> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/university/readme/api-application-discovery.md).

# API & Application Discovery

Learn API & Application Discovery through Harness University

Prioritize issues, enforce security standards, while maintaining strong, proactive security posture across your application and APIs.

Go to [Harness University](/university/readme.md) for the full catalogue of courses and certifications.

## Self-Paced Training

Free self-paced courses that you can consume on your own time.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-8d9330b11e4adb2c19a6b64b4a75262530fb0ef8%2Fplatform.svg?alt=media" alt="" data-size="line"> <strong>Harness Platform Fundamentals</strong></td><td>Self-paced video course introducing the Harness Platform.<br><em>Product version: Free Plans of any module</em></td><td><a href="https://university-registration.harness.io/self-paced-training-platform-fundamentals">https://university-registration.harness.io/self-paced-training-platform-fundamentals</a></td></tr><tr><td><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-8d9330b11e4adb2c19a6b64b4a75262530fb0ef8%2Fplatform.svg?alt=media" alt="" data-size="line"> <strong>Introduction to AI Agents</strong></td><td>Self-paced tidbit introducing the Custom AI Agents.<br><em>Product version: Paid Plans of any module</em></td><td><a href="https://university-registration.harness.io/self-paced-training-tidbit-custom-ai-agents">https://university-registration.harness.io/self-paced-training-tidbit-custom-ai-agents</a></td></tr><tr><td><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-0d0c28c8655cdff18ad9940a9c45ccd5be07d06d%2Fapp-discovery.svg?alt=media" alt="" data-size="line"> <strong>Traceable by Harness Platform Fundamentals</strong></td><td>Self-paced video course introducing the Traceable by Harness Platform.<br><em>Product version: Traceable by Harness Paid Plans</em></td><td><a href="https://university-registration.harness.io/self-paced-training-traceable-platform-fundamentals">https://university-registration.harness.io/self-paced-training-traceable-platform-fundamentals</a></td></tr></tbody></table>

## Instructor-Led Training

Intensive two-day courses are designed for engineers looking to deepen their understanding and expertise in Harness.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><img src="https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-8d9330b11e4adb2c19a6b64b4a75262530fb0ef8%2Fplatform.svg?alt=media" alt="" data-size="line"> <strong>Introduction to the Harness Platform</strong></td><td>Self-paced hands-on, prerequisite course to all module-specific ILT courses.<br><em>Product version: Paid Plans of any module</em></td><td><a href="https://university-registration.harness.io/introduction-to-the-harness-platform">https://university-registration.harness.io/introduction-to-the-harness-platform</a></td></tr></tbody></table>

## Certifications

Test and validate your knowledge of Harness by becoming a Harness Certified Expert.

{% tabs %}
{% tab title="For Developer" %}

### API & Application Discovery - Developer

![API & Application Discovery - Developer badge](https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-368405a589bfb1e12be6c15654c29b9be9ba5338%2Fcert-dev-asp-badge.svg?alt=media)

**Product version:** API & Application Discovery Paid Plans

Assesses the fundamental skills to manage your posture with API & Application Discovery (Traceable) projects.

#### Review Study Guide

| Topic                                                                                                                                                                           | Material                                                                         |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------- |
| **1. GraphQL-Based Dynamic API Ownership Assignment**                                                                                                                           |                                                                                  |
| Constructing and interpreting GraphQL `createPolicy` mutations for Static, Dynamic, and Regex-based policy assignments                                                          | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| Configuring RE2 regular expression patterns with specific capture group indices and fallback constants                                                                          | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| Managing active ownership policies using `getPolicies` queries, `updatePolicy` mutations, and `deletePolicies` mutations                                                        | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| **2. Dynamic Ownership Prerequisites and Operational Mechanics**                                                                                                                |                                                                                  |
| Configuring authentication prerequisites using JWT tokens and the `Authorization: Bearer` header                                                                                | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| Troubleshooting operational replication latencies and isolating span attributes in the Explorer tab                                                                             | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| Assessing the governance trade-offs of automated dynamic policy mapping versus manual, spreadsheet-based ownership assignment                                                   | [AppSec Discovery](https://developer.harness.io/docs/appsec-discovery)           |
| **3. Automating API Documentation and Specification Generation**                                                                                                                |                                                                                  |
| Triggering standard OpenAPI specifications (YAML or JSON) and WSDL schemas (for SOAP APIs) using the `createApiDefinition` mutation                                             | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| Applying the `learningEndpointStrategy` parameters (including `MENTION` vs. `EXCLUDE` behaviors) to govern endpoint documentation                                               | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| Extracting domain-specific scope credentials to parameterize schema generation                                                                                                  | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| **4. API Specification Monitoring and Retrieval Workflows**                                                                                                                     |                                                                                  |
| Checking spec generation job statuses using the `getApiDefinition` query to verify state fields, success states (`JOB_STATUS_SUCCESS`), timestamps, and error messages          | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| Programmatically downloading completed specification archives (`*.zip`) using REST GET clients with the `Authorization: <Platform_API_Token>` header                            | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| **5. Unified Asset Management and MCP/AI Discovery**                                                                                                                            |                                                                                  |
| Consolidating traditional API Endpoints, AI APIs, and Model Context Protocol (MCP) components into a any single system inventory                                                | [AppSec Discovery](https://developer.harness.io/docs/appsec-discovery)           |
| Tracking infrastructure health and data flows through core UI widgets and strategic filters                                                                                     | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| Troubleshooting production failures, diagnosing MCP server downtime, and conducting downstream impact analysis using "Last Called" filters                                      | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| **6. Business-Level Application Grouping and Severity Management**                                                                                                              |                                                                                  |
| Defining logical application groupings to map technical APIs directly to functional business units                                                                              | [AppSec Discovery](https://developer.harness.io/docs/appsec-discovery)           |
| Customizing filtering criteria and severity ratings to prioritize remediation efforts based on business risk                                                                    | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| **7. Role-Based Access Control (RBAC) and Administration**                                                                                                                      |                                                                                  |
| Enforcing administrative permissions, specifically requiring the `Module Level Access -> Discovery -> Settings` permission to create and manage application groups and policies | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| Scoping rules and security policies to "All Environments" versus restricted zones                                                                                               | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| **8. API Discovery Engine Internal Stages and Learning Logic**                                                                                                                  |                                                                                  |
| Modeling endpoint structures by observing URLs, headers, and request/response payloads in live spans                                                                            | [AppSec Discovery](https://developer.harness.io/docs/appsec-discovery)           |
| Filtering out malicious or junk traffic by strictly requiring successful HTTP response codes (between 2xx and 3xx) before learning new endpoints                                | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |
| Distinguishing between "Learning" and "Learnt" states in the API Catalog, and managing default state-filtering behavior                                                         | [API Discovery](/web-application-and-api-protection-waap/discovery/discovery.md) |

[**Register for Exam**](https://university-registration.harness.io/certification-exam-harness-certified-api-application-discovery-developer-certification)

#### Exam Details

The Harness API & Application Discovery Developer Certification exam tests your knowledge and skills of the API & Application Discovery module.

**Prerequisites**

* Basic terminal skills
* Basic understanding of Harness and API security.

**Exam Details**

Exam Duration: 90 minutes

Question Type: Multiple choice

| Covered Domain                                              | Percentage |
| ----------------------------------------------------------- | ---------- |
| GraphQL-Based Dynamic API Ownership Assignment              | 20%        |
| Dynamic Ownership Prerequisites and Operational Mechanics   | 13.3%      |
| Automating API Documentation and Specification Generation   | 13.3%      |
| API Specification Monitoring and Retrieval Workflows        | 13.3%      |
| Unified Asset Management and MCP/AI Discovery               | 16.7%      |
| Business-Level Application Grouping and Severity Management | 10%        |
| Role-Based Access Control (RBAC) and Administration         | 3.4%       |
| API Discovery Engine Internal Stages and Learning Logic     | 10%        |

**Exam Objectives**

<details>

<summary>List of Objectives</summary>

The following is a detailed list of exam objectives:

| #   | Objectives                                                                                                                                                                      |
| --- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| 1   | **GraphQL-Based Dynamic API Ownership Assignment**                                                                                                                              |
| 1.1 | Constructing and interpreting GraphQL `createPolicy` mutations for Static, Dynamic, and Regex-based policy assignments                                                          |
| 1.2 | Configuring RE2 regular expression patterns with specific capture group indices and fallback constants                                                                          |
| 1.3 | Managing active ownership policies using `getPolicies` queries, `updatePolicy` mutations, and `deletePolicies` mutations                                                        |
| 2   | **Dynamic Ownership Prerequisites and Operational Mechanics**                                                                                                                   |
| 2.1 | Configuring authentication prerequisites using JWT tokens and the `Authorization: Bearer` header                                                                                |
| 2.2 | Troubleshooting operational replication latencies and isolating span attributes in the Explorer tab                                                                             |
| 2.3 | Assessing the governance trade-offs of automated dynamic policy mapping versus manual, spreadsheet-based ownership assignment                                                   |
| 3   | **Automating API Documentation and Specification Generation**                                                                                                                   |
| 3.1 | Triggering standard OpenAPI specifications (YAML or JSON) and WSDL schemas (for SOAP APIs) using the `createApiDefinition` mutation                                             |
| 3.2 | Applying the `learningEndpointStrategy` parameters (including `MENTION` vs. `EXCLUDE` behaviors) to govern endpoint documentation                                               |
| 3.3 | Extracting domain-specific scope credentials to parameterize schema generation                                                                                                  |
| 4   | **API Specification Monitoring and Retrieval Workflows**                                                                                                                        |
| 4.1 | Checking spec generation job statuses using the `getApiDefinition` query to verify state fields, success states (`JOB_STATUS_SUCCESS`), timestamps, and error messages          |
| 4.2 | Programmatically downloading completed specification archives (`*.zip`) using REST GET clients with the `Authorization: <Platform_API_Token>` header                            |
| 5   | **Unified Asset Management and MCP/AI Discovery**                                                                                                                               |
| 5.1 | Consolidating traditional API Endpoints, AI APIs, and Model Context Protocol (MCP) components into a single system inventory                                                    |
| 5.2 | Tracking infrastructure health and data flows through core UI widgets and strategic filters                                                                                     |
| 5.3 | Troubleshooting production failures, diagnosing MCP server downtime, and conducting downstream impact analysis using "Last Called" filters                                      |
| 6   | **Business-Level Application Grouping and Severity Management**                                                                                                                 |
| 6.1 | Defining logical application groupings to map technical APIs directly to functional business units                                                                              |
| 6.2 | Customizing filtering criteria and severity ratings to prioritize remediation efforts based on business risk                                                                    |
| 7   | **Role-Based Access Control (RBAC) and Administration**                                                                                                                         |
| 7.1 | Enforcing administrative permissions, specifically requiring the `Module Level Access -> Discovery -> Settings` permission to create and manage application groups and policies |
| 7.2 | Scoping rules and security policies to "All Environments" versus restricted zones                                                                                               |
| 8   | **API Discovery Engine Internal Stages and Learning Logic**                                                                                                                     |
| 8.1 | Modeling endpoint structures by observing URLs, headers, and request/response payloads in live spans                                                                            |
| 8.2 | Filtering out malicious or junk traffic by strictly requiring successful HTTP response codes (between 2xx and 3xx) before learning new endpoints                                |
| 8.3 | Distinguishing between "Learning" and "Learnt" states in the API Catalog, and managing default state-filtering behavior                                                         |

***

</details>

**Next Steps**

The Harness API & Application Discovery Developer exam can start immediately after registering. Please allow up to 90 mins for the exam.

1. Create an account in Harness University
2. Register for an exam
3. Take the exam

[**Register for Exam**](https://university-registration.harness.io/certification-exam-harness-certified-api-application-discovery-developer-certification)
{% endtab %}

{% tab title="For Administrator" %}

### API & Application Discovery - Administrator (BETA COMING SOON)

![API & Application Discovery - Administrator (BETA COMING SOON) badge](https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-cdc1c1b4a07414cdd7ad1a0b1e5203edbfe39a21%2Fcert-adm-asp-badge.svg?alt=media)

**Product version:** API & Application Discovery Paid Plans

{% hint style="info" %}
**Coming soon**

This certification is in beta and not yet open for registration.
{% endhint %}

Assesses the fundamental skills to deploy and maintain API & Application Discovery projects and the overall Harness Platform.
{% endtab %}

{% tab title="For Architect" %}

### API & Application Discovery - Architect (BETA COMING SOON)

![API & Application Discovery - Architect (BETA COMING SOON) badge](https://2307127582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Feh03Q8VHpO02MFM5nUSL%2Fuploads%2Fgit-blob-8acf9c97fc7399f6b3cfd897b75c7ab034e0e1c7%2Fcert-arc-asp-badge.svg?alt=media)

**Product version:** API & Application Discovery Paid Plans

{% hint style="info" %}
**Coming soon**

This certification is in beta and not yet open for registration.
{% endhint %}

Assess key technical job functions and advanced skills in design, implementation and management of API & Application Discovery.
{% endtab %}
{% endtabs %}
