# ARMO

**Canonical:** https://apis.io/providers/armosec/  
**Website:** https://www.armosec.io/  
**APIs profiled:** 8

ARMO is the cloud-native and Kubernetes security company behind the leading open-source project Kubescape. ARMO Platform is a runtime-driven CNAPP that unifies Kubernetes Security Posture Management (KSPM), vulnerability and image scanning, compliance frameworks, network and seccomp policy generation, and runtime Cloud Application Detection and Response (CADR) - correlating runtime behavior with posture and vulnerabilities to cut alert noise. ARMO exposes a documented REST API over HTTPS (base https://api.armosec.io/api/v1 in the EU region and https://api.us.armosec.io/api/v1 in the US region), authenticated with an account access key sent in the X-API-KEY header. The API covers clusters, workloads, vulnerabilities, posture and compliance, security risks, runtime incidents, attack chains, network and runtime policies, registry scanning, and integrations. API access is available to platform customers who have generated an Agent Access Key; the endpoints below are documented but the data returned requires a connected account and clusters.

## Kin Score — 36.9 / 100 (thin)

Scored 2026-08-24 under rubric 0.13.0. Trend: flat (-0.4 from 37.3).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 53.3 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 34.2 |
| Developer Ergonomics | 19.0 |
| Commercial Clarity | 39.5 |
| Access Clarity | 39.5 |

## Agent readiness — 19.8 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (8)

- **ARMO Access Keys API** — Account API access key management.
- **ARMO Clusters API** — Connected clusters and workloads.
- **ARMO Integrations API** — Jira and collaboration/notification integrations.
- **ARMO Posture API** — KSPM posture and compliance framework results.
- **ARMO Registry API** — Container registry scanning.
- **ARMO Runtime API** — Runtime incidents (CADR), network and runtime policies.
- **ARMO Security Risks API** — Correlated security risks and attack chains.
- **ARMO Vulnerabilities API** — Image and workload vulnerability scanning and results.

## Agentic access (1)

- **Armosec Agentic Access** — 53 operations · 39 acting · 3 human-in-the-loop

## Security (2)

- **Armosec Authentication** — apiKey · 1 scheme
- **Armosec Domain Security** — HSTS · DMARC

## Plans (1)

- **Armosec Plans Pricing**

## Tags

Kubernetes Security, Cloud Native Security, CNAPP, DevSecOps, KSPM, Vulnerability Management, Compliance, Runtime Security, CADR, Kubescape, Container Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/armosec/). Scores are computed from the provider's own public artifacts under a published rubric.
