AI Access Abuse Analyzer
An AI access abuse analyzer aggregates an API access log by user and flags the patterns that separate a script from a person: bursts of requests inside a minute, one key consuming most of the token budget, calls to sensitive endpoints, and intervals so regular no human could produce them.
Last reviewed by the Radiatus Cloud team
Paste access logs to detect anomalies, high-velocity requests, and injection attempts.
Securing AI in production?
We build guardrails, governance & compliance for AI systems.
What it reads
Paste one request per line, either JSON (with user, endpoint, tokens and time fields, under any of several common names) or a comma-separated user,endpoint,tokens,time. The tool groups by user and computes, per user, total requests, tokens consumed, distinct endpoints, and the peak number of requests in any 60-second window.
The abuse signals
- Burst: more requests in one minute than your threshold, consistent with a loop rather than a person.
- Token hoarding: one key taking more than half of all tokens when several users are present, which is either a batch job or a leaked credential.
- Sensitive endpoints: any hit on admin, keys, export, billing, internal or debug paths.
- Off-hours: most activity between midnight and 6am UTC.
- Machine timing: request intervals with a coefficient of variation under 0.15, meaning near-perfect regularity. Humans are irregular; a fixed 2-second poll is not.
Why timing regularity is the strongest tell
Rate limits catch volume, but a patient scraper stays under them. What it cannot easily hide is rhythm: a script fires at a constant cadence, so the standard deviation of its inter-request gaps is tiny relative to the mean. The analyzer computes that ratio and flags it, which surfaces slow, deliberate abuse that volume thresholds miss.
Scope and privacy
Everything runs in the browser; the log is not uploaded. It is a triage aid over a sample, not a live detection system. Feed it an hour of logs to find which keys deserve a closer look, then investigate those in your real monitoring.
Related tools
- AI Prompt Leakage Analyzer — Paste a system prompt and a hostile user input to see whether the prompt holds secrets and whether the input carries injection patterns. Local, instant.
- Prompt Injection Simulator — Paste a system prompt and an attack prompt to classify the injection technique (override, jailbreak, extraction, delimiter escape, indirect, tool abuse) and see how each defence layer treats it.
- API Rate Limit Simulator — Simulate request bursts to visualize token bucket algorithms.
- JWT Risk Analyzer — Paste a JWT to decode its header and payload and flag security risks: alg none, jku/x5u header injection, missing expiry, millisecond timestamps and personal data in claims.
Frequently Asked Questions
What log format does it accept?
One request per line, as JSON with user, endpoint, tokens and time fields (several common field names are recognised) or as comma-separated user,endpoint,tokens,time. Missing fields are tolerated; more fields give more signals.
Is the log uploaded for analysis?
No. Parsing and all statistics run in your browser. You can analyse internal API logs without them leaving the page.
Why flag regular timing rather than just high volume?
A careful abuser stays under rate limits, so volume alone misses them. A script still fires at a steady cadence, giving its inter-request intervals a very low coefficient of variation. That rhythm is hard to disguise and reveals automation that volume thresholds do not.
What counts as token hoarding?
One user or key consuming more than half of all tokens in the sample when several users are present. That is normal for a designated batch job and suspicious for a general user key, which may be leaked.
Can I use this as live abuse detection?
No. It analyses a pasted sample for triage. Use it to identify which keys or users to investigate, then rely on your real-time monitoring and rate limiting for enforcement.
Privacy & Security
Analysis done locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
AI Prompt Leakage Analyzer
AI SecurityPaste a system prompt and a hostile user input to see whether the prompt holds secrets and whether the input carries injection patterns. Local, instant.
Prompt Injection Simulator
AI SecurityPaste a system prompt and an attack prompt to classify the injection technique (override, jailbreak, extraction, delimiter escape, indirect, tool abuse) and see how each defence layer treats it.
API Rate Limit Simulator
DeveloperSimulate request bursts to visualize token bucket algorithms.