ApiVista 1.3.0
dotnet add package ApiVista --version 1.3.0
NuGet\Install-Package ApiVista -Version 1.3.0
<PackageReference Include="ApiVista" Version="1.3.0" />
<PackageVersion Include="ApiVista" Version="1.3.0" />
<PackageReference Include="ApiVista" />
paket add ApiVista --version 1.3.0
#r "nuget: ApiVista, 1.3.0"
#:package ApiVista@1.3.0
#addin nuget:?package=ApiVista&version=1.3.0
#tool nuget:?package=ApiVista&version=1.3.0
ApiVista
Drop-in live traffic dashboard and a fully custom API documentation UI for ASP.NET Web API 2 (OWIN) and ASP.NET Core applications. No external services, no Node/build tooling - the docs/dashboard UI is plain HTML/CSS/JS.
Targets net45, net46, net461, net472, net48, net481 (.NET
Framework, via ASP.NET Web API 2/OWIN) and net6.0, net8.0 (ASP.NET Core) -
one package, one PackageId, works either way.
What you get
- Live traffic dashboard - total hits/success/fail, an hourly bar chart, and a per-endpoint breakdown, all computed in-memory from real requests.
- Per-endpoint drill-down - hourly chart and a log of the most recent individual requests for one endpoint.
- Request/response payload viewer - click a recent request to see its actual request and response body in a popup, with common sensitive field names (passwords, tokens, card numbers, etc.) automatically redacted before anything is stored.
- Self-discovering documentation UI - no Swagger/OpenAPI spec required.
ApiVista lists every endpoint your app actually has registered (via Web API
2's
IApiExplorer/ ASP.NET Core'sApiExplorer/route metadata - the same reflection Swashbuckle itself is built on) and renders a fully brandable Overview / Endpoints experience with a working "Try it out" (editable headers, live cURL preview, tabbed response viewer). Endpoints show up immediately, even ones that have never been called; once an endpoint has real traffic, its parameters/body are seeded from actual captured requests instead of type-driven placeholders. - Load test (opt-in) - a "Load test" panel next to "Try it out" fires concurrent requests (from the browser) at the selected endpoint using whatever headers/body/URL are currently filled in, and reports success/fail counts, latency percentiles, and achieved throughput.
- Companion Tool (opt-in) - a standalone page (its own tab) that discovers endpoints purely from your app's own captured traffic (no Swagger needed), infers example payloads from real request bodies, lets you chain a prerequisite API call's response into another endpoint's request, and produces a downloadable HTML report and CSV export from a run.
Everything is in-memory and resets when the process restarts - this is a live/rolling view, not a persisted audit log.
Install: ASP.NET Web API 2 / OWIN (.NET Framework)
Install this package into your ASP.NET Web API 2 project.
In your
WebApiConfig(or wherever you configureHttpConfiguration), add:config.EnableApiVista();Or override the defaults:
config.EnableApiVista(options => { options.RetainHours = 72; options.MaxRecentRequestsPerEndpoint = 100; options.SensitiveFieldNames.Add("accountNumber"); });Copy the
content/ApiVistaDocsfolder (installed alongside this package) into your web project as static content, then browse to/ApiVistaDocs/index.html- your endpoints should already be listed.
Install: ASP.NET Core (.NET 6+)
Install this package into your ASP.NET Core project.
In
Program.cs:var builder = WebApplication.CreateBuilder(args); builder.Services.AddApiVista(options => { options.RetainHours = 72; options.MaxRecentRequestsPerEndpoint = 100; }); var app = builder.Build(); app.UseApiVista(); // register early, before UseStaticFiles/UseRouting app.UseStaticFiles();UseApiVista()wires up the tracking middleware and - whenappis the top-levelWebApplication(the common minimal-hosting pattern above) - also maps the/api/_apivista/*diagnostics endpoints automatically. If you're using a classicStartupclass instead, callendpoints.MapApiVistaDiagnostics()explicitly inside yourapp.UseEndpoints(...)block.For full parameter/body detail on minimal API endpoints, also call
builder.Services.AddEndpointsApiExplorer();- this is the same call Swashbuckle asks for and is unrelated to Swagger itself; it just turns on ASP.NET Core's route-metadata reflection. Without it, minimal API endpoints still show up (method + route), just without parameter/body field detail until they've actually been called. MVC controllers get this automatically viaAddControllers()- no extra call needed for them.Copy the
content/ApiVistaDocsfolder (installed alongside this package) into your project'swwwrootfolder, then browse to/ApiVistaDocs/index.html- your endpoints should already be listed.
Security note
This package does not add authentication to the dashboard or diagnostics
endpoints (/api/_apivista/stats, /api/_apivista/stats/endpoint,
/api/_apivista/routes) - it tracks whatever your app already allows. If
your API is not otherwise locked down, anyone who can reach those routes can
see captured traffic (including request bodies, minus redacted fields) and
your full reflected route catalog (method/path/parameter names and types,
even for endpoints never called). Restrict access to these routes the same
way you would any other sensitive endpoint in your app (e.g. an
[Authorize] filter, IP allowlist, or a reverse-proxy rule) if that matters
for your deployment.
The load test panel and the Companion Tool raise the stakes on that
same risk: if enabled, anyone who can reach the docs UI can fire concurrent
requests at your tracked endpoints (the Companion Tool can do this across
every discovered endpoint, not just one). That's why EnableLoadTest and
EnableCompanionTool both default to false - only turn them on in
environments where that's acceptable (e.g. a locked-down staging
environment), and consider the LoadTestMax* caps as an additional (not a
replacement) safeguard alongside restricting access to the docs UI itself.
Configuration reference (ApiVistaOptions)
| Option | Default | Purpose |
|---|---|---|
TrackedPathPrefix |
/api/ |
Only paths starting with this are tracked |
ExcludedPathPrefixes |
["/api/_apivista"] |
Paths never tracked, checked after the prefix match |
RetainHours |
48 |
Hours of hourly buckets kept before pruning |
MaxRecentRequestsPerEndpoint |
50 |
Individual requests kept per endpoint for the payload drill-down |
MaxBodyLength |
8000 |
Captured request/response bodies longer than this are truncated |
SensitiveFieldNames |
password/token/card/etc. | JSON field names redacted before storage |
EnableLoadTest |
false |
Whether the docs UI's "Load test" panel is available |
LoadTestMaxConcurrency |
20 |
Max concurrent in-flight requests per load test run |
LoadTestMaxRequests |
500 |
Max total requests per load test run |
LoadTestMaxDurationSeconds |
30 |
Max wall-clock duration per load test run |
EnableCompanionTool |
false |
Whether the standalone Companion Tool (companion.html) is available |
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net6.0 is compatible. net6.0-android was computed. net6.0-ios was computed. net6.0-maccatalyst was computed. net6.0-macos was computed. net6.0-tvos was computed. net6.0-windows was computed. net7.0 was computed. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
| .NET Framework | net45 is compatible. net451 was computed. net452 was computed. net46 is compatible. net461 is compatible. net462 was computed. net463 was computed. net47 was computed. net471 was computed. net472 is compatible. net48 is compatible. net481 is compatible. |
-
.NETFramework 4.5
- Microsoft.AspNet.WebApi.Core (>= 5.2.7)
-
.NETFramework 4.6
- Microsoft.AspNet.WebApi.Core (>= 5.2.7)
-
.NETFramework 4.6.1
- Microsoft.AspNet.WebApi.Core (>= 5.2.7)
-
.NETFramework 4.7.2
- Microsoft.AspNet.WebApi.Core (>= 5.2.7)
-
.NETFramework 4.8
- Microsoft.AspNet.WebApi.Core (>= 5.2.7)
-
.NETFramework 4.8.1
- Microsoft.AspNet.WebApi.Core (>= 5.2.7)
-
net6.0
- No dependencies.
-
net8.0
- No dependencies.
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.3.0 | 113 | 8/3/2026 |