PlexTrac API

PlexTrac's JWT-authenticated REST API (v1 and v2) for managing clients, reports, findings, assets, and content-library writeups, along with tenant/RBAC administration and outbound webhooks. The base URL is the customer's own PlexTrac instance (the multi-tenant SaaS instance is app.plextrac.com); authentication is a bearer JWT obtained from POST /api/v1/authenticate with a 15-minute expiry.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/plextrac-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

API entry from apis.yml

apis.yml Raw ↑
name: PlexTrac API
description: PlexTrac's JWT-authenticated REST API (v1 and v2) for managing clients, reports, findings,
  assets, and content-library writeups, along with tenant/RBAC administration and outbound webhooks. The
  base URL is the customer's own PlexTrac instance (the multi-tenant SaaS instance is app.plextrac.com);
  authentication is a bearer JWT obtained from POST /api/v1/authenticate with a 15-minute expiry.
humanURL: https://api-docs.plextrac.com/
baseURL: https://app.plextrac.com/api/v1
tags:
- Penetration Testing
- Vulnerability Management
- Security Reporting
properties:
- type: Authentication
  url: authentication/plextrac-llc-authentication.yml
- type: Webhooks
  url: asyncapi/plextrac-llc-webhooks.yml
- type: Conventions
  url: conventions/plextrac-llc-conventions.yml
- type: Lifecycle
  url: lifecycle/plextrac-llc-lifecycle.yml
- type: Deprecation
  url: lifecycle/plextrac-llc-lifecycle.yml
- type: Conformance
  url: conformance/plextrac-llc-conformance.yml
- type: X-MCPServerCandidate
  url: mcp/plextrac-llc-mcp.yml
  note: 'Renamed from MCPServer 2026-09-03 (roadmap#247): the manifest self-describes as status: candidate
    — a tool list derived from the published API contracts, not an existing server. The scorer already
    read the manifest and reported mcp_server correctly; the MCPServer type was crediting the artifact-type
    surfaces with a server that does not exist.'