# Aembit

**Canonical:** https://apis.io/providers/aembit/  
**Website:** https://aembit.io/  
**APIs profiled:** 2

Aembit is a Workload Identity and Access Management (Workload IAM) platform for non-human identities — AI agents, applications, microservices, CI/CD pipelines, scripts and service accounts. Instead of long-lived, hard-coded secrets, Aembit cryptographically attests a workload against a Trust Provider (AWS, Azure, GCP, GitHub Actions, GitLab, Kubernetes, Terraform Cloud, OIDC, SPIFFE, Kerberos), evaluates an Access Policy with optional conditional-access signals from CrowdStrike and Wiz, and injects a short-lived credential just-in-time so the application never stores one. The platform is delivered as a SaaS control plane (Aembit Cloud) plus a distributed enforcement layer (Aembit Edge — Agent Proxy, Agent Injector, AWS Lambda extension, CLI and Edge SDKs). Aembit publishes two OpenAPI 3.1.1 contracts — the Aembit Cloud API for managing every platform resource and the Aembit Edge API for workload authentication and credential retrieval — alongside a hosted, read-only MCP Server for querying audit, authorization and workload events, an MCP Identity Gateway and an MCP Authorization Server for governing AI-agent access to MCP servers.

## Kin Score — 71.5 / 100 (exemplar)

Scored 2026-09-10 under rubric 0.20.0.

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 65.1 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 84.2 |
| Developer Ergonomics | 76.8 |
| Commercial Clarity | 85.5 |
| Access Clarity | 85.5 |

## Agent readiness — 55.4 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | served |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | verified |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | served |
| Protected Resource Metadata | verified |
| Dynamic Client Registration | yes |
| Agentic Commerce | no |

## APIs (3)

- **Aembit Cloud API** — The Aembit Cloud API is the management and control plane contract for the Aembit platform. It exposes 165 operations across 74 paths for Access Policies, Access Conditions, Clie...
- **Aembit Edge API** — The Aembit Edge API is the workload-facing runtime contract. Two operations let a Client Workload bootstrap a session by presenting attestation evidence to a configured Trust Pr...
- **Aembit MCP Server** — A first-party hosted Model Context Protocol server that gives AI agents and MCP clients read-only access to a tenant's Aembit event logs. Three tools — get_audit_logs, get_auth_...

## MCP servers (1)

- **Aembit MCP Server**

## Agentic access (1)

- **Aembit Agentic Access** — 167 operations · 98 acting · 5 human-in-the-loop

## Security (4)

- **Aembit Authentication** — http · 2 schemes
- **Aembit Domain Security** — TLSv1.3 · HSTS · DMARC
- **Aembit Vulnerability Disclosure** — Hackerone · contact published
- **Aembit Trust Center** — SOC 2, ISO 27001

## Plans (1)

- **Aembit Plans Pricing**

## Tags

Security, Identity, Access Management, Workload Identity, Non-Human Identity, Secrets Management, Zero Trust, Agentic AI, Model Context Protocol, Authentication, Authorization, DevSecOps, Cloud Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/aembit/). Scores are computed from the provider's own public artifacts under a published rubric.
