GET STARTED
TOOLS
COMMUNITY
Explore APIs in this category. Connect any of them to your AI agent through Jentic.
Filters
REST API for the SecurityScorecard platform: manage portfolios, companies, scores, findings, and integrations. This documentation is built from two kinds of sources. Internal API docs (`servicesWithInternalApiDocs`) Specs are fetched at runtime from other microservices/repositories. Those sections are dynamic and reflect the live specs exposed by each service. - [audit](https://users.prod.ssc.camp. The API exposes 683 endpoints secured with apiKey authentication.
The Probely API provides programmatic access to a web application security scanning platform with 331 endpoints covering target management, vulnerability scanning, finding triage, reporting, and integration configuration. It supports scheduling automated DAST scans against web applications and APIs, reviewing discovered vulnerabilities by severity, assigning remediation tasks, and generating compliance reports across multiple targets and teams.
The Cryptlex Web API powers software licensing for desktop, mobile, and on-premise applications. It manages products, license keys, activations, customers, releases, and trials, and supports node-locked, floating, and consumption-based licensing models. The API exposes 284 endpoints covering activation logs, analytics, automated emails, billing, custom fields, and webhook management, with HTTPS-only access and a 50-request burst per 5-second window per IP.
Jentic publishes the only available OpenAPI specification for MISP Automation API, keeping it validated and agent-ready. MISP (Malware Information Sharing Platform) is the open-source threat intelligence platform used to share indicators of compromise across CERTs, ISACs, and security teams. The automation API exposes 165 endpoints covering events, attributes, objects, analyst data, sharing groups, taxonomies, galaxies, warninglists, sightings, feeds, and the full restSearch query language. Each MISP deployment runs at its own URL.
HCL AppScan on Cloud is a security testing platform for static, dynamic, and software composition analysis. Its v4 REST API exposes the same operations as the AppScan UI plus additional automation hooks: managing application records, launching SAST and DAST scans, exporting issues, and integrating with asset groups and policies. Security teams use it to embed AppScan into CI/CD pipelines and pull issue data into ticketing systems for triage.
PingOne provides cloud-based identity and access management with single sign-on, multi-factor authentication, directory services, and user lifecycle management. The API exposes full control over users, groups, applications, authentication policies, MFA configuration, directory synchronization, and identity verification workflows. Built for enterprises requiring CIAM (Customer Identity and Access Management) and workforce IAM at scale with OAuth 2.0, OIDC, and SAML support.
Introduction Zenduty is a cutting edge platform for incident management. With high level automation, Zenduty enables faster and better incident resolution keeping developers first. Javascript Libraries: https://github.com/Zenduty/zenduty-js Ruby Libraries: https://github.com/Zenduty/zenduty-ruby Python Libraries: https://github.com/Zenduty/zenduty-python-sdk Postman Collection for Zenduty API: htt. The API exposes 140 endpoints secured with bearer authentication.
The Mend API exposes Mend's application security platform - software composition analysis, AI dependency scanning, container image scanning, code findings, SBOM and attribution reports, and policy management - across 125 endpoints. Authentication uses a per-organisation JWT issued from a long-lived user key, with 10-minute token lifetime and cursor pagination on list endpoints. The API is designed to drive CI/CD enforcement, vulnerability triage workflows, and compliance reporting for organisations standardising on Mend's platform.
The Anchore Engine API is the primary external surface for Anchore Engine, an open-source container image scanning and policy evaluation service. Across 112 endpoints it covers accounts and users, image and repository management, archives of historical analyses, archive rules, events, policies and policy evaluation, registries, repository credentials, subscriptions, summaries, system health and configuration, and import flows for SBOM and analysis data. The spec uses HTTP Basic authentication and is typically deployed inside a customer's environment, so the base URL is whatever host the operator binds the service to.
Drata is a continuous compliance automation platform that monitors security controls across SOC 2, ISO 27001, HIPAA, and other frameworks. The V2 public API exposes 110 operations covering workspaces, controls, control notes and owners, vendors and vendor types, risk registers, personnel, policies, devices, assets, users, roles, and custom connections. Authentication is via a bearer token, suitable for headless ingestion of evidence and synchronisation of compliance state across systems. The spec is currently published as a public beta.
Jentic publishes the only available OpenAPI specification for Tenable Vulnerability Management API (Nessus), keeping it validated and agent-ready. Configure and execute vulnerability scans, export findings, manage assets, and track remediation progress across 93 endpoints covering scan lifecycle management, plugin-based detection, agent management, and workbench analytics. The API provides programmatic access to Tenable's vulnerability database with severity-scored findings, CVSS ratings, and asset-level risk prioritization for infrastructure spanning on-premise servers, cloud instances, and containerized workloads.
Jentic publishes the only available OpenAPI specification for Prisma Cloud CSPM API, keeping it validated and agent-ready. Monitor and enforce cloud security posture across AWS, Azure, and GCP environments through 91 endpoints covering alert management, compliance reporting, policy configuration, asset inventory, and cloud account onboarding. The API provides programmatic access to Prisma Cloud's risk scoring, compliance framework mapping (CIS, NIST, SOC 2, PCI-DSS), and multi-cloud asset visibility with bearer token authentication across three regional deployments.
Jentic publishes the only available OpenAPI specification for addy.io API Documentation, keeping it validated and agent-ready. addy.io is an anonymous email forwarding service that lets users create unlimited aliases backed by their real inbox, then activate, deactivate, pin, or delete those aliases as relationships with senders change. The API exposes account details, alias bulk actions, individual aliases, blocklists, recipients, custom domains, usernames, rules, failed deliveries, and more - covering every concept in the addy.io UI. Authentication is a personal access token passed as a bearer token in the Authorization header.
Jentic publishes the only available OpenAPI specification for the Azure Key Vault data plane (7.0-preview), keeping it validated and agent-ready. The KeyVaultClient performs cryptographic key operations and secret, certificate, and storage account credential operations against a vault host such as https://myvault.vault.azure.net. It exposes 78 endpoints to manage keys, secrets, certificates and their policies, soft-deleted resources and recovery, certificate issuers and contacts, and storage account access definitions.
Jentic publishes the only available OpenAPI specification for AWS WAF Classic, keeping it validated and agent-ready. AWS WAF Classic protects CloudFront distributions and Application Load Balancers from common web exploits by matching incoming requests against rules built from byte-match, IP-set, geo-match, regex, size-constraint, SQL-injection, and XSS conditions. The 77 operations cover full CRUD on every match-condition type, on rules and rate-based rules, on rule groups, and on Web ACLs, along with the change-token workflow that AWS WAF Classic uses for consistency. Note: AWS recommends WAFv2 for new deployments; this API covers the original (Classic) version.
Jentic publishes the only available OpenAPI specification for CrowdStrike Falcon API, keeping it validated and agent-ready. Detect, investigate, and respond to endpoint threats across 74 API endpoints covering host management, alert triage, incident response, IOC management, and real-time response sessions. The Falcon platform provides access to threat intelligence feeds, prevention policy configuration, spotlight vulnerability data, and event streaming for security operations centers managing thousands of endpoints. OAuth 2.0 authentication with regional cloud support (US-1, US-2, EU-1) ensures secure, multi-tenant access.
Jentic publishes the only available OpenAPI specification for Amazon GuardDuty, keeping it validated and agent-ready. Amazon GuardDuty is a continuous threat detection service that analyses VPC flow logs, CloudTrail events, DNS logs, EKS audit logs, and EBS volume data to surface suspicious activity in AWS accounts. The API covers full lifecycle management of detectors, findings, threat intelligence sets, IP allow lists, member accounts, malware protection plans, and publishing destinations across 67 operations.
Sysdig Secure REST API for cloud-native security. Provides programmatic access to runtime security, vulnerability management, compliance, posture management, identity and access management features. The API exposes 65 endpoints secured with bearer authentication.
AWS Audit Manager automates the collection of evidence for compliance audits across AWS workloads. It uses prebuilt and custom frameworks - such as PCI DSS, HIPAA, and SOC 2 - to map controls to assessable AWS services and continuously gather evidence into structured assessments and reports.
Jentic publishes the only available OpenAPI specification for AWS SecurityHub, keeping it validated and agent-ready. AWS Security Hub aggregates, normalises, and prioritises security findings from AWS services such as GuardDuty, Inspector, and Macie, plus integrated third-party products. Agents can ingest findings through BatchImportFindings, update finding status with BatchUpdateFindings, enable security standards like CIS and PCI DSS, run automated insights, and manage member accounts in a multi-account organisation. The API exposes 61 operations covering findings, controls, standards, insights, action targets, and finding aggregators.
Jentic publishes the only available OpenAPI specification for Arventa WHS Monitor API, keeping it validated and agent-ready. Arventa WHS Monitor is a cloud-based Work Health and Safety compliance platform used by Australian businesses to manage workers, sites, chemicals, incident reports, and risk assessments. The API exposes 58 endpoints across 15 resource areas including checklists, audit logs, departments, locations, and chemical storage tracking. Bearer token authentication protects all calls and the API supports paginated retrieval for high-volume operational data.
Trend Micro Vision One (formerly XDR) REST API v3.0. Provides programmatic access to detection, response, threat intelligence, and security operations capabilities including alerts, suspicious objects, endpoint actions, email actions, network security, and workbench management. The API exposes 52 endpoints secured with bearer authentication.
The Network Security API configures and manages Google Cloud network security policies - address groups, authorization policies, server and client TLS policies, gateway security policies, and security profile groups. It provides the control plane for shaping which traffic is allowed across VPC networks, load balancers, and Google Cloud workloads. Use it to define IP allow lists, enforce mTLS, attach URL filtering rules, and bind security profiles to gateways. The spec exposes 47 endpoints across regional locations and long-running operations.
Jentic publishes the only available OpenAPI specification for AWS CloudTrail, keeping it validated and agent-ready. AWS CloudTrail records management and data events across an AWS account, delivers them to S3 or an event data store, and lets you query the log with CloudTrail Lake. The API covers trails, channels, event data stores, query execution, and resource policies, so an agent can configure logging, run SQL-like queries, and pull recent events without touching the console.
NextDNS API enables programmatic control of DNS security profiles, privacy filters, and parental controls for network-level threat protection. Configure blocklists, allowlists, security policies, and privacy settings across DNS profiles, then monitor queries through real-time analytics and historical logs. Track blocked threats, analyze domain patterns, and enforce content filtering policies for devices and networks.
Jentic publishes the only available OpenAPI specification for Evervault API, keeping it validated and agent-ready. Evervault wraps encryption, decryption, relay proxying, payment-card processing, network tokenization, and webhook management into one platform. The 43-endpoint surface lets agents encrypt PII, route outbound calls through Evervault Relays that auto-decrypt or tokenize on the wire, mint network tokens for stored cards, manage Functions, and configure webhooks for event-driven flows.
Jentic publishes the only available OpenAPI specification for Netlas API, keeping it validated and agent-ready. Netlas API is an internet intelligence service that lets you query indexed data on hosts, IPs, domains, certificates, WHOIS records, and historical responses across the public internet. It exposes 42 endpoints covering host discovery, response search, certificate lookup, IP and domain WHOIS, and on-demand scanning. Use it for attack surface mapping, threat hunting, brand-protection investigations, and recon workflows that need to enumerate exposed services.
Shodan is the world's first search engine for Internet-connected devices. Use the Shodan API to search, scan, and monitor devices. The API exposes 41 endpoints secured with apiKey authentication.
Spyse is an internet assets search engine that provides comprehensive data on domains, IPs, SSL certificates, autonomous systems, CVEs, and emails. The API allows programmatic access to search, retrieve, and download internet asset data for security research and reconnaissance. The API exposes 41 endpoints secured with bearer authentication.
Jentic publishes the only available OpenAPI specification for Dradis Pro API, keeping it validated and agent-ready. Dradis Pro is a collaboration and reporting platform built for information security teams running penetration tests, vulnerability assessments, and red team engagements. The API exposes the full project lifecycle - projects, nodes, issues, evidence, notes, content blocks, document properties, and tags - so engagements can be created, populated, and reported on programmatically. Authentication is via a token in the Authorization header, suitable for headless ingestion of scanner output and automated report assembly.
The GitGuardian API powers automated secret detection and remediation across source code and developer pipelines. Agents can submit content for scanning, list and triage incidents, manage honeytokens, administer teams and members, configure connected sources, and pull audit logs. The API uses an ApiKey scheme and offers both US and EU production hosts to support regional data residency requirements.
The Black Kite API is the programmatic surface of Black Kite's cyber risk intelligence platform, used to assess third-party and supply chain risk from technical, compliance, and financial perspectives. It exposes operations to manage the catalogue of monitored companies and their attack-surface assets (domains, subdomains, IPs, IP blocks, ASNs, cloud associations), pull risk score summaries and monthly trends, and generate or download company risk reports. The published rate limit is 60 requests per minute.
BOOK A DEMO
Browse thousands of APIs and connect them all to your agent with Jentic One. One layer, one credential — every API your agent needs.