BeyondTrust website screenshot

BeyondTrust

BeyondTrust is a cybersecurity company specializing in privileged access management (PAM) and vulnerability management solutions. Their products help organizations prevent data breaches, malware attacks, and insider threats by identifying and controlling the access of privileged users, accounts, and credentials across the enterprise.

BeyondTrust publishes 6 APIs on the APIs.io network, including Authentication API, Credentials API, Managed Accounts API, and 3 more. Tagged areas include Access, Access Management, Compliance, Credentials, and Privileged Access.

The BeyondTrust catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

BeyondTrust’s developer surface includes authentication, developer portal, getting-started guide, and 8 more developer resources.

30.0/100 thin ▬ flat Agent 31/100 agent ready Full breakdown ↓
scored 2026-09-08 · rubric v0.20.0
AccessFreemiumSelf serve⚡ Free to try
6 APIs 8 Features 6 Use Cases
AccessAccess ManagementComplianceCredentialsPrivileged AccessSecuritySecretsZero Trust

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-08 · rubric v0.20.0
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it carries 10 points of the composite. It is scored from the published contracts themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in front of it, and the first time that check is skipped a duplicate record is created. Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet, not penalised by it.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/beyondtrust: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 6

Individual APIs this provider publishes, each with its own machine-readable definition.

BeyondTrust Authentication API

API authentication and authorization

BeyondTrust Credentials API

Manage privileged account credentials and passwords

BeyondTrust Managed Accounts API

Manage privileged accounts and their configurations

BeyondTrust Managed Systems API

Manage systems registered in Password Safe

BeyondTrust Requests API

Submit and manage access requests for privileged accounts

BeyondTrust Secrets API

Manage secrets and secret store entries

Open Collections 7

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

API Collection

OPEN COLLECTION

Scroll for all 7

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Beyondtrust Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 8

Notable capabilities this provider offers.

Privileged Password Management

Automatically discover, manage, and rotate passwords for privileged accounts across systems.

Just-In-Time Privileged Access

Grant time-limited, approval-based access to privileged accounts minimizing standing privileges.

Secrets Safe

Store, manage, and retrieve application secrets, API keys, and credentials securely.

Session Management

Record, monitor, and control privileged remote sessions for audit and compliance.

Endpoint Privilege Management

Remove admin rights from endpoints while allowing approved applications to run.

Privileged Remote Access

Provide secure remote access to privileged systems without VPN or exposed credentials.

Vulnerability Management

Identify and prioritize vulnerabilities across the attack surface.

AD Bridge

Extend Active Directory authentication and group policies to Unix and Linux systems.

Scroll for all 8

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Beyondtrust Context

13 classes · 37 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

BeyondTrust API Rules

5 rules · 3 warnings 2 info

SPECTRAL

BeyondTrust API Rules

29 rules · 11 errors 14 warnings 4 info

SPECTRAL

JSON Schema 11

Standalone JSON Schema definitions for this provider's data models.

CreateRequestBody

5 properties

JSON SCHEMA

CreateSecretRequest

6 properties

JSON SCHEMA

CredentialResponse

2 properties

JSON SCHEMA

ManagedAccount

8 properties

JSON SCHEMA

ManagedSystem

6 properties

JSON SCHEMA

Request

11 properties

JSON SCHEMA

Secret

7 properties

JSON SCHEMA

SecretWithValue

7 properties

JSON SCHEMA

SessionResponse

4 properties

JSON SCHEMA

SignAppInRequest

2 properties

JSON SCHEMA

UpdateRequestBody

2 properties

JSON SCHEMA

Scroll for all 11

JSON Structure 11

JSON Structure definitions describing this provider's data shapes.

Beyondtrust Create Request Body Structure

5 properties

JSON STRUCTURE

Beyondtrust Credential Response Structure

2 properties

JSON STRUCTURE

Beyondtrust Managed Account Structure

8 properties

JSON STRUCTURE

Beyondtrust Managed System Structure

6 properties

JSON STRUCTURE

Beyondtrust Request Structure

11 properties

JSON STRUCTURE

Beyondtrust Secret Structure

7 properties

JSON STRUCTURE

Beyondtrust Secret With Value Structure

7 properties

JSON STRUCTURE

Beyondtrust Session Response Structure

4 properties

JSON STRUCTURE

Beyondtrust Sign App In Request Structure

2 properties

JSON STRUCTURE

Beyondtrust Update Request Body Structure

2 properties

JSON STRUCTURE

Scroll for all 11

Examples 11

Example request and response payloads for these APIs.

Beyondtrust Request Example

11 fields

EXAMPLE

Scroll for all 11

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Beyondtrust Authentication

apiKey · 1 scheme

SECURITY

Beyondtrust Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Beyondtrust Vulnerability Disclosure

security.txt · contact published

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Beyondtrust Agentic Access

14 operations · 7 acting

14 operations · 7 acting

AGENTIC

Use Cases 6

What developers build with this provider.

Zero Standing Privileges

Eliminate persistent privileged access by granting just-in-time credentials on demand.

DevOps Secrets Management

Retrieve credentials and secrets programmatically in CI/CD pipelines without hardcoded credentials.

Privileged Account Discovery

Automatically discover and on-board all privileged accounts across hybrid environments.

Compliance Reporting

Generate audit trails for all privileged access to meet SOX, PCI-DSS, and HIPAA requirements.

Ransomware Prevention

Prevent lateral movement by removing local admin rights and controlling privileged access.

Third-Party Vendor Access

Grant temporary, monitored access to vendors and contractors without sharing credentials.

Integrations 7

Pre-built integrations with other platforms and tools.

ServiceNow

Integrate access requests with ServiceNow ITSM workflows for approval management.

Active Directory

Sync users, groups, and managed accounts from Active Directory.

AWS

Manage privileged access to AWS IAM roles and EC2 instances.

Azure

Integrate with Azure Active Directory and manage Azure privileged identities.

HashiCorp Vault

Bridge BeyondTrust and HashiCorp Vault for secrets management.

Splunk

Forward audit logs and session recordings to Splunk for SIEM analysis.

Terraform

Manage BeyondTrust Password Safe resources as infrastructure as code.

Scroll for all 7

Resources

Get Started 2

Portal, sign-up, and the first successful call

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 2

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: beyondtrust
url: https://raw.githubusercontent.com/api-evangelist/beyondtrust/refs/heads/main/apis.yml
apis:
- aid: beyondtrust:beyondtrust-authentication-api
  name: BeyondTrust Authentication API
  description: API authentication and authorization
  humanURL: https://docs.beyondtrust.com/
  baseURL: https://{host}/BeyondTrust/api/public/v3
  tags:
  - Authentication
  properties:
  - type: OpenAPI
    url: openapi/beyondtrust-authentication-api-openapi.yml
  - type: Documentation
    url: https://docs.beyondtrust.com/
- aid: beyondtrust:beyondtrust-credentials-api
  name: BeyondTrust Credentials API
  description: Manage privileged account credentials and passwords
  humanURL: https://docs.beyondtrust.com/
  baseURL: https://{host}/BeyondTrust/api/public/v3
  tags:
  - Credentials
  properties:
  - type: OpenAPI
    url: openapi/beyondtrust-credentials-api-openapi.yml
  - type: Documentation
    url: https://docs.beyondtrust.com/
- aid: beyondtrust:beyondtrust-managed-accounts-api
  name: BeyondTrust Managed Accounts API
  description: Manage privileged accounts and their configurations
  humanURL: https://docs.beyondtrust.com/
  baseURL: https://{host}/BeyondTrust/api/public/v3
  tags:
  - Managed Accounts
  properties:
  - type: OpenAPI
    url: openapi/beyondtrust-managed-accounts-api-openapi.yml
  - type: Documentation
    url: https://docs.beyondtrust.com/
- aid: beyondtrust:beyondtrust-managed-systems-api
  name: BeyondTrust Managed Systems API
  description: Manage systems registered in Password Safe
  humanURL: https://docs.beyondtrust.com/
  baseURL: https://{host}/BeyondTrust/api/public/v3
  tags:
  - Managed Systems
  properties:
  - type: OpenAPI
    url: openapi/beyondtrust-managed-systems-api-openapi.yml
  - type: Documentation
    url: https://docs.beyondtrust.com/
- aid: beyondtrust:beyondtrust-requests-api
  name: BeyondTrust Requests API
  description: Submit and manage access requests for privileged accounts
  humanURL: https://docs.beyondtrust.com/
  baseURL: https://{host}/BeyondTrust/api/public/v3
  tags:
  - Requests
  properties:
  - type: OpenAPI
    url: openapi/beyondtrust-requests-api-openapi.yml
  - type: Documentation
    url: https://docs.beyondtrust.com/
- aid: beyondtrust:beyondtrust-secrets-api
  name: BeyondTrust Secrets API
  description: Manage secrets and secret store entries
  humanURL: https://docs.beyondtrust.com/
  baseURL: https://{host}/BeyondTrust/api/public/v3
  tags:
  - Secrets
  properties:
  - type: OpenAPI
    url: openapi/beyondtrust-secrets-api-openapi.yml
  - type: Documentation
    url: https://docs.beyondtrust.com/
name: BeyondTrust
tags:
- Access
- Access Management
- Compliance
- Credentials
- Privileged Access
- Security
- Secrets
- Zero Trust
kind: contract
deliveryModel:
  model: unknown
  open_source: false
  commercial: false
  callable_host: false
  label: Delivery model not determined — needs a product licence on record
  confidence: low
  source:
  - openapi
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: medium
  source:
  - plans
  - authentication
  - security
  generated: '2026-09-03'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/beyondtrust.png
access: 3rd-Party
created: '2025-02-17'
modified: '2026-05-19'
position: Consuming
description: BeyondTrust is a cybersecurity company specializing in privileged access management (PAM) and vulnerability management
  solutions. Their products help organizations prevent data breaches, malware attacks, and insider threats by identifying
  and controlling the access of privileged users, accounts, and credentials across the enterprise.
common:
- type: AgenticAccess
  url: agentic-access/beyondtrust-agentic-access.yml
- type: VulnerabilityDisclosure
  url: security/beyondtrust-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/beyondtrust-domain-security.yml
- type: Authentication
  url: authentication/beyondtrust-authentication.yml
- type: LinkedIn
  url: https://www.linkedin.com/company/beyondtrust
- type: Portal
  url: https://docs.beyondtrust.com/
- type: GettingStarted
  url: https://docs.beyondtrust.com/
- type: GitHubOrganization
  url: https://github.com/BeyondTrust
- type: SpectralRules
  url: https://raw.githubusercontent.com/api-evangelist/beyondtrust/refs/heads/main/rules/beyondtrust-spectral-rules.yml
- type: Vocabulary
  url: https://raw.githubusercontent.com/api-evangelist/beyondtrust/refs/heads/main/vocabulary/beyondtrust-vocabulary.yaml
- type: Features
  data:
  - name: Privileged Password Management
    description: Automatically discover, manage, and rotate passwords for privileged accounts across systems.
  - name: Just-In-Time Privileged Access
    description: Grant time-limited, approval-based access to privileged accounts minimizing standing privileges.
  - name: Secrets Safe
    description: Store, manage, and retrieve application secrets, API keys, and credentials securely.
  - name: Session Management
    description: Record, monitor, and control privileged remote sessions for audit and compliance.
  - name: Endpoint Privilege Management
    description: Remove admin rights from endpoints while allowing approved applications to run.
  - name: Privileged Remote Access
    description: Provide secure remote access to privileged systems without VPN or exposed credentials.
  - name: Vulnerability Management
    description: Identify and prioritize vulnerabilities across the attack surface.
  - name: AD Bridge
    description: Extend Active Directory authentication and group policies to Unix and Linux systems.
- type: UseCases
  data:
  - name: Zero Standing Privileges
    description: Eliminate persistent privileged access by granting just-in-time credentials on demand.
  - name: DevOps Secrets Management
    description: Retrieve credentials and secrets programmatically in CI/CD pipelines without hardcoded credentials.
  - name: Privileged Account Discovery
    description: Automatically discover and on-board all privileged accounts across hybrid environments.
  - name: Compliance Reporting
    description: Generate audit trails for all privileged access to meet SOX, PCI-DSS, and HIPAA requirements.
  - name: Ransomware Prevention
    description: Prevent lateral movement by removing local admin rights and controlling privileged access.
  - name: Third-Party Vendor Access
    description: Grant temporary, monitored access to vendors and contractors without sharing credentials.
- type: Integrations
  data:
  - name: ServiceNow
    description: Integrate access requests with ServiceNow ITSM workflows for approval management.
  - name: Active Directory
    description: Sync users, groups, and managed accounts from Active Directory.
  - name: AWS
    description: Manage privileged access to AWS IAM roles and EC2 instances.
  - name: Azure
    description: Integrate with Azure Active Directory and manage Azure privileged identities.
  - name: HashiCorp Vault
    description: Bridge BeyondTrust and HashiCorp Vault for secrets management.
  - name: Splunk
    description: Forward audit logs and session recordings to Splunk for SIEM analysis.
  - name: Terraform
    description: Manage BeyondTrust Password Safe resources as infrastructure as code.
- type: LlmsText
  url: https://docs.beyondtrust.com/llms.txt
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
specificationVersion: '0.23'

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/beyondtrust"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/beyondtrust/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/beyondtrust/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.