# AirMDR

**Canonical:** https://apis.io/providers/airmdr/  
**Website:** https://airmdr.com/  
**APIs profiled:** 4

AirMDR is an AI-native managed detection and response (MDR) provider whose virtual security analyst, Darryl, automates alert triage, investigation and response across endpoint, cloud, SaaS, identity, email and network tools. The platform ingests alerts from 200+ integrations, runs automated or AI-generated investigation playbooks, and produces documented cases; it is sold as a full-service MDR for small security teams, an AI SOC platform for MSSPs and enterprise SOCs, and a free plan with 100 alert investigations. Programmatic access is a REST API on app.airmdr.com (Case Manager and User Management services, documented in Redoc), authenticated with an API token sent as a Session cookie, plus a webhook endpoint for pushing alerts into the platform.

## Kin Score — 55.1 / 100 (strong)

Scored 2026-10-09 under rubric 0.23.0. Trend: flat (+0.0 from 55.1).

| Facet | Score |
|---|---|
| Discoverability | 81.7 |
| Contract Quality | 52.2 |
| Contract Governance | 4.5 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 59.5 |
| Access Clarity | 59.2 |

Regulatory layer — **Horizontal (data, software, accessibility, platform)**: 20.6 (matched via fallback).

## Agent readiness — 45.8 (agent-native)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | documented |
| MCP Server | documented |
| Auth Clarity | bearer |
| Idempotency | verified |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | yes |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## APIs (23)

- **AirMDR Documentation MCP Server** — Hosted, unauthenticated Streamable-HTTP MCP server on the AirMDR documentation host (Mintlify-operated) exposing three tools: search the AirMDR documentation, run read-only quer...
- **AirMDR Alert Catalog API** — The AlertCatalog API from AirMDR — 8 operation(s) for alertcatalog.
- **AirMDR Alerts API** — The Alerts API from AirMDR — 15 operation(s) for alerts.
- **AirMDR Alert Types API** — The AlertTypes API from AirMDR — 3 operation(s) for alerttypes.
- **AirMDR Case Manager API** — The Case Manager API from AirMDR — 32 operation(s) for case manager.
- **AirMDR Case Manager Internal API** — The Case Manager Internal API from AirMDR — 10 operation(s) for case manager internal.
- **AirMDR Case Manager V2 API** — The Case Manager V2 API from AirMDR — 43 operation(s) for case manager v2.
- **AirMDR Case Decision Automation API** — The CaseDecisionAutomation API from AirMDR — 4 operation(s) for casedecisionautomation.
- **AirMDR Dashboard API** — The Dashboard API from AirMDR — 20 operation(s) for dashboard.
- **AirMDR Internal API** — The Internal API from AirMDR — 8 operation(s) for internal.
- **AirMDR Mitre Tactics API** — The MitreTactics API from AirMDR — 1 operation(s) for mitretactics.
- **AirMDR Organization API** — Endpoints to manage organizations
- **AirMDR Password API** — Endpoints to manage user password
- **AirMDR Permission API** — Endpoints to read system permissions
- **AirMDR Ping API** — The Ping API from AirMDR — 1 operation(s) for ping.
- **AirMDR Query DSL API** — The Query DSL API from AirMDR — 3 operation(s) for query dsl.
- **AirMDR Security Review API** — The Security Review API from AirMDR — 5 operation(s) for security review.
- **AirMDR Session API** — Endpoints to manage sessions
- **AirMDR Token API** — Endpoints to manage tokens
- **AirMDR Trial API** — The Trial API from AirMDR — 1 operation(s) for trial.
- **AirMDR User API** — Endpoints to manager users
- **AirMDR User Group API** — Endpoints to manage user groups
- **AirMDR Webhooks API** — The Webhooks API from AirMDR — 3 operation(s) for webhooks.

## MCP servers (1)

- **AirMDR documentation MCP** — Remote MCP server at docs.airmdr.com over streamable HTTP; 3 tools listed.

## Security (2)

- **Airmdr Authentication** — apiKey · 2 schemes
- **Airmdr Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC

## Plans (1)

- **Airmdr Plans Pricing**

## Tags

Security, Managed Detection and Response, Security Operations, Alert Triage, Incident Response, AI Agents, SOC Automation, Threat Detection, MCP, A2A

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/airmdr/). Scores are computed from the provider's own public artifacts under a published rubric.
