Cloud Custodian website screenshot

Cloud Custodian

Cloud Custodian is an open-source rules engine for cloud security, compliance, and cost-optimization governance now stewarded by Stacklet. Operators express policies as YAML files that select a cloud resource type, apply filters, and execute actions; the engine then runs those policies against AWS, Azure, and GCP via provider-specific plugins. Custodian does not expose a developer REST API of its own - integration is via the c7n CLI, the policy YAML schema, c7n-org for multi-account fan-out, and c7n-mailer for SQS-driven notifications.

Cloud Custodian publishes 1 API on the APIs.io network: C7n-Mailer. Tagged areas include Cloud Security, Compliance, Cost Optimization, Multi-Cloud, and Policy as Code.

The Cloud Custodian catalog on APIs.io includes 1 event-driven AsyncAPI specification, 1 JSON-LD context, and 2 Spectral governance rulesets.

Cloud Custodian’s developer surface includes documentation, getting-started guide, changelog, and 11 more developer resources.

36.7/100 thin ▬ flat Agent 17/100 agent aware self hosted · Apache-2.0 Full breakdown ↓
scored 2026-09-08 · rubric v0.20.0
AccessFreemium
6 APIs
Cloud SecurityComplianceCost OptimizationMulti-CloudPolicy as Code

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-08 · rubric v0.20.0
Regulatory Posture applies to this provider. Its tags matched the Insurance regime, so Regulatory Posture carries 15 points of the composite. If this regime is wrong for your business, say so on your provider repo — the applicability map is public and we will correct it.
Open Source Surface applies to this provider. This product is open source and we read its repository directly, so Open Source Surface carries 10 points of the composite. It is scored from what the repository actually publishes — a security policy, a contribution guide, a release history, a code of conduct — read live from the provider rather than inferred from our own catalog pointers. This facet adds; nothing was taken away to make room for it. An open-source project is not excused from the commercial facets, because exemption would strip it of the points it does earn. If we have the wrong repository, or this product is not open source, say so on your provider repo and we will drop the facet rather than have you publish against it.
Create-or-Update Ergonomics could not be measured. We hold no machine-readable contract for this provider to read, so there is nothing to measure a write surface against. Excluded rather than scored zero: never-measured and measured-empty are different facts. Publishing an OpenAPI is what makes this facet — and several others — scorable at all.
The six quality facets above are damped to 75 points between them, because both conditional facets apply and carry 25 points together. That is why each facet's contribution is shown against a damped maximum: raising a quality facet moves the composite by 75% of its nominal weight, not 100%. The full arithmetic is at apis.io/rating/.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/cloud-custodian: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 6

Individual APIs this provider publishes, each with its own machine-readable definition.

Cloud Custodian

Cloud Custodian provides rules-engine capabilities for managing cloud resources with security, compliance, and cost optimization policies.

Cloud Custodian AWS Provider

The Cloud Custodian AWS provider enables policy-as-code management of Amazon Web Services resources including EC2, S3, IAM, RDS, Lambda, and hundreds of other AWS service resour...

Cloud Custodian Azure Provider

The Cloud Custodian Azure provider enables policy-as-code management of Microsoft Azure resources including virtual machines, storage accounts, network security groups, and othe...

Cloud Custodian GCP Provider

The Cloud Custodian GCP provider enables policy-as-code management of Google Cloud Platform resources including Compute Engine instances, GCS buckets, Cloud SQL instances, and o...

Cloud Custodian C7n-Org

c7n-org is a Cloud Custodian tool for running policies across multiple cloud accounts, projects, or subscriptions in parallel. It uses an accounts configuration file with assume...

Cloud Custodian C7n-Mailer

c7n-mailer is a Cloud Custodian notification tool that subscribes to an SQS queue populated by policy actions and sends notifications via SES email, Slack messages, or integrati...

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Cloud Custodian Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Cloud Custodian c7n-mailer Notification Events

The Cloud Custodian c7n-mailer AsyncAPI defines the event-driven notification interface used by the Cloud Custodian policy engine to deliver policy violation alerts. When a poli...

ASYNCAPI

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Cloud Custodian Context

0 classes · 8 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Cloud Custodian API Rules

3 rules · 1 errors 2 warnings

SPECTRAL

Cloud Custodian API Rules

6 rules · 5 warnings 1 info

SPECTRAL

JSON Schema 1

Standalone JSON Schema definitions for this provider's data models.

Cloud Custodian Policy File

2 properties

JSON SCHEMA

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Resources

Get Started 1

Portal, sign-up, and the first successful call

Documentation 3

Reference material describing how the API behaves

Design & Contract 1

Pagination, idempotency, versioning, errors, and events

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Operate 3

Status, limits, changes, and where to get help

Commercial 1

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: cloud-custodian
url: https://raw.githubusercontent.com/api-evangelist/cloud-custodian/refs/heads/main/apis.yml
name: Cloud Custodian
tags:
- Cloud Security
- Compliance
- Cost Optimization
- Multi-Cloud
- Policy as Code
type: Index
deliveryModel:
  model: self-hosted
  license: Apache-2.0
  open_source: true
  commercial: false
  callable_host: false
  label: Self-hosted open source · you run it yourself
  confidence: high
  source:
  - license
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: freemium
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Freemium
  confidence: medium
  source:
  - plans
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloud-custodian.png
access: Open Source
created: '2025-01-01'
modified: '2026-04-27'
position: Consuming
kind: opensource
description: Cloud Custodian is an open-source rules engine for cloud security, compliance, and cost-optimization governance
  now stewarded by Stacklet. Operators express policies as YAML files that select a cloud resource type, apply filters, and
  execute actions; the engine then runs those policies against AWS, Azure, and GCP via provider-specific plugins. Custodian
  does not expose a developer REST API of its own - integration is via the c7n CLI, the policy YAML schema, c7n-org for multi-account
  fan-out, and c7n-mailer for SQS-driven notifications.
apis:
- aid: cloud-custodian:cloud-custodian
  name: Cloud Custodian
  tags:
  - Cloud Security
  - Policy as Code
  humanURL: https://cloudcustodian.io/
  properties:
  - url: https://cloudcustodian.io/docs/
    type: Documentation
  - url: https://cloudcustodian.io/docs/quickstart/index.html
    type: GettingStarted
  - url: https://cloudcustodian.io/docs/overview/capabilities.html
    type: Reference
  - url: https://github.com/cloud-custodian/cloud-custodian
    type: GitHubRepository
  - type: JSONSchema
    url: json-schema/cloud-custodian-policy-schema.json
  description: Cloud Custodian provides rules-engine capabilities for managing cloud resources with security, compliance,
    and cost optimization policies.
- aid: cloud-custodian:cloud-custodian-aws
  name: Cloud Custodian AWS Provider
  description: The Cloud Custodian AWS provider enables policy-as-code management of Amazon Web Services resources including
    EC2, S3, IAM, RDS, Lambda, and hundreds of other AWS service resource types. Policies can be run in multiple execution
    modes including serverless Lambda functions, AWS Config rules, and scheduled CloudWatch Events.
  humanURL: https://cloudcustodian.io/docs/aws/gettingstarted.html
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
  properties:
  - url: https://cloudcustodian.io/docs/aws/gettingstarted.html
    type: GettingStarted
  - url: https://cloudcustodian.io/docs/aws/resources/index.html
    type: Reference
  - url: https://cloudcustodian.io/docs/aws/examples/index.html
    type: Documentation
  tags:
  - AWS
  - Cloud Security
  - Compliance
  - Policy as Code
- aid: cloud-custodian:cloud-custodian-azure
  name: Cloud Custodian Azure Provider
  description: The Cloud Custodian Azure provider enables policy-as-code management of Microsoft Azure resources including
    virtual machines, storage accounts, network security groups, and other Azure services. Policies can enforce security requirements,
    tagging standards, and cost controls across Azure subscriptions.
  humanURL: https://cloudcustodian.io/docs/azure/gettingstarted.html
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
  properties:
  - url: https://cloudcustodian.io/docs/azure/gettingstarted.html
    type: GettingStarted
  - url: https://cloudcustodian.io/docs/azure/policy/resources/index.html
    type: Reference
  tags:
  - Azure
  - Cloud Security
  - Compliance
  - Policy as Code
- aid: cloud-custodian:cloud-custodian-gcp
  name: Cloud Custodian GCP Provider
  description: The Cloud Custodian GCP provider enables policy-as-code management of Google Cloud Platform resources including
    Compute Engine instances, GCS buckets, Cloud SQL instances, and other GCP services. Policies can be used to enforce security,
    compliance, and cost governance standards across GCP projects.
  humanURL: https://cloudcustodian.io/docs/gcp/gettingstarted.html
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
  properties:
  - url: https://cloudcustodian.io/docs/gcp/gettingstarted.html
    type: GettingStarted
  - url: https://cloudcustodian.io/docs/gcp/resources/index.html
    type: Reference
  tags:
  - Cloud Security
  - Compliance
  - GCP
  - Policy as Code
- aid: cloud-custodian:cloud-custodian-c7n-org
  name: Cloud Custodian C7n-Org
  description: c7n-org is a Cloud Custodian tool for running policies across multiple cloud accounts, projects, or subscriptions
    in parallel. It uses an accounts configuration file with assumed roles to orchestrate Custodian execution at scale across
    AWS Organizations, Azure subscriptions, or GCP projects.
  humanURL: https://cloudcustodian.io/docs/tools/c7n-org.html
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
  properties:
  - url: https://cloudcustodian.io/docs/tools/c7n-org.html
    type: Documentation
  tags:
  - Cloud Security
  - Multi-Account
  - Orchestration
- aid: cloud-custodian:cloud-custodian-c7n-mailer
  name: Cloud Custodian C7n-Mailer
  description: c7n-mailer is a Cloud Custodian notification tool that subscribes to an SQS queue populated by policy actions
    and sends notifications via SES email, Slack messages, or integrations with DataDog and Splunk. It enables teams to alert
    resource owners when Custodian policies detect policy violations.
  humanURL: https://cloudcustodian.io/docs/tools/c7n-mailer.html
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
  properties:
  - url: https://cloudcustodian.io/docs/tools/c7n-mailer.html
    type: Documentation
  - type: AsyncAPI
    url: asyncapi/cloud-custodian-mailer-asyncapi.yml
  tags:
  - Alerting
  - Email
  - Notification
  - Slack
  tags_raw:
  - Alerting
  - Email
  - Notifications
  - Slack
common:
- type: IssueTracker
  url: https://github.com/cloud-custodian/cloud-custodian/issues
- type: SecurityPolicy
  url: https://github.com/cloud-custodian/cloud-custodian/blob/main/SECURITY.md
- type: License
  name: Apache-2.0
  url: https://github.com/cloud-custodian/cloud-custodian/blob/main/LICENSE
- type: DomainSecurity
  url: security/cloud-custodian-domain-security.yml
- type: Website
  url: https://cloudcustodian.io/
- type: Documentation
  url: https://cloudcustodian.io/docs/
- type: GitHubOrganization
  url: https://github.com/cloud-custodian/cloud-custodian
- type: GettingStarted
  url: https://cloudcustodian.io/docs/quickstart/index.html
- type: Community
  url: https://cloudcustodian.io/community/
- type: GitHubRepository
  url: https://github.com/cloud-custodian/cloud-custodian
- type: ChangeLog
  url: https://github.com/cloud-custodian/cloud-custodian/releases
- type: JSONLDContext
  url: json-ld/cloud-custodian-context.jsonld
- type: JSONSchema
  url: json-schema/cloud-custodian-policy-schema.json
- type: AsyncAPI
  url: asyncapi/cloud-custodian-mailer-asyncapi.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
specificationVersion: '0.23'

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/cloud-custodian"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/cloud-custodian/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/cloud-custodian/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.