Contact Us 1-800-596-4880

Correlating Risk Using Akamai API Security

Use Akamai for risk correlation to map external security findings to the right services in Portfolio. Teams get one view to triage risk, track incidents, and remediate faster. To enable this correlation, configure an Akamai API Security scanner that connects your Akamai account, runs scheduled scans, and surfaces mapped findings on related services in Portfolio. The scanner doesn’t import or register third-party services. It correlates risk scores, findings, and incidents for APIs and MCP services in one governance workflow.

The integration relies on a bidirectional sync between your MuleSoft and Akamai API Security tenants. You connect the two tenants with credentials in each direction: Akamai reads your API assets and instances from MuleSoft so it can match its security observations to the correct APIs, and the scanner pulls the resulting findings and incidents back into Portfolio.

Akamai Scanner vs. Import Scanners

Most provider scanners discover metadata in external platforms and import services into Portfolio catalogs. The Akamai API Security scanner works differently: instead of creating new services, it enriches existing ones with Akamai security data.

Before You Begin

Before setting up the Akamai scanner, make sure you have:

  • Exchange Administrator permission in the target business group.

  • Akamai Security base URL, client ID, and client secret.

  • Access to apply Akamai correlation policy in the environments you want to scan.

  • Existing APIs and MCP services in Portfolio catalogs for correlation targets.

For credential and role details, see Scanner Prerequisites by Provider.

Set Up Tenant Connectivity

The integration uses a bidirectional sync between your MuleSoft tenant and your Akamai API Security tenant. You provision and configure both tenants. Each MuleSoft customer tenant (root organization) connects to one Akamai API Security tenant (for example, <tenant>.nonamesec.com).

Setup involves credentials in both directions:

  • A service account in Akamai, which you configure on the MuleSoft side so the scanner can read findings and incidents from Akamai.

  • A connected app in MuleSoft, which you configure on the Akamai side so Akamai can pull API asset and instance information from MuleSoft.

Complete these steps as an organization administrator:

  1. Create a service account in Akamai API Security.

    In your Akamai API Security tenant, create a service account and note its client ID and client secret.

  2. Configure the scanner in MuleSoft.

    Add an Akamai scanner and enter the Akamai service account credentials (client ID and client secret) and the Akamai base URL, along with a scan frequency. See Set Up the Akamai Scanner.

  3. Create a connected app in MuleSoft.

    In Anypoint Platform, go to Access Management > Connected Apps and create an app that acts on its own behalf (client credentials). Add the Exchange Viewer or Asset Viewer scope so Akamai can read API instance and asset information, then save. Copy the client ID and client secret.

  4. Configure the sync on the Akamai side.

    In your Akamai API Security tenant, enter the MuleSoft connected app client ID and client secret so Akamai can pull API asset and instance information from MuleSoft.

Set Up the Akamai Scanner

Before you set up the scanner, review the prerequisites for Akamai scanners in Scanner Prerequisites by Provider.

  1. From Platform > Providers, select Akamai.

  2. Click Add Scanner and enter the connection values.

  3. Test the connection.

  4. Enter scanner metadata, such as scanner name, description, frequency, and time.

  5. Apply the Akamai correlation policy to selected environments.

  6. Save the scanner and run a discovery scan.

How the Sync Works

After both tenants are connected, data flows in two directions:

MuleSoft to Akamai

Akamai periodically pulls API instance and asset information from MuleSoft (typically every few hours) and adds it to its API security inventory. Akamai correlates these API instances with the north-south traffic it observes, so it can attach MuleSoft context — such as organization ID, environment ID, and API instance ID — to the endpoints it monitors. The pull runs at the root organization level.

Akamai to MuleSoft

The scanner pulls security findings and incidents from Akamai on the schedule you set, then correlates and stores them so they appear on the related services in Portfolio.

For Akamai to observe and correlate traffic, the Akamai correlation policy must be applied to your API instances. This out-of-the-box policy (for Flex Gateway and Mule gateways) stamps correlation headers on API responses so Akamai can match observed traffic to the correct MuleSoft API. Akamai observes north-south traffic only for domains you own and control.

Review Scanner Detail Tabs

After you select a configured Akamai scanner from the provider list, use scanner detail tabs to monitor scanner status, related services, and configuration values.

For common tab behavior across scanners, see Viewing Scanner History and Settings. For Akamai scanners, the Overview tab highlights correlation policy status and shows whether existing services are being updated with Akamai risk, findings, and incident data. The Services tab lists services associated with the scanner and shows which existing services are receiving correlated Akamai security data. The Settings tab shows scanner configuration values, including schedule and provider connection values, and provides options to edit or delete the scanner.

Apply Missing Correlation Policies

If some environments show that correlation policy isn’t applied, you can apply missing policies from the scanner detail page:

  1. Open Platform > Providers and select the configured Akamai scanner.

  2. In Overview, check the Akamai Correlation Policy status.

  3. If the status shows missing environments, click Check again to apply policy only to those environments.

  4. Wait for the status to change to Applied and confirm all target environments are covered.

If policy application fails, verify your Admin API write permissions and environment access, then retry.

Reviewing Akamai Security Results in the Enhanced Experience

After a successful run, Akamai results appear on existing services:

  • API list views show values in the Security Risk column.

  • API detail pages show Akamai security data in Conformance.

  • Security sections display violation totals, findings, incidents, and endpoint context.

  • Finding detail views show fields such as status, type, endpoint path, and mapped frameworks.

Interpret Risk Status Levels

The Security Risk column shows the risk level assigned to correlated Akamai findings:

Low

Lower urgency risk. Review and remediate in your normal security lifecycle.

Medium

Moderate risk. Prioritize remediation after high-risk issues.

High

Elevated risk. Investigate and remediate first.

Critical

Highest urgency risk. Remediate immediately.

Remediate Risks from the API Conformance Tab

Use the API Conformance tab in Portfolio to triage and remediate Akamai findings:

  1. Open the API from the APIs catalog in Portfolio.

  2. Select Conformance and review the Akamai section, including findings and incidents.

  3. Select a finding to open details, such as endpoint, severity, and mapped standards.

  4. Apply recommended remediation policies directly from the finding detail view when available.

  5. Re-run the scanner after remediation to confirm updated findings and risk levels.

If no direct remediation policy is available for a finding, use the finding details to update the API configuration in your gateway or upstream system, then scan again to verify the result.

Troubleshoot Missing Akamai Findings

If a scan completes but results don’t appear:

  • Verify the correlation policy is applied in the same environment as the service instance.

  • Confirm the target service already exists in Portfolio catalogs.

  • Confirm scanner scope and business group match the service location.

  • Re-run the scanner after connection or policy changes.