API exposure

The calculator uses the numbers you enter. With 4 public, 3 PII, 2 auth, 3 deps the result is API exposure index: 50 / 100. This is not a penetration test.

This is not a penetration test. Fairness gap is on Fairness gap.

Input data

Results

Enter data and click Calculate.

How it works

API exposure in this calculator is the mean of four 1 to 5 scores, then a 0 to 100 scale. With 4 public, 3 PII, 2 auth, 3 deps the result is API exposure index: 50 / 100.

score = mean(map15) × 100. map15 = (x − 1) / 4. The formula uses auth and PII.

API exposure index: 50 / 100 is not a penetration test. Another set of numbers gives API exposure index: 38 / 100, and a further set gives API exposure index: 69 / 100. Empty optional fields do not change the result.

Fairness gap answers a different question. Documentation does too. Here 4 public, 3 PII, 2 auth, 3 deps leave API exposure index: 50 / 100.

Type 4 public, 3 PII, 2 auth, 3 deps and click Calculate. Two more ready sets sit under the form: API exposure index: 38 / 100 and API exposure index: 69 / 100.

Other numbers on the same labels move the result. The first example gives API exposure index: 50 / 100.

Formula

score = mean(map15) × 100. map15 = (x − 1) / 4.

How to use

  1. Type 4 public, 3 PII, 2 auth, 3 deps.
  2. Leave optional fields empty if you do not want them in the result.
  3. Click Calculate. This set shows API exposure index: 50 / 100.
  4. The second example under the result is API exposure index: 38 / 100, the third API exposure index: 69 / 100.
  5. This is not a penetration test.

API exposure = API exposure index: 50 / 100

The calculator uses the numbers you enter. With 4 public, 3 PII, 2 auth, 3 deps the result is API exposure index: 50 / 100. This is not a penetration test.

API exposure
API exposure is this calculator's result. The first example is API exposure index: 50 / 100.
auth
The formula includes auth. The second example gives API exposure index: 38 / 100.
PII
The formula includes PII. The second example gives API exposure index: 38 / 100.

Examples

Example 1

  • 4 public
  • 3 PII
  • 2 auth
  • 3 deps

API exposure index: 50 / 100

The calculator uses the numbers you enter. With 4 public, 3 PII, 2 auth, 3 deps the result is API exposure index: 50 / 100. This is not a penetration test.

Example 2

  • 2 public
  • 2 PII
  • 4 auth
  • 2 deps

API exposure index: 38 / 100

With 2 public, 2 PII, 4 auth, 2 deps the result is API exposure index: 38 / 100.

Example 3

  • 5 public
  • 5 PII
  • 1 auth
  • 4 deps

API exposure index: 69 / 100

With 5 public, 5 PII, 1 auth, 4 deps the result is API exposure index: 69 / 100.

Related calculators

Common questions

What do you get from 4 public, 3 PII, 2 auth, 3 deps?

API exposure index: 50 / 100. This is not a penetration test.

What about the second example?

API exposure index: 38 / 100.

What about the third example?

API exposure index: 69 / 100.

Is API exposure index: 50 / 100 a penetration test?

No. It is the result from the numbers you enter.

Do empty fields change API exposure index: 50 / 100?

No. Empty optional fields do not change the result.

How is this different from Fairness gap?

That calculator answers another question. Here API exposure stays at API exposure index: 50 / 100.

Does a comma in the number work?

Yes. A comma and a dot mean the same in a number field.

Is the result a diagnosis or official opinion?

No. The result comes from the numbers you enter. a penetration test sits outside this calculator.

Do 2 public, 2 PII, 4 auth, 2 deps give API exposure index: 38 / 100?

Yes. That is the second example under the form.

How is the 0 to 100 index calculated?

The calculator takes the mean of four 1 to 5 scores: publicness, data, authentication, and dependencies. Each score is mapped to 0 to 1 with (score - 1) / 4, then the mean is multiplied by 100. In the first example the result is API exposure index: 50 / 100.

What do the 1 to 5 scores mean?

Each field is a score from 1 to 5. 1 is low and 5 is high. The fields are not percent weights; they enter the mean with equal weight.

Does 50 out of 100 mean a security hole?

No. The result is a heuristic from the scores you enter. The calculator is not a penetration test and does not scan an API.

Does the auth score lower the result when publicness is high?

Not separately. A high auth score and low publicness enter the same mean. No field multiplies the others.

Knowledge sources

The terms come from EU acts. The calculator result is a sketch index, not a regulator decision.

Page updated in 2026.