AppDefender.dev console is open for Client onboardinghello@appdefender.dev
Request access

App Security · AppDefender.dev

ApiDefender

Access-token validation, SSL pinning, ATS Lite and Full.

Umbrella for the ATS platform. Login + token is never enough. Per-route Lite or Full, transaction binding on payments, SSL pinning and pinning-over-VPN. MITM and token-in-body are rejected.

ATS Lite & ATS Full

SSL pinning / MITM block

Transaction binding on payments

Token cannot override RASP

Per-route policy in ThreatDesk

Pin-over-VPN

What it does

ApiDefender on the launch path

ApiDefender is the session and API layer after the launch gate. A login and an access token prove a session, not a clean device and not an honest request. ATS Lite covers routine reads. ATS Full binds money movement.

SSL pinning, including pin-over-VPN, blocks MITM. Token-in-body is rejected. Transaction binding ties a payment, UPI collect, IMPS, or BBPS confirmation to the enrolled device and the launch score.

If AppDefender already decided BLOCK, ApiDefender does not reopen the path. Super Admin sets Lite or Full per route on that Client’s isolated catalog. Production route changes need Checker review.

What it scores

Signals this module is built for

  • ATS Lite on balance, history, and catalog reads
  • ATS Full on pay, collect, mandate, and bill confirm
  • SSL pinning and pin-over-VPN
  • MITM and token-in-body rejection
  • Transaction binding on payment APIs
  • Launch BLOCK still wins over a valid token

How it runs

Detect, decide, enforce

After ALLOW

The user authenticates. ApiDefender wraps protected APIs. Inquiry routes can stay on ATS Lite.

When money moves

ATS Full binds the transaction to device, SIM, and launch score. UPI, IMPS, NEFT, and BBPS pay use this path.

Reject the cheat

MITM, broken pin, and token-in-body fail closed. ThreatDesk records the action for that Client only.

Operators

Who owns the control

Super Admin

Enables the environment and the default Lite / Full map. Does not mix Client catalogs.

Client Admin

Proposes route policy in Sandbox. Two checkers approve Production. No self-approval.

Other App Security modules

Read the product page, not a copy here

All modules