# Akto

**Canonical:** https://apis.io/providers/akto/  
**Website:** https://www.akto.io/  
**APIs profiled:** 0

Akto is a proactive API security platform that discovers, tests, and protects APIs and AI systems across an organization's infrastructure. Its open-source core (MIT, Java) delivers automated API discovery, API security posture management, and dynamic API security testing (DAST) in CI/CD, backed by a community test library of 1000+ tests covering the OWASP API Security Top 10 and HackerOne top vulnerabilities. Traffic is ingested from eBPF, Kubernetes, API gateways (Envoy, NGINX, Istio, Kong, Apigee, MuleSoft and more), and cloud mirroring, and can be deployed self-hosted in ~60 seconds or as SaaS. Akto has expanded into agentic AI security with Atlas (shadow-AI discovery for employee-facing endpoints) and Argus (governance and red-teaming for homegrown AI, MCP tools, and LLMs), adding runtime guardrails and human-in-the-loop testing. Recognized by Gartner in the API and AI-agent protection markets and backed by Accel.

## Kin Score — 26.5 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 26.5).

| Facet | Score |
|---|---|
| Discoverability | 57.4 |
| Contract Quality | 0.0 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 18.4 |
| Developer Ergonomics | 38.1 |
| Commercial Clarity | 53.9 |
| Access Clarity | 53.9 |

## Agent readiness — 0.0 (human-only)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Unknown — onboarding: unknown, pricing: unknown, trial: no (confidence: low).

## Security (2)

- **Akto Domain Security** — TLSv1.3 · HSTS · DMARC
- **Akto Trust Center** — SOC 2, ISO 27001, GDPR, HIPAA

## Tags

Company, API Security, Security, API Security Testing, DAST, API Discovery, AI Security, MCP Security, Open-Source, DevSecOps, Governance

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/akto/). Scores are computed from the provider's own public artifacts under a published rubric.
