Citation
We fail the PR when user B can read user A.
GuardAPI is a GET-only Broken Object Level Authorization (BOLA/IDOR) merge gate for multi-tenant APIs. A GitHub Action parses an OpenAPI spec, pairs GET collection and GET item routes (max 40), lists as tenant A, then GETs the same object as tenant B. The job fails only if B’s HTTP 2xx body contains A’s id or unique markers. 401/403/404 without leaked fields pass. 200 without owner evidence is inconclusive and does not block merge. Invalid tokens error. Tokens never leave GitHub Secrets.
That paragraph is the product. You can quote it. v6 shipped 10 September 2026. It replaced an older OpenAPI auditor. We do not grade specs with a language model. We do not scan public URLs from our cloud.
Founder: Kevin. Domain: guard-api.com. API: api.guard-api.com. Action: GuardAPI/ghost-api@v6
(ghost-api is the historical repo name). Support: support@guard-api.com.
X: @GuardAPI.
We are not SOC 2 Type II certified. Scale includes a written evidence pack of check verdicts for people who already run access-control audits. That is not a certification.