Bishop Fox
Bishop Fox is an offensive security firm delivering penetration testing, red teaming, application and cloud security assessment, and continuous threat exposure management. Its managed Cosmos platform keeps a living inventory of an organization's external attack surface — domains, subdomains, DNS records, network ranges, IP addresses, open ports, and IP/hostname services — pairing continuous automated discovery with human operator validation so customers receive triaged, exploitable findings instead of scanner noise. Customers consume Cosmos data programmatically through the authenticated Cosmos v5 REST API at api.cosmos.bishopfox.com, secured with OAuth 2.0 client-credentials tokens issued by Bishop Fox's Auth0 tenant against the cosmos_public audience, and through bi-directional Jira and ServiceNow integrations plus AWS, GCP, Azure, Cloudflare, and Oracle cloud connectors. Bishop Fox also publishes a widely used open-source offensive-security toolkit — Sliver, CloudFox, sj (Swagger Jacker), jsluice, and aimap — from its GitHub organization.
Bishop Fox publishes 1 API on the APIs.io network. Tagged areas include Company, Cybersecurity, Offensive Security, Penetration Testing, and Attack Surface Management.
Bishop Fox’s developer surface includes developer portal, engineering blog, support, authentication, and 18 more developer resources.
Kin Score
APIs 1
Individual APIs this provider publishes, each with its own machine-readable definition.
Bishop Fox Cosmos API (v5)
Authenticated REST API for the Bishop Fox Cosmos attack-surface management platform. Exposes the customer's discovered asset inventory through /v5/asset-view/* resources (domain...
Security Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Scopes 1
OAuth scopes governing access to this provider's APIs.
Resources
Get Started 2
Portal, sign-up, and the first successful call
Agent Surfaces 2
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 5
Pagination, idempotency, versioning, errors, and events
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 6
Authentication, authorization, and security posture
Operate 1
Status, limits, changes, and where to get help
Commercial 1
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Source (apis.yml)
Work with this as data
Every provider here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for providers
9 MCP tools reach this
find_providersBrowse and filter every provider in the catalog.get_provider_artifactsEvery artifact this provider publishes, grouped by type.get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.get_provider_toolsEvery MCP tool they ship, with the operation each wraps.get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.get_provider_ratingPRO — composite, band, trend and facet scores.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/providers/bishop-fox"
curl "https://apis.io/api/v1/providers?limit=25"
curl "https://apis.io/api/v1/providers/bishop-fox/operations?limit=25"
curl "https://apis.io/api/v1/providers/bishop-fox/evidence"
Discovery needs no key. Ratings and market analysis are Pro.