Sonar — API Inventory

iOS app by NYRAI LLC. Developer Tools · NYRAI LLC

Store rating
0 / 5
Store rating count
0
Download price
29.99 USD
In-app purchases
Unknown
Version
1.1.0
Listing last refreshed
2026-09-12

View the original store listing

Store description excerpt

Sonar builds a complete inventory of every external API call your own apps make — and it does it entirely on your Mac. Point Sonar at your iOS, web, or mixed source projects and it statically scans the code to surface a clean dashboard of every outbound dependency: raw HTTP and HTTPS endpoints, plus the third-party SDKs each project pulls in. In seconds you can answer the questions that usually take hours of manual grep: Which services does this app actually talk to? What endpoints are baked into the client? Did a forgotten key or token slip into source? EVERYTHING STAYS ON YOUR MACHINE Sonar performs 100% on-device static analysis. Your source code is never uploaded, never sent to a server, and never shared. There is no account, no login, no telemetry, and no network round-trip required to scan. What you scan stays on your Mac, full stop. SEE EVERY API CALL - Detects raw HTTP and HTTPS endpoints written directly in your client code. - Identifies third-party SDK usage across your projects. - Recognizes popular services out of the box, including Supabase, Stripe, Firebase, Anthropic, OpenAI, Replicate, ElevenLabs, Resend, DocuSign, and Google. - Organizes findings into a per-app dashboard so you can compare projects at a glance. CATCH SECRETS BEFORE THEY SHIP Sonar flags possible secrets — API keys, tokens, and credentials — that may be hardcoded in client source, so you can rotate or move them before they reach production or the App Store. CONFIGURABLE, NOT LOCKED DOWN and you can add your own rules to detect any internal API, vendor, or pattern your team cares about. Tune Sonar to match your stack instead of fighting a fixed list. FAST RESCANS Sonar parses Swift and JavaScript/TypeScript today. Rescans are incremental: only the files that changed are re-parsed, so keeping your inventory current is quick even on large codebases. SAFE BY DEFAULT Sonar is strictly read-only. It analyzes your source and never modifies, moves, or deletes a single file in your projects. WHO IT'S FOR - Indie developers who want to know exactly what their apps phone home to. - App studios standardizing security and dependency reviews across a portfolio. - Security-conscious engineers auditing client-side surface area. - Agencies reviewing the apps they build for clients. Sonar gives you the visibility of a manual security audit with the speed of a static analyzer — privately, on your own Mac. What's New Initial release of Sonar. - On-device static analysis of your iOS and web source. - Per-app dashboard of every HTTP/HTTPS endpoint and third-party SDK. - Built-in detection for Supabase, Stripe, Firebase, Anthropic, OpenAI, Replicate, ElevenLabs, Resend, DocuSign, and Google. - Possible-secret flagging for hardcoded keys and tokens in client source. - Editable JSON rule packs — add detection for any service you use. - Incremental rescans that re-parse only

Review coverage

AppRill has captured 0 reviews for this app. This is a collected sample, separate from the store rating count. Latest review capture: Not captured yet.

Recent captured chart positions

No chart positions have been captured for this app yet.

Chart position, rating count and review coverage do not establish downloads, revenue or profit. Understand the differences.