# AWS WAF

**Canonical:** https://apis.io/providers/aws-waf/  
**Website:** https://aws.amazon.com/waf/  
**APIs profiled:** 2

AWS WAF is a web application firewall that monitors and controls HTTP and HTTPS requests forwarded to protected resources such as Amazon CloudFront distributions, API Gateway REST APIs, Application Load Balancers, AWS AppSync GraphQL APIs, Cognito user pools, App Runner services, Amplify applications, and Verified Access instances. It enables rule-based blocking, rate limiting, and managed rule groups to defend against common web exploits. The AWS WAFV2 API and AWS SDKs provide programmatic access using AWS Signature Version 4 authentication.

## Kin Score — 32.6 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 32.6).

| Facet | Score |
|---|---|
| Discoverability | 68.5 |
| Contract Quality | 58.7 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 0.0 |
| Developer Ergonomics | 23.8 |
| Commercial Clarity | 31.6 |
| Access Clarity | 31.6 |

## Agent readiness — 26.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (2)

- **AWS WAFV2 API** — REST API for creating and managing web ACLs, rule groups, IP sets, regex pattern sets, and logging configurations across regional and CloudFront-scoped AWS WAF deployments. Requ...
- **AWS WAF AWS WAFV2 API API** — The AWS WAFV2 API API from AWS WAF — 1 operation(s) for aws wafv2 api.

## Agentic access (1)

- **Aws Waf Agentic Access** — 1 operation · 1 acting

## Security (4)

- **Aws Waf Authentication** — apiKey · 1 scheme
- **Aws Waf Domain Security** — TLSv1.3 · HSTS · DMARC
- **Aws Waf Vulnerability Disclosure** — security.txt · contact published
- **Aws Waf Trust Center** — PCI DSS, HIPAA, FedRAMP, GDPR, FIPS 140

## Tags

Security, Web Application Firewall, DDoS Protection, Bot Management, Edge Security, Cloud

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/aws-waf/). Scores are computed from the provider's own public artifacts under a published rubric.
