OWASP Noir is an open-source static analysis tool that builds a complete inventory of an application's exposed endpoints—paths, HTTP methods, parameters, headers, and cookies—directly from source code. Unlike dynamic scanners such as ZAP or Burp Suite, which crawl a running app and only test routes they can reach, Noir sees every route defined in the code, including shadow APIs that never made it into documentation. That means undocumented handlers and deprecated routes show up in the same list as everything else, giving reviewers a full attacker-reachable surface.
The tool detects the language, framework, and routing convention automatically, covering 29 languages and 205 frameworks from a single binary with no plugins. When static rules miss a custom framework, Noir can hand the code to an LLM via OpenAI, Ollama, or similar providers, though the maintainers advise manual verification of LLM-generated routes. Seventeen taggers label endpoints with properties like jwt, payment, admin, and file_upload, so reviewers can prioritize sensitive handlers first.
Noir is built for three audiences: human reviewers get a list of entrypoints to work through; AI code auditors receive the same list plus guards, sinks, and validators via the --ai-context flag; and DAST tools like ZAP, Burp Suite, Caido, and Gori can import the routes as a proxy target or OpenAPI spec. Results export in 22 formats, including JSON, SARIF, OpenAPI, Postman, and cURL, and the tool ships as a GitHub Action for CI pipelines. It is available free on GitHub.
Because this article draws on a single source, the details reflect only that report. The tool's effectiveness in real-world projects, especially the accuracy of LLM-assisted route discovery, would benefit from independent testing, but the core capability—surfacing undocumented endpoints statically—addresses a known blind spot in dynamic scanning.