# Abnormal AI

**Canonical:** https://apis.io/providers/abnormal/  
**Website:** https://abnormal.ai/  
**APIs profiled:** 17

Abnormal AI (formerly Abnormal Security) is a San Francisco based cloud email and human-behavior security company whose behavioral AI platform protects Microsoft 365 and Google Workspace against phishing, business email compromise, vendor fraud, account takeover and misdirected email. The platform is API-first: it integrates with Microsoft and Google over their APIs rather than by rewriting MX records, and every capability in the Abnormal Portal — threats, cases, AI Security Mailbox, employee and vendor insights, audit logs, RBAC roles and users, security posture management and dashboard aggregations — is also reachable through the Abnormal Security Client API, a bearer-token REST API published as OpenAPI 3.0.3 on SwaggerHub with separate US and EU production hosts. Abnormal also streams the same event data to SIEM and SOAR platforms over near-real-time webhooks.

## Kin Score — 55.0 / 100 (strong)

Scored 2026-08-25 under rubric 0.14.0. Trend: flat (-0.7 from 55.7).

| Facet | Score |
|---|---|
| Discoverability | 85.2 |
| Contract Quality | 64.4 |
| Governance | 16.7 |
| Contract Governance | 16.7 |
| Operational Transparency | 52.6 |
| Developer Ergonomics | 57.7 |
| Commercial Clarity | 50.0 |
| Access Clarity | 50.0 |

## Agent readiness — 41.5 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | served |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | served |
| Protected Resource Metadata | no |
| Dynamic Client Registration | yes |
| Agentic Commerce | no |

## APIs (17)

- **Abnormal AI AI Security Mailbox (formerly known as Abuse Mailbox) API** — API to manage AI Security Mailbox (formerly known as Abuse Mailbox)
- **Abnormal AI Audit Logs API** — API to retrieve audit logs for Portal
- **Abnormal AI Cases API** — APIs to manage Abnormal Cases
- **Abnormal AI Dashboard Aggregations API** — APIs to manage Dashboard metrics
- **Abnormal AI Detection360 API** — The Detection360 API from Abnormal AI — 1 operation(s) for detection360.
- **Abnormal AI Employee Insights API** — API to manage employees
- **Abnormal AI Messages API** — API to manage message details
- **Abnormal AI Resources API** — The Resources API from Abnormal AI — 5 operation(s) for resources.
- **Abnormal AI Roles API** — API to retrieve roles from RBAC system
- **Abnormal AI Search and Respond API** — The Search and Respond API from Abnormal AI — 6 operation(s) for search and respond.
- **Abnormal AI Security Settings API** — API to retrieve security settings including session timeout configuration
- **Abnormal AI SPM API** — The SPM API from Abnormal AI — 6 operation(s) for spm.
- **Abnormal AI Threats API** — APIs to manage threats notified in the Abnormal Threat Log
- **Abnormal AI Tokens API** — API to manage SOAR API tokens
- **Abnormal AI URL Rewrite API** — The URL Rewrite API from Abnormal AI — 1 operation(s) for url rewrite.
- **Abnormal AI Users API** — API to retrieve users from RBAC system
- **Abnormal AI Vendors API** — API to manage Vendorbase and threats from Vendors

## MCP servers (1)

- **Abnormal AI MCP Server**

## Security (4)

- **Abnormal Authentication** — http · 1 scheme
- **Abnormal Domain Security** — TLSv1.3 · HSTS · DMARC
- **Abnormal Vulnerability Disclosure** — Hackerone · contact published
- **Abnormal Trust Center** — SOC 2, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 42001:2023, CSA STAR, FedRAMP Moderate, GovRAMP, TX-RAMP, CMMC, Cyber Essentials Plus, CJIS, ITAR, VPAT

## Tags

Company, Security, Email Security, Cybersecurity, Threat Intelligence, Artificial Intelligence, SOAR, Identity, Compliance

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/abnormal/). Scores are computed from the provider's own public artifacts under a published rubric.
