Most API security tools start from a spec file. Akto starts from traffic. The README describes it as an API security platform that maintains a continuous inventory of APIs, tests them for vulnerabilities, and finds runtime issues, with coverage claimed for all OWASP Top 10 and HackerOne Top 10 categories including BOLA, authentication, SSRF and XSS. The stated audience is security teams, with engineering teams named as the second group. That pairing matters: the inventory only stays current if someone keeps a traffic feed connected, which is usually an infrastructure task, while the test results are read by whoever owns the API. The README lists three jobs the product does: API inventory, business logic tests run in CI/CD, and runtime vulnerability discovery. If your problem is "we do not know which endpoints exist, and the ones we know about are untested," that is the gap Akto targets. If your problem is "our WAF needs better rules," this is a different category of tool.

## How Akto turns traffic into an inventory and a test run

The mechanism visible in the repository is a three-container pipeline. The docker-compose.yml defines mongo as the datastore, akto-api-security-dashboard as the UI and API layer, and akto-api-security-testing as the component that executes tests. A fourth service, akto-puppeteer-replay, runs on port 3000 and is used for replaying recorded sessions. The dashboard reads its configuration from docker.env and is published on host port 9090, mapped to container port 8080. The testing container depends on mongo and shares the same env file, which means both services read the same database connection settings. The README describes the flow in two steps: create inventory, then run tests. Inventory comes from traffic sources it lists as burpsuite, AWS, GCP, postman and gateways. The testing engine then reads that traffic data to understand API traffic patterns, which the README says reduces false positives. That is the design bet: tests are parameterized by observed traffic rather than by a hand-written schema, so a BOLA test can use real object identifiers instead of guessed ones. The cost is that an endpoint with no recorded traffic has no inventory entry and nothing to test against.

## Installing Akto with docker-compose and running your first test

The README gives a docker-compose path that it says works on any machine with Docker installed, and requires curl and Docker. It also says Akto takes 60 seconds to get started. Clone the repository, change into it, and bring the stack up detached.

```bash
git clone https://github.com/akto-api-security/akto.git
cd akto
docker-compose up -d
```

After the containers start, the dashboard is exposed on port 9090. The compose file maps "9090:8080", so the browser URL is http://localhost:9090 on your own machine. The README's cloud section uses the same port and shows the tunnel form for a private subnet:

```bash
ssh -i pemfile ec2-user@vpn-public-instance -L 9090:private-instance:9090
```

Once you are in the dashboard, the README's two-step flow applies: connect a traffic source so Akto can build the inventory, then run tests against the resulting API collection. The docs link for that second step is the testing/run-test page, and the API inventory page is api-inventory/api-collections. The README does not walk through the exact dashboard clicks for a first test run, so expect to follow the linked docs pages rather than the README alone. For contributors who want to build from source instead of pulling images, the Makefile exposes three targets: proto-gen, build and build-clean.

```bash
make build
```

That target runs the proto generation script and then mvn install -DskipTests, so the Java build does not run the test suite by default.

## The traffic dependency is the real limitation

Akto cannot test what it has not seen. The README frames the engine as reading traffic data to understand API traffic patterns, which is presented as a false-positive reduction, and it is. But the same design means an endpoint that no traffic source has captured will not appear in the inventory, and an endpoint that only receives a rare request shape will be tested against a thin sample. The README's cloud guidance makes the operational consequence explicit: it says Akto is "really powerful in Cloud deployment if you can provide your application's mirrored traffic (0 performance impact)." That conditional is doing a lot of work. If you cannot mirror traffic, the open source edition gives you less than the marketing line suggests. There is a second boundary in the same section: scheduling tests in CI/CD and inviting more team members on the dashboard are described as reasons to install the Enterprise edition from stairway.akto.io. So the open source docker-compose stack is the inventory and testing core, not the multi-user, scheduled-CI product. Teams that read "run business logic tests in CI/CD" as an out-of-the-box open source feature should check the pricing page before assuming it is in the compose stack.

## Akto against a spec-driven scanner

The obvious alternative is a scanner that takes an OpenAPI or Postman collection and fires requests at each documented operation. The difference is where the input comes from. A spec-driven scanner trusts the spec, so it tests exactly what the spec declares and misses shadow endpoints that were never documented, which is precisely the class of endpoint that tends to be forgotten and exposed. Akto inverts this: the inventory is derived from observed traffic, so shadow endpoints appear because they were called. The trade-off runs the other way too. A spec-driven scanner can run against a staging environment before any real user touches the API, while Akto needs production or mirrored traffic to have something to learn from. Neither approach replaces the other. If you already maintain an accurate spec and want pre-release coverage, a spec-driven scanner fits earlier in the lifecycle. If your inventory is a guess and you want to know what is actually being called, Akto's traffic-first model answers a question a spec scanner cannot.

## Maintenance, licensing and what you inherit

Akto is MIT licensed, so the code in this repository can be used, modified and redistributed under those terms. The licence text is in LICENSE.md at the repository root, and that file, not this article, is what governs your use. Note that the docker-compose stack pulls images from Docker Hub under the aktosecurity namespace, and the Enterprise edition is a separate hosted product at stairway.akto.io; the MIT licence on this repository does not automatically extend to hosted services you sign up for. On maintenance, the repository is not archived and the last push was on 2026-09-10, with releases v2.33.7, v2.33.6 and v2.33.5 all dated 2026-09-10. That is a same-day release cadence, which tells you the project ships frequently but also that the version you pin today may be several patch releases behind within a week. The upgrade cost is mostly in the database: the compose file mounts a named volume, mongodata, at /data/db, so schema or data migrations between versions land in that volume. Back it up before pulling newer images. There is no documented rollback path in the README, so treat the volume as the thing you protect.

## Conclusion

Adopt Akto if you have a security or platform team that can feed it real API traffic and wants a self-hosted inventory plus OWASP-style test runs without a paid tier. Skip it if you need a hosted, zero-ops service, or if you cannot supply mirrored traffic and expect the tool to discover your API surface on its own. Before you commit, confirm two things in your own deployment: that the dashboard on port 9090 is reachable only from your VPC or IP, and that the traffic source you plan to use (Burp, Postman, a gateway, or a cloud mirror) is one the docs actually list for the open source edition.

## FAQ

### What kind of APIs does Akto test?

Akto builds its inventory from traffic captured from sources the README lists as burpsuite, AWS, GCP, postman and gateways, so it tests the APIs that appear in that traffic. The README claims coverage for all OWASP Top 10 and HackerOne Top 10 categories, including BOLA, authentication, SSRF, XSS and security configurations.

### What does Akto do?

The README describes three jobs: maintain a continuous inventory of APIs, run business logic tests in CI/CD, and find vulnerabilities at runtime. The testing engine reads traffic data to understand API traffic patterns, which the README says reduces false positives.

### How do I install Akto?

The README's docker-compose path requires Docker and curl. You clone the repository, change into the akto directory, and run docker-compose up -d, after which the dashboard is available on port 9090.

### Which port does the Akto dashboard run on?

The docker-compose.yml maps host port 9090 to container port 8080 for the akto-api-security-dashboard service, so the dashboard is reached at http://localhost:9090 locally. The README's cloud guidance also opens inbound access on port 9090 only.

### Is the Akto dashboard multi-user?

The README lists inviting more team members on the dashboard as a reason to install the Enterprise edition from stairway.akto.io, alongside scheduling tests in CI/CD. The open source docker-compose stack is described as the inventory and testing core.

### What licence does Akto use?

The repository is MIT licensed, with the licence text in LICENSE.md at the repository root. The Enterprise edition is a separate hosted product, so the repository licence does not by itself cover that service.

## Sources

- [akto-api-security/akto on GitHub](https://github.com/akto-api-security/akto)
- [License: MIT](https://github.com/akto-api-security/akto/blob/master/LICENSE)
- [Project website](https://www.akto.io/)
- [README](https://github.com/akto-api-security/akto/blob/master/README.md)
- [Releases](https://github.com/akto-api-security/akto/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/akto-api-security-akto
