For the complete documentation index, see llms.txt. This page is also available as Markdown.

API & Application Discovery

Learn API & Application Discovery through Harness University

Prioritize issues, enforce security standards, while maintaining strong, proactive security posture across your application and APIs.

Go to Harness University for the full catalogue of courses and certifications.

Self-Paced Training Instructor-Led Training Certifications

Self-Paced Training

Free self-paced courses that you can consume on your own time.

Instructor-Led Training

Intensive two-day courses are designed for engineers looking to deepen their understanding and expertise in Harness.

Certifications

Test and validate your knowledge of Harness by becoming a Harness Certified Expert.

API & Application Discovery - Developer

API & Application Discovery - Developer badge

Product version: API & Application Discovery Paid Plans

Assesses the fundamental skills to manage your posture with API & Application Discovery (Traceable) projects.

Review Study Guide

Topic
Material

1. GraphQL-Based Dynamic API Ownership Assignment

Constructing and interpreting GraphQL createPolicy mutations for Static, Dynamic, and Regex-based policy assignments

Configuring RE2 regular expression patterns with specific capture group indices and fallback constants

Managing active ownership policies using getPolicies queries, updatePolicy mutations, and deletePolicies mutations

2. Dynamic Ownership Prerequisites and Operational Mechanics

Configuring authentication prerequisites using JWT tokens and the Authorization: Bearer header

Troubleshooting operational replication latencies and isolating span attributes in the Explorer tab

Assessing the governance trade-offs of automated dynamic policy mapping versus manual, spreadsheet-based ownership assignment

3. Automating API Documentation and Specification Generation

Triggering standard OpenAPI specifications (YAML or JSON) and WSDL schemas (for SOAP APIs) using the createApiDefinition mutation

Applying the learningEndpointStrategy parameters (including MENTION vs. EXCLUDE behaviors) to govern endpoint documentation

Extracting domain-specific scope credentials to parameterize schema generation

4. API Specification Monitoring and Retrieval Workflows

Checking spec generation job statuses using the getApiDefinition query to verify state fields, success states (JOB_STATUS_SUCCESS), timestamps, and error messages

Programmatically downloading completed specification archives (*.zip) using REST GET clients with the Authorization: <Platform_API_Token> header

5. Unified Asset Management and MCP/AI Discovery

Consolidating traditional API Endpoints, AI APIs, and Model Context Protocol (MCP) components into a any single system inventory

Tracking infrastructure health and data flows through core UI widgets and strategic filters

Troubleshooting production failures, diagnosing MCP server downtime, and conducting downstream impact analysis using "Last Called" filters

6. Business-Level Application Grouping and Severity Management

Defining logical application groupings to map technical APIs directly to functional business units

Customizing filtering criteria and severity ratings to prioritize remediation efforts based on business risk

7. Role-Based Access Control (RBAC) and Administration

Enforcing administrative permissions, specifically requiring the Module Level Access -> Discovery -> Settings permission to create and manage application groups and policies

Scoping rules and security policies to "All Environments" versus restricted zones

8. API Discovery Engine Internal Stages and Learning Logic

Modeling endpoint structures by observing URLs, headers, and request/response payloads in live spans

Filtering out malicious or junk traffic by strictly requiring successful HTTP response codes (between 2xx and 3xx) before learning new endpoints

Distinguishing between "Learning" and "Learnt" states in the API Catalog, and managing default state-filtering behavior

Register for Exam

Exam Details

The Harness API & Application Discovery Developer Certification exam tests your knowledge and skills of the API & Application Discovery module.

Prerequisites

  • Basic terminal skills

  • Basic understanding of Harness and API security.

Exam Details

Exam Duration: 90 minutes

Question Type: Multiple choice

Covered Domain
Percentage

GraphQL-Based Dynamic API Ownership Assignment

20%

Dynamic Ownership Prerequisites and Operational Mechanics

13.3%

Automating API Documentation and Specification Generation

13.3%

API Specification Monitoring and Retrieval Workflows

13.3%

Unified Asset Management and MCP/AI Discovery

16.7%

Business-Level Application Grouping and Severity Management

10%

Role-Based Access Control (RBAC) and Administration

3.4%

API Discovery Engine Internal Stages and Learning Logic

10%

Exam Objectives

List of Objectives

The following is a detailed list of exam objectives:

#
Objectives

1

GraphQL-Based Dynamic API Ownership Assignment

1.1

Constructing and interpreting GraphQL createPolicy mutations for Static, Dynamic, and Regex-based policy assignments

1.2

Configuring RE2 regular expression patterns with specific capture group indices and fallback constants

1.3

Managing active ownership policies using getPolicies queries, updatePolicy mutations, and deletePolicies mutations

2

Dynamic Ownership Prerequisites and Operational Mechanics

2.1

Configuring authentication prerequisites using JWT tokens and the Authorization: Bearer header

2.2

Troubleshooting operational replication latencies and isolating span attributes in the Explorer tab

2.3

Assessing the governance trade-offs of automated dynamic policy mapping versus manual, spreadsheet-based ownership assignment

3

Automating API Documentation and Specification Generation

3.1

Triggering standard OpenAPI specifications (YAML or JSON) and WSDL schemas (for SOAP APIs) using the createApiDefinition mutation

3.2

Applying the learningEndpointStrategy parameters (including MENTION vs. EXCLUDE behaviors) to govern endpoint documentation

3.3

Extracting domain-specific scope credentials to parameterize schema generation

4

API Specification Monitoring and Retrieval Workflows

4.1

Checking spec generation job statuses using the getApiDefinition query to verify state fields, success states (JOB_STATUS_SUCCESS), timestamps, and error messages

4.2

Programmatically downloading completed specification archives (*.zip) using REST GET clients with the Authorization: <Platform_API_Token> header

5

Unified Asset Management and MCP/AI Discovery

5.1

Consolidating traditional API Endpoints, AI APIs, and Model Context Protocol (MCP) components into a single system inventory

5.2

Tracking infrastructure health and data flows through core UI widgets and strategic filters

5.3

Troubleshooting production failures, diagnosing MCP server downtime, and conducting downstream impact analysis using "Last Called" filters

6

Business-Level Application Grouping and Severity Management

6.1

Defining logical application groupings to map technical APIs directly to functional business units

6.2

Customizing filtering criteria and severity ratings to prioritize remediation efforts based on business risk

7

Role-Based Access Control (RBAC) and Administration

7.1

Enforcing administrative permissions, specifically requiring the Module Level Access -> Discovery -> Settings permission to create and manage application groups and policies

7.2

Scoping rules and security policies to "All Environments" versus restricted zones

8

API Discovery Engine Internal Stages and Learning Logic

8.1

Modeling endpoint structures by observing URLs, headers, and request/response payloads in live spans

8.2

Filtering out malicious or junk traffic by strictly requiring successful HTTP response codes (between 2xx and 3xx) before learning new endpoints

8.3

Distinguishing between "Learning" and "Learnt" states in the API Catalog, and managing default state-filtering behavior


Next Steps

The Harness API & Application Discovery Developer exam can start immediately after registering. Please allow up to 90 mins for the exam.

  1. Create an account in Harness University

  2. Register for an exam

  3. Take the exam

Register for Exam

API & Application Discovery - Administrator (BETA COMING SOON)

API & Application Discovery - Administrator (BETA COMING SOON) badge

Product version: API & Application Discovery Paid Plans

Coming soon

This certification is in beta and not yet open for registration.

Assesses the fundamental skills to deploy and maintain API & Application Discovery projects and the overall Harness Platform.

API & Application Discovery - Architect (BETA COMING SOON)

API & Application Discovery - Architect (BETA COMING SOON) badge

Product version: API & Application Discovery Paid Plans

Coming soon

This certification is in beta and not yet open for registration.

Assess key technical job functions and advanced skills in design, implementation and management of API & Application Discovery.

Last updated

Was this helpful?