# Jsmon > Jsmon is an AI-powered External Attack Surface Management (EASM) platform that combines deep JavaScript-layer analysis with continuous monitoring to uncover shadow APIs, exposed secrets, and client-side vulnerabilities that traditional scanners miss. Jsmon was built by a top-15 ranked HackerOne researcher (Inderjeet Singh, aka encodedguy) and brings real-world offensive security expertise into an enterprise-grade platform. Unlike conventional EASM tools that stop at network-level scanning, Jsmon analyzes the JavaScript and application code layer where modern web applications expose critical attack vectors — including API endpoints, hardcoded credentials, GraphQL schemas, cloud misconfigurations, and third-party dependency risks. The platform serves two audiences: individual security researchers (bug bounty hunters, pentesters) and enterprise security teams (CISOs, AppSec teams, compliance officers) with community and enterprise editions. Jsmon continuously maps and monitors external attack surfaces, identifying real risks as they emerge in production. ## Core Links - [Homepage](https://jsmon.sh/) - [App / Dashboard](https://app.jsmon.sh/) - [Pricing](https://jsmon.sh/pricing) - [User Documentation](https://knowledge.jsmon.sh/) - [API Documentation](https://api.jsmon.sh/api-docs/) - [Changelog](https://knowledge.jsmon.sh/changelog) - [Blog](https://blogs.jsmon.sh/) - [Contact](https://jsmon.sh/contact) - [Privacy Policy](https://jsmon.sh/privacy-policy) - [Terms of Use](https://jsmon.sh/terms-of-use) - [Subprocessors](https://jsmon.sh/subprocessors) ## Product Features - [Scans](https://jsmon.sh/feature-scans): Multi-depth domain crawling with auto-scope discovery, IP rotation across AWS regions, WAF bypass, authenticated scans, and custom scan modules. Scans can be triggered from the web app, CLI, API, CI/CD pipelines, or browser extensions. - [Reconnaissance](https://jsmon.sh/feature-reconnaissance): Threat discovery mapped to JS files, business domains, and assets. Categories include APIs, URLs, cloud assets, NPM packages, S3 buckets, GraphQL operations, GUIDs, JWTs, IP addresses, and emails. Supports positive, negative, and regex search. - [Keys & Secrets](https://jsmon.sh/features-keys-secrets): Detection of 150+ types of hardcoded API keys, tokens, and credentials within JavaScript code. Covers AWS, Stripe, Google, Azure, and many other providers. - [Monitoring](https://jsmon.sh/feature-monitoring): Continuous tracking of JavaScript response changes with automated scans during monitoring. Real-time alerts via Slack, Discord, JIRA, Linear, email, and webhooks. Version history maintained across JS files. - [Jsmon Radar](https://radar.jsmon.sh/): Free domain reconnaissance tool with full SEO metadata, social content, and a blog post per domain. - [Jsmon Datasets](https://jsmon-datasets.jsmon.sh/): B2B data product selling JS-extracted API endpoints, secrets, GraphQL schemas, and hidden paths as monthly cybersecurity domain scan datasets. - [For Businesses](https://jsmon.sh/for-bussiness): Enterprise-focused offering for CISOs, tech leaders, and security teams — third-party risk monitoring, compliance support, and asset inventory. ## Integrations & Extensions - [CLI (jsmon-cli)](https://github.com/jsmonhq/jsmon-cli): Command-line interface written in Go for automating JS security tasks, scanning domains, and querying results. Supports reverse search, WAF bypass, custom headers, and scan depth control. - [Chrome Extension](https://chromewebstore.google.com/detail/jsmon-chrome-extension/): Browser extension for Chrome. - [Firefox Extension](https://addons.mozilla.org/en-US/firefox/addon/jsmon-extension/): Browser extension for Mozilla Firefox. - [Burp Suite Extension](https://github.com/jsmonhq/jsmon-burpsuite-extension): Integrates Jsmon's JS scanning and monitoring into Burp Suite for manual security research. - Alert channels: Slack, Discord, JIRA, Linear, email, and custom webhooks. ## Free Micro Tools - [Unminify](https://app.jsmon.sh/tools/unminify/): JavaScript unminification tool. - [JS Explorer](https://app.jsmon.sh/jsexplorer/): Explore JavaScript files interactively. - [DepiConf](https://app.jsmon.sh/tools/npm-dependency-confusion-validator): NPM dependency confusion validator. - [Robots.txt Analyzer](https://app.jsmon.sh/tools/robots-txt-analyzer) - [Sitemap Analyzer](https://app.jsmon.sh/tools/sitemap-analyzer) - [CDN & Firewall Detector](https://app.jsmon.sh/tools/cdn-detector) - [CORS Policy Checker](https://app.jsmon.sh/tools/cors-checker) - [IP Lookup](https://app.jsmon.sh/tools/ip-lookup) - [Secret Key Detector](https://app.jsmon.sh/tools/secret-key-detector) - [JWT Decoder](https://app.jsmon.sh/tools/jwt-decoder) - [HTTP Security Headers Checker](https://app.jsmon.sh/tools/http-headers-checker) - [Base64 Encoder/Decoder](https://app.jsmon.sh/tools/base64-encoder-decoder) - [URL Encoder/Decoder](https://app.jsmon.sh/tools/url-encoder-decoder) - [DMARC & SPF Checker](https://app.jsmon.sh/tools/dmarc-spf-checker) - [CNAME Checker](https://app.jsmon.sh/tools/cname-checker) ## Pricing Jsmon has both researcher and business tiers: ### Researcher Plans - **Free Trial**: 1,500 lifetime scan credits, 50 URLs for daily monitoring, email alerts only. No credit card required. - **Recon ($15/mo or $180/yr)**: 25,000 credits/month, 10,000 scans/month, WAF bypass, authenticated scans, custom scan modules, alerts via Email/Discord/Slack. - **Recon Pro ($50/mo or $600/yr)**: 100,000 credits/month, priority scan queue, advanced reporting exports, dedicated Slack channel support. Everything in Recon plus more. ### Business Plans - **Business** and **Enterprise** tiers are available for organizations. Enterprise includes custom configurations, SLA, and dedicated support. Contact sales for pricing. [Book a Demo] - https://jsmon.sh/contact ## API The Jsmon API uses API key authentication via the `X-Jsmon-Key` header. Base URL: `https://api.jsmon.sh/api/v2/`. Key endpoints include domain scanning, profile viewing, workspace management, and result retrieval. Full API documentation is available at the API docs link above. ## Comparison Pages - [Jsmon vs Semgrep](https://jsmon.sh/compare/jsmon-vs-semgrep) - [Jsmon vs Checkmarx](https://jsmon.sh/compare/jsmon-vs-checkmarx) - [Jsmon vs Snyk](https://jsmon.sh/compare/jsmon-vs-snyk) - [Jsmon vs Burp Suite](https://jsmon.sh/compare/jsmon-vs-burpsuite) ## Programs - [Become a Design Partner](https://jsmon.sh/design-partners) - [Startup Program](https://jsmon.sh/start-up-program) ## Open Source - [jsmon-cli](https://github.com/jsmonhq/jsmon-cli): CLI for the Jsmon platform (Go). - [apiffuf](https://github.com/jsmonhq/apiffuf): API fuzzing tool. - [xnew](https://github.com/jsmonhq/xnew): Utility tool for filtering new entries. - [Burp Suite Extension](https://github.com/jsmonhq/jsmon-burpsuite-extension): Burp Suite integration for Jsmon. ## Social - [X / Twitter](https://x.com/jsmonsh) - [LinkedIn](https://www.linkedin.com/company/jsmon/) - [YouTube](https://www.youtube.com/@jsmon-sh) - [Instagram](https://instagram.com/jsmon.sh) - [Schedule a Meeting](https://jsmon.sh/meeting)