Alcatraz AI website screenshot

Alcatraz AI

Alcatraz AI, Inc. builds privacy-first facial authentication for enterprise physical access control, replacing badges, cards and PINs with the face. Its flagship edge device, Rock X, installs in-line between any Wiegand or OSDP reader and an existing access control system and authenticates people in real time at the edge without storing or transmitting a facial image. Founded in 2016 in Cupertino, California, the company pioneered Facial-Authentication-as-a-Service (FAaaS) and layers tailgating detection, 3D liveness, ONVIF video-at-the-door and SIP intercom onto a single reader, managed through a cloud or on-premises Admin Portal with native C-CURE and Genetec integrations and a customer-facing REST API secured with an x-alcatraz-api-key header.

Alcatraz AI publishes 1 API on the APIs.io network. Tagged areas include Company, Access Control, Biometrics, Facial Authentication, and Physical Security.

Alcatraz AI’s developer surface includes documentation, support, engineering blog, authentication, and 11 more developer resources.

22.4/100 emerging ▬ flat Agent 9/100 agent aware Full breakdown ↓
scored 2026-08-17 · rubric v0.11.0
1 APIs
CompanyAccess ControlBiometricsFacial AuthenticationPhysical SecurityIdentityInternet of ThingsArtificial Intelligence

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-17 · rubric v0.11.0
Composite quality — 22.4/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 5.2 / 20
Commercial Clarity 7.4 / 20
Operational Transparency 0.7 / 13
Governance 1.5 / 12
Discoverability 7.6 / 10
Agent readiness — 9/100 · agent aware
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/alcatraz-ai: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

Alcatraz Admin Portal API

Customer-facing REST API for the Alcatraz Admin Portal, used by third-party projects and applications to administer Rock devices, users, profiles and events. Access is authorize...

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Alcatraz Ai Authentication

apiKey · 1 scheme

SECURITY

Alcatraz Ai Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Alcatraz Ai Trust Center

SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018

SECURITY

Resources

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 2

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: alcatraz-ai
name: Alcatraz AI
description: Alcatraz AI, Inc. builds privacy-first facial authentication for enterprise physical access control, replacing
  badges, cards and PINs with the face. Its flagship edge device, Rock X, installs in-line between any Wiegand or OSDP reader
  and an existing access control system and authenticates people in real time at the edge without storing or transmitting
  a facial image. Founded in 2016 in Cupertino, California, the company pioneered Facial-Authentication-as-a-Service (FAaaS)
  and layers tailgating detection, 3D liveness, ONVIF video-at-the-door and SIP intercom onto a single reader, managed through
  a cloud or on-premises Admin Portal with native C-CURE and Genetec integrations and a customer-facing REST API secured with
  an x-alcatraz-api-key header.
image: https://cdn.prod.website-files.com/67e2614c2319766b465b0ce2/6904b90a7255ef89e1191eca_open-graph-main.jpg
url: https://raw.githubusercontent.com/api-evangelist/alcatraz-ai/refs/heads/main/apis.yml
x-type: company
x-source: harvest:secondary-market
x-tier: stub
x-tier-reason: harvest
specificationVersion: '0.20'
created: '2026-08-06'
modified: '2026-08-06'
tags:
- Company
- Access Control
- Biometrics
- Facial Authentication
- Physical Security
- Identity
- Internet of Things
- Artificial Intelligence
apis:
- aid: alcatraz-ai:admin-portal-api
  name: Alcatraz Admin Portal API
  description: Customer-facing REST API for the Alcatraz Admin Portal, used by third-party projects and applications to administer
    Rock devices, users, profiles and events. Access is authorized with an API key generated in the Admin Portal (Accounts
    > Account Settings > API Keys) and passed in the x-alcatraz-api-key header. The endpoint reference is published only inside
    the authenticated Admin Portal via its API Docs button; the vendor directs everyone else to their Alcatraz AI account
    manager.
  humanURL: https://support.alcatraz.ai/api-keys
  baseURL: https://platform.alcatraz.ai/api/v2/
  tags:
  - Access Control
  - Biometrics
  - Identity
  properties:
  - type: Documentation
    url: https://support.alcatraz.ai/api-keys
  - type: Authentication
    url: authentication/alcatraz-ai-authentication.yml
  x-evidence:
    base_url_source: https://alcatraz-docs.s3.us-west-2.amazonaws.com/Guides/Alcatraz+AI+Admin+Portal+Guide+v2.5.pdf
    base_url_source_note: 'Section 3.1.7.2 API Key Documentation: "Request URL for Alcatraz AI API is https://platform.alcatraz.ai/api/v2/"
      and "use the authentication header: x-alcatraz-api-key"'
    checked: '2026-08-06'
    host_resolves: false
    host_resolution_note: platform.alcatraz.ai returned NXDOMAIN from 8.8.8.8, 1.1.1.1 and 9.9.9.9 on 2026-08-06; the documented
      API host is not resolvable from the public internet.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: DomainSecurity
  url: security/alcatraz-ai-domain-security.yml
- type: Website
  url: https://www.alcatraz.ai/
- type: Documentation
  url: https://support.alcatraz.ai/
- type: Support
  url: https://support.alcatraz.ai/
- type: HelpCenter
  url: https://support.alcatraz.ai/
- type: Blog
  url: https://www.alcatraz.ai/blog
- type: GitHubOrganization
  url: https://github.com/Alcatraz-ai
- type: TermsOfService
  url: https://www.alcatraz.ai/utilities/terms-of-service
- type: PrivacyPolicy
  url: https://www.alcatraz.ai/utilities/privacy-policy
- type: TrustCenter
  url: security/alcatraz-ai-trust-center.yml
- type: Compliance
  url: https://www.alcatraz.ai/resources/security
- type: LLMsTxt
  url: llms/alcatraz-ai-llms.txt
- type: Authentication
  url: authentication/alcatraz-ai-authentication.yml
- type: Conformance
  url: conformance/alcatraz-ai-conformance.yml
- type: Lifecycle
  url: lifecycle/alcatraz-ai-lifecycle.yml
x-enrichment:
  date: '2026-08-06'
  status: minimal
  artifacts_added: 6
  pass: local-v1
x-coverage:
  state: gated
  reason: customer-only-docs
  detail: Alcatraz publishes that a REST API exists at https://platform.alcatraz.ai/api/v2/ behind an x-alcatraz-api-key header,
    but the endpoint reference is only reachable from the "API Docs" button inside the authenticated Admin Portal, the Help
    Center tells everyone else to "contact your Alcatraz AI account manager", and the documented API host does not even resolve
    from the public internet.
  evidence:
  - url: https://support.alcatraz.ai/api-keys
    status: 200
  - url: https://www.alcatraz.ai/openapi.json
    status: 404
  - url: https://platform.alcatraz.ai/api/v2/
    status: 0
  checked: '2026-08-06'