Intruder-class fuzzing. No throttle, no paid tier.

Mark the positions, pick an attack, and read the results while the job runs.

Run an attack

From a captured request to results.

apiaxess
FileCaptureViewHelp
Go to surface, flow, endpoint or command⌘K
api.northwind-retail.ioLive control connected
Attack type
Positions
GET /v1/checkout/§orders§
host: api.northwind-retail.io
authorization: Bearer §token§
Payload typeNumbers + wordlistGrep-match"insufficient"Grep-extractorder_id
#PayloadStatusLength
No results yetPick an attack type and start. Results stream in here.
Intercept queue 0Diagnostics 0Control · reliable
No paused requestsWith intercept on, matching requests pause here until you forward, modify or drop them.
WORKBENCHsession:2l1a434f3f6b1aControlTelemetry127.0.0.1
  1. Wrap the parts to vary in §markers§: a path segment, a token, a field.

The details

Attacks
Sniper, battering ram, pitchfork and cluster bomb
Payloads
17 types: wordlists, numbers, dates, brute force, case and character permutations, recursive grep, your own files
Processing
Encode, hash, prefix, suffix, match-and-replace or skip, per payload
Reading
Grep-match, grep-extract, sort by status, length or time
Runs
Locally, through 127.0.0.1:8080. No cloud runner and no per-request limit
Price
Free, and Apache-2.0 licensed

Point it at an app. Read the API.