Acronis scores 83.9 on the Kin Score, band exemplar, up 2.6 from 81.3 at the last run. Its Agent Readiness is 56.3, band agent-native. For a cyber protection vendor whose customers are mostly managed service providers running thousands of tenants, that is the record you would hope to find, and most of it holds up.
The one gap that matters most for agents sits in the part of the surface a security company should own outright: authorization.
What is in the surface
Acronis publishes 12 OpenAPI definitions on developer.acronis.com. The catalog splits them into 71 API pages, from Tenants, Users and Agents through Backups, Alerts, Incidents, Invoices and the Event Manager. There are 74 contracts in the record, 4 of them derived by us, and every one is 100% callable. There is an AsyncAPI description for event webhooks and five documented rate limits.
| Facet | Score |
|---|---|
| Access clarity | 100.0 |
| Developer ergonomics | 86.3 |
| Operational transparency | 76.3 |
| Discoverability | 71.7 |
| Contract quality | 61.5 |
| Contract governance | 45.5 |
Access clarity at a perfect 100 and ergonomics at 86.3 are the MSP story: self-serve signup, a published authorization server, and docs built for someone scripting tenant provisioning at scale.
The MCP server is theirs
The part that sets Acronis apart is that it did the agent work itself. @acronis-platform/mcp went up on npm at v1.0.1 on 2026-07-22. It exposes 160 tools, 157 of them mapped to API operations, and authenticates with OAuth client credentials against the Acronis IDP. It runs locally over stdio. Acronis serves no hosted remote endpoint, so the operator runs the server. The provenance marks the MCP server and the agent skill as first-party, and the agent-readiness record backs that up with verified idempotency, verified error semantics, a verified rate-limit signal and documented reversibility. Thirty providers in a catalog of 29,172 carry all four.
The operation map on the page is ours. It counts 320 operations, 167 acting and 5 flagged human-in-the-loop, and none of that counts toward the score.
Ninety scopes, no descriptions
The 12 definitions declare 90 OAuth scope strings across client credentials, authorization code and password flows. Every description is empty. The apis.io scopes record reads “OAuth 2.0, no documented scopes,” and from a reader’s side that is accurate. Two of the strings are templates filled with a query at request time, which you learn only by reading the raw spec.
That is the gap to fix. A scope that nobody describes can only be granted blindly. An agent holding a credential for a backup platform, with 167 operations that change state, needs to know what event_manager publisher versus subscriber actually permits before a human approves it. Contract governance at 45.5, the lowest facet, reflects the same looseness.
The unlit agent dimensions follow from it: no protected resource metadata, no dynamic client registration, no consent identity, no agent card, no dry-run mode.
What would move the number
Describe the 90 scopes in the OpenAPI definitions, and publish protected resource metadata that points at the IDP Acronis already runs. Both come from the security team, not the docs team, and both are the kind of work only a provider can do.
The full profile is at apis.io/providers/acronis/.