Amazon Security Hub website screenshot

Amazon Security Hub

AWS Security Hub is a cloud security posture management service that provides a comprehensive view of your security state across AWS accounts. It aggregates, organizes, and prioritizes security findings from multiple AWS services and third-party tools, enabling centralized security monitoring, compliance checking, and automated remediation workflows.

Amazon Security Hub publishes 5 APIs on the APIs.io network, including Administration API, Findings API, Insights API, and 2 more. Tagged areas include Compliance, Monitoring, and Security.

The Amazon Security Hub catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Amazon Security Hub’s developer surface includes developer portal, getting-started guide, documentation, API reference, developer console, signup flow, pricing, and 27 more developer resources.

66.5/100 exemplar ▬ flat Agent 28/100 agent aware Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemium
5 APIs 8 Features 6 Use Cases
ComplianceMonitoringSecurity

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 66.5/100 · exemplar
Contract Quality 16.4 / 25
Developer Ergonomics 10.4 / 20
Commercial Clarity 17.4 / 20
Operational Transparency 6.8 / 13
Governance 8.3 / 12
Discoverability 7.2 / 10
Agent readiness — 28/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/amazon-security-hub: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 5

Individual APIs this provider publishes, each with its own machine-readable definition.

Amazon Security Hub Administration API

Operations for enabling and configuring Security Hub.

Amazon Security Hub Findings API

Operations for managing security findings.

Amazon Security Hub Insights API

Operations for managing security insights.

Amazon Security Hub Integrations API

Operations for managing product integrations.

Amazon Security Hub Standards API

Operations for managing security standards.

Postman Collections 1

Ready-to-run Postman collections for exercising this provider's APIs.

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Amazon Security Hub

OPEN COLLECTION

Arazzo Workflows 6

Multi-step API workflows described with the Arazzo specification.

Amazon Security Hub Bootstrap Posture Baseline

Enable Security Hub, confirm its standards, and capture an initial findings baseline.

ARAZZO

Amazon Security Hub Enable Hub and Review Standards

Enable Security Hub for the account and review which security standards are now available.

ARAZZO

Amazon Security Hub Onboard Product Integration

Enable a partner product integration and verify its findings flow into Security Hub.

ARAZZO

Amazon Security Hub Review Insight Findings

List a saved insight and drill into the findings behind it.

ARAZZO

Amazon Security Hub Standards Compliance Audit

List the enabled security standards and pull the failing compliance findings behind them.

ARAZZO

Amazon Security Hub Triage and Update Findings

Retrieve high-severity findings and update them by re-importing the modified records.

ARAZZO

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Amazon Security Hub Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 8

Notable capabilities this provider offers.

Multi-Account Findings Aggregation

Aggregate security findings from across multiple AWS accounts and regions into a single pane of glass.

AWS Security Finding Format (ASFF)

Standardized JSON format for all security findings enabling consistent analysis and automation.

Built-in Compliance Standards

Automated compliance checks against CIS AWS Foundations, PCI DSS, NIST, SOC 2, and AWS Foundational Security Best Practices.

Third-Party Integrations

Ingest findings from 80+ third-party security partners including CrowdStrike, Palo Alto Networks, and Splunk.

Automated Remediation

Trigger automated remediation via Amazon EventBridge and AWS Security Hub automated response and remediation.

Security Insights

Correlated views of security findings to highlight areas needing attention.

Custom Actions

Create custom actions to send findings to ticketing, chat, and SOAR platforms.

Cross-Region Aggregation

Aggregate findings across multiple AWS regions into a designated aggregation region.

Scroll for all 8

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Amazon Security Hub Context

1 classes · 15 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Amazon Security Hub API Rules

5 rules · 4 warnings 1 info

SPECTRAL

Amazon Security Hub API Rules

22 rules · 8 errors 12 warnings 2 info

SPECTRAL

JSON Schema 1

Standalone JSON Schema definitions for this provider's data models.

Finding

15 properties

JSON SCHEMA

JSON Structure 1

JSON Structure definitions describing this provider's data shapes.

Amazon Security Hub Finding Structure

15 properties

JSON STRUCTURE

Examples 1

Example request and response payloads for these APIs.

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Amazon Security Hub Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Amazon Security Hub Vulnerability Disclosure

security.txt · contact published

SECURITY

Amazon Security Hub Trust Center

PCI DSS, HIPAA, FedRAMP, GDPR, FIPS 140

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Amazon Security Hub Agentic Access

6 operations · 5 acting

6 operations · 5 acting

AGENTIC

Use Cases 6

What developers build with this provider.

Cloud Security Posture Management

Continuously monitor your AWS environment for security misconfigurations and compliance gaps.

Compliance Reporting

Automate compliance checks and generate reports for CIS, PCI DSS, NIST, and other frameworks.

Multi-Account Security Operations

Centralize security monitoring across dozens or hundreds of AWS accounts in an organization.

Threat Detection Aggregation

Aggregate findings from GuardDuty, Inspector, Macie, and third-party tools in one place.

Automated Incident Response

Trigger automated remediation workflows when critical findings are detected.

Security Tool Consolidation

Replace multiple point solutions with centralized finding aggregation and normalized data.

Resources

Get Started 4

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 10

Pagination, idempotency, versioning, errors, and events

Scroll for all 10

Build 3

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Learn 1

Tutorials, courses, talks, and written guidance

Operate 4

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
accessModel:
  pricing: freemium
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Freemium
  confidence: medium
  source:
  - plans
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/amazon-security-hub.png
name: Amazon Security Hub
description: AWS Security Hub is a cloud security posture management service that provides a comprehensive view of your security
  state across AWS accounts. It aggregates, organizes, and prioritizes security findings from multiple AWS services and third-party
  tools, enabling centralized security monitoring, compliance checking, and automated remediation workflows.
url: https://aws.amazon.com/security-hub/
baseURL: https://securityhub.amazonaws.com
kind: company
created: '2024-01-15'
modified: '2026-05-19'
tags:
- AWS
- Compliance
- Monitoring
- Security
apis:
- aid: amazon-security-hub:amazon-security-hub-administration-api
  name: Amazon Security Hub Administration API
  description: Operations for enabling and configuring Security Hub.
  humanURL: https://docs.aws.amazon.com/securityhub/latest/APIReference/
  baseURL: https://securityhub.{region}.amazonaws.com
  tags:
  - Administration
  properties:
  - type: OpenAPI
    url: openapi/amazon-security-hub-administration-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/securityhub/latest/APIReference/
  - type: JSONSchema
    url: json-schema/amazon-security-hub-finding-schema.json
- aid: amazon-security-hub:amazon-security-hub-findings-api
  name: Amazon Security Hub Findings API
  description: Operations for managing security findings.
  humanURL: https://docs.aws.amazon.com/securityhub/latest/APIReference/
  baseURL: https://securityhub.{region}.amazonaws.com
  tags:
  - Findings
  properties:
  - type: OpenAPI
    url: openapi/amazon-security-hub-findings-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/securityhub/latest/APIReference/
  - type: JSONSchema
    url: json-schema/amazon-security-hub-finding-schema.json
- aid: amazon-security-hub:amazon-security-hub-insights-api
  name: Amazon Security Hub Insights API
  description: Operations for managing security insights.
  humanURL: https://docs.aws.amazon.com/securityhub/latest/APIReference/
  baseURL: https://securityhub.{region}.amazonaws.com
  tags:
  - Insights
  properties:
  - type: OpenAPI
    url: openapi/amazon-security-hub-insights-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/securityhub/latest/APIReference/
  - type: JSONSchema
    url: json-schema/amazon-security-hub-finding-schema.json
- aid: amazon-security-hub:amazon-security-hub-integrations-api
  name: Amazon Security Hub Integrations API
  description: Operations for managing product integrations.
  humanURL: https://docs.aws.amazon.com/securityhub/latest/APIReference/
  baseURL: https://securityhub.{region}.amazonaws.com
  tags:
  - Integrations
  properties:
  - type: OpenAPI
    url: openapi/amazon-security-hub-integrations-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/securityhub/latest/APIReference/
  - type: JSONSchema
    url: json-schema/amazon-security-hub-finding-schema.json
- aid: amazon-security-hub:amazon-security-hub-standards-api
  name: Amazon Security Hub Standards API
  description: Operations for managing security standards.
  humanURL: https://docs.aws.amazon.com/securityhub/latest/APIReference/
  baseURL: https://securityhub.{region}.amazonaws.com
  tags:
  - Standards
  properties:
  - type: OpenAPI
    url: openapi/amazon-security-hub-standards-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/securityhub/latest/APIReference/
  - type: JSONSchema
    url: json-schema/amazon-security-hub-finding-schema.json
common:
- type: AgenticAccess
  url: agentic-access/amazon-security-hub-agentic-access.yml
- type: TrustCenter
  url: security/amazon-security-hub-trust-center.yml
- type: VulnerabilityDisclosure
  url: security/amazon-security-hub-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/amazon-security-hub-domain-security.yml
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/amazon-security-hub/overview
- type: Arazzo
  url: arazzo/amazon-security-hub-bootstrap-posture-baseline-workflow.yml
  name: Amazon Security Hub Bootstrap Posture Baseline
- type: Arazzo
  url: arazzo/amazon-security-hub-enable-hub-and-review-standards-workflow.yml
  name: Amazon Security Hub Enable Hub and Review Standards
- type: Arazzo
  url: arazzo/amazon-security-hub-onboard-product-integration-workflow.yml
  name: Amazon Security Hub Onboard Product Integration
- type: Arazzo
  url: arazzo/amazon-security-hub-review-insight-findings-workflow.yml
  name: Amazon Security Hub Review Insight Findings
- type: Arazzo
  url: arazzo/amazon-security-hub-standards-compliance-audit-workflow.yml
  name: Amazon Security Hub Standards Compliance Audit
- type: Arazzo
  url: arazzo/amazon-security-hub-triage-and-update-findings-workflow.yml
  name: Amazon Security Hub Triage and Update Findings
- type: Portal
  url: https://aws.amazon.com/
- type: GettingStarted
  url: https://aws.amazon.com/security-hub/getting-started/
- type: Documentation
  url: https://docs.aws.amazon.com/securityhub/
- type: APIReference
  url: https://docs.aws.amazon.com/securityhub/latest/APIReference/
- type: Console
  url: https://console.aws.amazon.com/securityhub/
- type: Signup
  url: https://signin.aws.amazon.com/signup?request_type=register
- type: Pricing
  url: https://aws.amazon.com/security-hub/pricing/
- type: FAQ
  url: https://aws.amazon.com/security-hub/faqs/
- type: Blog
  url: https://aws.amazon.com/blogs/security/
- type: StatusPage
  url: https://health.aws.amazon.com/health/status
- type: Support
  url: https://aws.amazon.com/premiumsupport/
- type: TermsOfService
  url: https://aws.amazon.com/service-terms/
- type: PrivacyPolicy
  url: https://aws.amazon.com/privacy/
- type: Compliance
  url: https://aws.amazon.com/compliance/
- type: GitHubOrganization
  url: https://github.com/aws
- type: YouTube
  url: https://www.youtube.com/user/AmazonWebServices
- type: StackOverflow
  url: https://stackoverflow.com/questions/tagged/aws-security-hub
- type: KnowledgeCenter
  url: https://repost.aws/knowledge-center
- type: SpectralRules
  url: rules/amazon-security-hub-spectral-rules.yml
- type: Vocabulary
  url: vocabulary/amazon-security-hub-vocabulary.yaml
- type: Features
  data:
  - name: Multi-Account Findings Aggregation
    description: Aggregate security findings from across multiple AWS accounts and regions into a single pane of glass.
  - name: AWS Security Finding Format (ASFF)
    description: Standardized JSON format for all security findings enabling consistent analysis and automation.
  - name: Built-in Compliance Standards
    description: Automated compliance checks against CIS AWS Foundations, PCI DSS, NIST, SOC 2, and AWS Foundational Security
      Best Practices.
  - name: Third-Party Integrations
    description: Ingest findings from 80+ third-party security partners including CrowdStrike, Palo Alto Networks, and Splunk.
  - name: Automated Remediation
    description: Trigger automated remediation via Amazon EventBridge and AWS Security Hub automated response and remediation.
  - name: Security Insights
    description: Correlated views of security findings to highlight areas needing attention.
  - name: Custom Actions
    description: Create custom actions to send findings to ticketing, chat, and SOAR platforms.
  - name: Cross-Region Aggregation
    description: Aggregate findings across multiple AWS regions into a designated aggregation region.
- type: UseCases
  data:
  - name: Cloud Security Posture Management
    description: Continuously monitor your AWS environment for security misconfigurations and compliance gaps.
  - name: Compliance Reporting
    description: Automate compliance checks and generate reports for CIS, PCI DSS, NIST, and other frameworks.
  - name: Multi-Account Security Operations
    description: Centralize security monitoring across dozens or hundreds of AWS accounts in an organization.
  - name: Threat Detection Aggregation
    description: Aggregate findings from GuardDuty, Inspector, Macie, and third-party tools in one place.
  - name: Automated Incident Response
    description: Trigger automated remediation workflows when critical findings are detected.
  - name: Security Tool Consolidation
    description: Replace multiple point solutions with centralized finding aggregation and normalized data.
- type: Integrations
  data:
  - name: Amazon GuardDuty
    description: Native integration to ingest GuardDuty threat detection findings.
  - name: Amazon Inspector
    description: Aggregate Inspector vulnerability assessment findings.
  - name: Amazon Macie
    description: Ingest Macie sensitive data discovery findings.
  - name: AWS Config
    description: Integration with Config rules for configuration compliance findings.
  - name: Amazon EventBridge
    description: Trigger automated remediation and notification workflows based on findings.
  - name: AWS Lambda
    description: Execute custom remediation actions in response to security findings.
  - name: AWS Organizations
    description: Enable Security Hub across all accounts in an AWS Organization.
  - name: CrowdStrike
    description: Third-party integration for endpoint detection and response findings.
  - name: Splunk
    description: Export Security Hub findings to Splunk SIEM for advanced analysis.
  - name: Palo Alto Networks
    description: Ingest Prisma Cloud and other Palo Alto findings via Security Hub integration.
- type: JSONLD
  url: json-ld/amazon-security-hub-context.jsonld
- type: JSONStructure
  url: json-structure/amazon-security-hub-finding-structure.json
- type: Examples
  url: examples/amazon-security-hub-finding-example.json
- type: Integrations
  url: https://aws.amazon.com/partners/
integrations:
- name: Partner Programs
- name: Resources
- name: Success Stories
- name: Work with an AWS Partner
- name: AWS Marketplace
- name: AWS Partner Central
- name: Partner Paths
- name: co-sell with AWS
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com