ApiVista 1.3.0

dotnet add package ApiVista --version 1.3.0
                    
NuGet\Install-Package ApiVista -Version 1.3.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="ApiVista" Version="1.3.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="ApiVista" Version="1.3.0" />
                    
Directory.Packages.props
<PackageReference Include="ApiVista" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add ApiVista --version 1.3.0
                    
#r "nuget: ApiVista, 1.3.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package ApiVista@1.3.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=ApiVista&version=1.3.0
                    
Install as a Cake Addin
#tool nuget:?package=ApiVista&version=1.3.0
                    
Install as a Cake Tool

ApiVista

Drop-in live traffic dashboard and a fully custom API documentation UI for ASP.NET Web API 2 (OWIN) and ASP.NET Core applications. No external services, no Node/build tooling - the docs/dashboard UI is plain HTML/CSS/JS.

Targets net45, net46, net461, net472, net48, net481 (.NET Framework, via ASP.NET Web API 2/OWIN) and net6.0, net8.0 (ASP.NET Core) - one package, one PackageId, works either way.

What you get

  • Live traffic dashboard - total hits/success/fail, an hourly bar chart, and a per-endpoint breakdown, all computed in-memory from real requests.
  • Per-endpoint drill-down - hourly chart and a log of the most recent individual requests for one endpoint.
  • Request/response payload viewer - click a recent request to see its actual request and response body in a popup, with common sensitive field names (passwords, tokens, card numbers, etc.) automatically redacted before anything is stored.
  • Self-discovering documentation UI - no Swagger/OpenAPI spec required. ApiVista lists every endpoint your app actually has registered (via Web API 2's IApiExplorer / ASP.NET Core's ApiExplorer/route metadata - the same reflection Swashbuckle itself is built on) and renders a fully brandable Overview / Endpoints experience with a working "Try it out" (editable headers, live cURL preview, tabbed response viewer). Endpoints show up immediately, even ones that have never been called; once an endpoint has real traffic, its parameters/body are seeded from actual captured requests instead of type-driven placeholders.
  • Load test (opt-in) - a "Load test" panel next to "Try it out" fires concurrent requests (from the browser) at the selected endpoint using whatever headers/body/URL are currently filled in, and reports success/fail counts, latency percentiles, and achieved throughput.
  • Companion Tool (opt-in) - a standalone page (its own tab) that discovers endpoints purely from your app's own captured traffic (no Swagger needed), infers example payloads from real request bodies, lets you chain a prerequisite API call's response into another endpoint's request, and produces a downloadable HTML report and CSV export from a run.

Everything is in-memory and resets when the process restarts - this is a live/rolling view, not a persisted audit log.

Install: ASP.NET Web API 2 / OWIN (.NET Framework)

  1. Install this package into your ASP.NET Web API 2 project.

  2. In your WebApiConfig (or wherever you configure HttpConfiguration), add:

    config.EnableApiVista();
    

    Or override the defaults:

    config.EnableApiVista(options =>
    {
        options.RetainHours = 72;
        options.MaxRecentRequestsPerEndpoint = 100;
        options.SensitiveFieldNames.Add("accountNumber");
    });
    
  3. Copy the content/ApiVistaDocs folder (installed alongside this package) into your web project as static content, then browse to /ApiVistaDocs/index.html - your endpoints should already be listed.

Install: ASP.NET Core (.NET 6+)

  1. Install this package into your ASP.NET Core project.

  2. In Program.cs:

    var builder = WebApplication.CreateBuilder(args);
    builder.Services.AddApiVista(options =>
    {
        options.RetainHours = 72;
        options.MaxRecentRequestsPerEndpoint = 100;
    });
    
    var app = builder.Build();
    app.UseApiVista();   // register early, before UseStaticFiles/UseRouting
    app.UseStaticFiles();
    

    UseApiVista() wires up the tracking middleware and - when app is the top-level WebApplication (the common minimal-hosting pattern above) - also maps the /api/_apivista/* diagnostics endpoints automatically. If you're using a classic Startup class instead, call endpoints.MapApiVistaDiagnostics() explicitly inside your app.UseEndpoints(...) block.

  3. For full parameter/body detail on minimal API endpoints, also call builder.Services.AddEndpointsApiExplorer(); - this is the same call Swashbuckle asks for and is unrelated to Swagger itself; it just turns on ASP.NET Core's route-metadata reflection. Without it, minimal API endpoints still show up (method + route), just without parameter/body field detail until they've actually been called. MVC controllers get this automatically via AddControllers() - no extra call needed for them.

  4. Copy the content/ApiVistaDocs folder (installed alongside this package) into your project's wwwroot folder, then browse to /ApiVistaDocs/index.html - your endpoints should already be listed.

Security note

This package does not add authentication to the dashboard or diagnostics endpoints (/api/_apivista/stats, /api/_apivista/stats/endpoint, /api/_apivista/routes) - it tracks whatever your app already allows. If your API is not otherwise locked down, anyone who can reach those routes can see captured traffic (including request bodies, minus redacted fields) and your full reflected route catalog (method/path/parameter names and types, even for endpoints never called). Restrict access to these routes the same way you would any other sensitive endpoint in your app (e.g. an [Authorize] filter, IP allowlist, or a reverse-proxy rule) if that matters for your deployment.

The load test panel and the Companion Tool raise the stakes on that same risk: if enabled, anyone who can reach the docs UI can fire concurrent requests at your tracked endpoints (the Companion Tool can do this across every discovered endpoint, not just one). That's why EnableLoadTest and EnableCompanionTool both default to false - only turn them on in environments where that's acceptable (e.g. a locked-down staging environment), and consider the LoadTestMax* caps as an additional (not a replacement) safeguard alongside restricting access to the docs UI itself.

Configuration reference (ApiVistaOptions)

Option Default Purpose
TrackedPathPrefix /api/ Only paths starting with this are tracked
ExcludedPathPrefixes ["/api/_apivista"] Paths never tracked, checked after the prefix match
RetainHours 48 Hours of hourly buckets kept before pruning
MaxRecentRequestsPerEndpoint 50 Individual requests kept per endpoint for the payload drill-down
MaxBodyLength 8000 Captured request/response bodies longer than this are truncated
SensitiveFieldNames password/token/card/etc. JSON field names redacted before storage
EnableLoadTest false Whether the docs UI's "Load test" panel is available
LoadTestMaxConcurrency 20 Max concurrent in-flight requests per load test run
LoadTestMaxRequests 500 Max total requests per load test run
LoadTestMaxDurationSeconds 30 Max wall-clock duration per load test run
EnableCompanionTool false Whether the standalone Companion Tool (companion.html) is available
Product Compatible and additional computed target framework versions.
.NET net6.0 is compatible.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
.NET Framework net45 is compatible.  net451 was computed.  net452 was computed.  net46 is compatible.  net461 is compatible.  net462 was computed.  net463 was computed.  net47 was computed.  net471 was computed.  net472 is compatible.  net48 is compatible.  net481 is compatible. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.3.0 113 8/3/2026