Overview
Qodex.ai is an AI-first platform that auto-discovers APIs, generates functional and security tests (including OWASP Top 10), auto-heals tests when APIs change, and integrates with CI/CD and GitHub to monitor and secure APIs and AI agents. Key capabilities include: auto-discovery of API endpoints from repos to produce a full endpoint map (methods, parameters, descriptions); AI-generated test creation (unit, functional, end-to-end, regression suites); security testing covering OWASP Top 10, injection tests, header checks, and penetration-style scans; auto-healing that detects API response changes and suggests fixes; export and GitHub sync to push generated tests to a private repo with pre-commit validations and CI/CD integration; multiple execution modes (UI, CLI, scheduled Test Plans, CI/CD runs) with reportedly unlimited executions; support for test formats like Postman, OpenAPI/Swagger, and SDK-generated OpenAPI; monitoring and alerting, data governance features (runtime threat protection, data redaction, staging validations); extensibility via custom JS rules; and enterprise-grade options (24×7 expert support, mutual TLS, unlimited environments).
Key Features
Auto-discovery of API endpoints
From repos (SDK/script) to produce a full endpoint map with methods, parameters, and descriptions.
AI-generated test creation
Unit, functional, end-to-end, and regression test generation from English prompts.
Security testing
OWASP Top 10 checks, injection tests, header checks, and penetration-style scans.
Auto-healing
Detects API changes, flags outdated rules, and offers one-click fixes.
Export / GitHub sync
Push generated tests to a private GitHub repo with pre-commit validations and CI/CD integration.
Execution modes
UI, CLI, scheduled Test Plans, CI/CD runs; supports unlimited executions.



Who Can Use This Tool?
- Developers:Automated API testing, security testing, and CI/CD integration
- Security engineers:Threat protection, data redaction, and API security controls
Pricing Plans
Free plan with up to 100 API endpoints/month, up to 12,500 tests/month, alerting & reporting, and 24×7 community support.
- ✓Up to 100 API endpoints/month
- ✓Up to 12,500 tests/month
- ✓Alerting & Reporting
- ✓24×7 Community Support
Higher limits (example: up to 500 API endpoints/month; up to 200,000 tests/month), Jira/CI/CD integrations, 24×7 expert support. Marked as the popular plan.
- ✓Higher limits (up to 500 API endpoints/month)
- ✓Up to 200,000 tests/month
- ✓Jira, CI/CD integrations
- ✓24×7 expert technical support
- ✓Popular plan
Custom pricing, unlimited endpoints, 1M+ to unlimited tests; advanced security/compliance, API runtime threat protection, data redaction, mutual TLS, unlimited environments, expert 24×7 support.
- ✓Custom pricing
- ✓Unlimited endpoints
- ✓1M+ to unlimited tests
- ✓Advanced security/compliance
- ✓API runtime threat protection
- ✓Data redaction
- ✓Mutual TLS
- ✓24x7 expert support
Pros & Cons
✓ Pros
- ✓G2 reviews praise ease of use
- ✓CI/CD integration
- ✓Active GitHub presence with tooling
✗ Cons
- ✗Pricing details for Premium/Enterprise not publicly listed
- ✗Inconsistent founding year signals in third-party sources
- ✗Some site features page (e.g., /features) 404s