CloudGuard website screenshot

CloudGuard

Check Point CloudGuard is a Cloud Native Application Protection Platform (CNAPP) delivering cloud security posture management (CSPM), cloud workload protection (CWPP), code security, cloud network security and cloud detection and response across AWS, Azure, GCP, Alibaba Cloud, Oracle Cloud, Kubernetes and on-premises environments. The public CloudGuard REST API - originally Dome9, still served from api.dome9.com and mirrored on the Infinity Portal regional hosts - is documented across 23 first-party OpenAPI definitions covering 823 operations: onboarding cloud accounts, running compliance assessments, managing rulesets and policies, triaging findings, routing notifications, protecting Kubernetes and serverless workloads, and reading a cross-cloud protected-asset inventory. Authentication is HTTP Basic with a V2 API key id and secret created in the CloudGuard portal.

CloudGuard publishes 23 APIs on the APIs.io network, including Onboarding API, Posture Management API, Events API, and 20 more. Tagged areas include Check Point, CNAPP, Cloud Security, Cloud Security Posture Management, and Compliance.

The CloudGuard catalog on APIs.io includes 1 event-driven AsyncAPI specification, 1 JSON-LD context, and 1 Spectral governance ruleset.

CloudGuard’s developer surface includes documentation, API reference, getting-started guide, authentication, signup flow, support, engineering blog, and 29 more developer resources.

53.7/100 developing ▬ flat Agent 34/100 agent ready Full breakdown ↓
scored 2026-09-08 · rubric v0.20.0
AccessFreemiumSelf serve⚡ Free to try
23 APIs 1 MCP Servers
Check PointCNAPPCloud SecurityCloud Security Posture ManagementComplianceCSPMCWPPKubernetes SecurityMulti-CloudPosture ManagementWorkload ProtectionDome9

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-08 · rubric v0.20.0
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it carries 10 points of the composite. It is scored from the published contracts themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in front of it, and the first time that check is skipped a duplicate record is created. Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet, not penalised by it.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/cloudguard: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 25

Individual APIs this provider publishes, each with its own machine-readable definition.

CloudGuard Onboarding API

Onboard and manage cloud accounts across AWS, Azure, GCP, Alibaba, OCI and Kubernetes - registration, credentials, missing-permission checks, data sync and organizational-unit p...

CloudGuard Posture Management API

Run compliance rulesets against cloud accounts, read assessment history and trends, export executive reports, and manage continuous compliance policies. 56 operations across 35 ...

CloudGuard Events API

Search, acknowledge, assign, comment on, re-prioritise, archive and close compliance findings, and push third-party findings in through the External Findings surface. 44 operati...

CloudGuard Administration API

Tenant administration - users, roles, IAM Safe entities, delivery integrations, and the Continuous Compliance Notification surface that routes findings to webhooks, SNS, Slack, ...

CloudGuard Risk Management API

Effective Risk Management - DSPM account registration, custom rulesets, the security graph query surface and toxic-combination evidence paths. 67 operations across 49 paths.

CloudGuard Workload Protection (CWPP) API

Workload protection - Kubernetes image assurance, admission control, runtime protection, agentless workload posture, serverless function protection and ShiftLeft/Code Security a...

CloudGuard Network Security API

Cloud network security - AWS/Azure security group policies, cloud security groups, IP lists, IP address metadata and access leases for just-in-time network access.

CloudGuard Identity API

IAM Safe identity protection - lease-based elevation of IAM entities and the identity surface CloudGuard uses to broker temporary cloud permissions.

CloudGuard Intelligence API

Cloud intelligence and CDR - account onboarding for the Intelligence (Magellan) service, usage quota notification rates and intelligence views over cloud activity logs.

CloudGuard Inventory API

Cross-cloud protected-asset inventory - entity reports and the generic inventory surface CloudGuard exposes over everything it has fetched from onboarded accounts.

CloudGuard Inventory - AWS Global API

Global AWS inventory entities - organizational units, regions and account-wide objects CloudGuard fetches from onboarded AWS accounts.

CloudGuard Inventory - AWS IAM API

AWS IAM inventory - users, roles, policies, virtual MFA devices and credential objects CloudGuard fetches for identity posture analysis.

CloudGuard Inventory - AWS Compute and Containers API

AWS compute and container inventory - EC2 instances, Lambda functions, ECS/EKS objects and the images and configurations attached to them.

CloudGuard Inventory - AWS Networking and Content Delivery API

AWS networking inventory - VPCs, subnets, route tables, load balancers, Route 53 domains and CloudFront distributions.

CloudGuard Inventory - AWS Storage API

AWS storage inventory - S3 buckets, EBS volumes and backup vaults as CloudGuard protected assets.

CloudGuard Inventory - AWS Analytics API

AWS analytics inventory - EMR clusters, Kinesis streams, Athena and related analytics services CloudGuard tracks as protected assets.

CloudGuard Inventory - AWS Management Tools API

AWS management-tooling inventory - AWS Config settings, CloudTrail and related governance services.

CloudGuard Inventory - AWS Machine Learning API

AWS machine-learning inventory - SageMaker resources CloudGuard tracks as protected assets.

CloudGuard Inventory - AWS Application Integration API

AWS application-integration inventory - SNS topics, SQS queues and related messaging services.

CloudGuard Inventory - AWS Security, Identity and Compliance API

AWS security-service inventory - KMS keys, Secrets Manager and related security services as CloudGuard protected assets.

CloudGuard Inventory - Azure API

Azure inventory - virtual machines, web apps, storage, networking, policy assignments, analysis services and 45 more Azure resource types CloudGuard fetches as protected assets....

CloudGuard Inventory - GCP API

Google Cloud inventory - networks, Pub/Sub topics, compute, storage and IAM objects CloudGuard fetches from onboarded GCP projects.

CloudGuard Inventory - OCI API

Oracle Cloud Infrastructure inventory - compartments and OCI resources CloudGuard fetches from onboarded OCI tenancies.

CloudGuard WAF API

CloudGuard WAF (formerly CloudGuard AppSec) protects web applications and APIs with contextual machine-learning threat prevention. Its management API is GraphQL, reached through...

CloudGuard Code Security (Spectral) API

CloudGuard Code Security (formerly Spectral) provides developer-first secrets detection, infrastructure-as-code scanning and SCA. It is a CLI-driven toolchain wired into CI/CD r...

Scroll for all 25

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

API Collection

OPEN COLLECTION

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

CloudGuard MCP Server

Check Point publishes a monorepo of 22 official MCP servers under github.com/CheckPointSW/mcp-servers, each shipped to npm under the @chkp scope. One of them - @chkp/checkpoint-...

MCP SERVER

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Cloudguard Rate Limits

0 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Cloudguard Context

0 classes · 5 properties

JSON-LD

Spectral Rules 1

Spectral governance rulesets for linting and validating these APIs.

CloudGuard API Rules

9 rules · 4 errors 5 warnings

SPECTRAL

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Cloudguard Authentication

http · 1 scheme

SECURITY

Cloudguard Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Cloudguard Agentic Access

823 operations · 396 acting · 80 human-in-the-loop

823 operations · 396 acting

AGENTIC

Resources

Get Started 3

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 4

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 8

Pagination, idempotency, versioning, errors, and events

Scroll for all 8

Build 5

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Operate 5

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: cloudguard
url: https://raw.githubusercontent.com/api-evangelist/cloudguard/refs/heads/main/apis.yml
name: CloudGuard
tags:
- Check Point
- CNAPP
- Cloud Security
- Cloud Security Posture Management
- Compliance
- CSPM
- CWPP
- Kubernetes Security
- Multi-Cloud
- Posture Management
- Workload Protection
- Dome9
type: Index
deliveryModel:
  model: unknown
  open_source: false
  commercial: false
  callable_host: true
  label: Delivery model not determined — needs a product licence on record
  confidence: low
  source:
  - openapi
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: medium
  source:
  - plans
  - authentication
  - security
  generated: '2026-09-03'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
access: 3rd-Party
created: '2024-01-01'
modified: '2026-09-05'
position: Consuming
kind: company
x-company: Check Point Software Technologies
description: 'Check Point CloudGuard is a Cloud Native Application Protection Platform (CNAPP) delivering cloud security posture
  management (CSPM), cloud workload protection (CWPP), code security, cloud network security and cloud detection and response
  across AWS, Azure, GCP, Alibaba Cloud, Oracle Cloud, Kubernetes and on-premises environments. The public CloudGuard REST
  API - originally Dome9, still served from api.dome9.com and mirrored on the Infinity Portal regional hosts - is documented
  across 23 first-party OpenAPI definitions covering 823 operations: onboarding cloud accounts, running compliance assessments,
  managing rulesets and policies, triaging findings, routing notifications, protecting Kubernetes and serverless workloads,
  and reading a cross-cloud protected-asset inventory. Authentication is HTTP Basic with a V2 API key id and secret created
  in the CloudGuard portal.'
apis:
- aid: cloudguard:cloudguard-cloudaccounts-api
  name: CloudGuard Onboarding API
  description: Onboard and manage cloud accounts across AWS, Azure, GCP, Alibaba, OCI and Kubernetes - registration, credentials,
    missing-permission checks, data sync and organizational-unit placement. 160 operations across 133 paths.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Cloud Accounts
  - Onboarding
  - Multi-Cloud
  - Kubernetes
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-onboarding-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-onboarding-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-compliance-api
  name: CloudGuard Posture Management API
  description: Run compliance rulesets against cloud accounts, read assessment history and trends, export executive reports,
    and manage continuous compliance policies. 56 operations across 35 paths.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Compliance
  - CSPM
  - Posture Management
  - Assessments
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-posture-management-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-posture-management-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-findings-api
  name: CloudGuard Events API
  description: Search, acknowledge, assign, comment on, re-prioritise, archive and close compliance findings, and push third-party
    findings in through the External Findings surface. 44 operations across 42 paths.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Findings
  - Events
  - Alerts
  - Triage
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-events-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-events-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-notifications-api
  name: CloudGuard Administration API
  description: Tenant administration - users, roles, IAM Safe entities, delivery integrations, and the Continuous Compliance
    Notification surface that routes findings to webhooks, SNS, Slack, Teams, ticketing systems and cloud security hubs. 77
    operations across 50 paths.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Administration
  - Notification
  - Integrations
  - Users
  - Roles
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-administration-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-administration-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-policies-api
  name: CloudGuard Risk Management API
  description: Effective Risk Management - DSPM account registration, custom rulesets, the security graph query surface and
    toxic-combination evidence paths. 67 operations across 49 paths.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Risk Management
  - DSPM
  - Security Graph
  - Rulesets
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-risk-management-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-risk-management-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-workload-api
  name: CloudGuard Workload Protection (CWPP) API
  description: Workload protection - Kubernetes image assurance, admission control, runtime protection, agentless workload
    posture, serverless function protection and ShiftLeft/Code Security accounts. 168 operations across 124 paths.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Container Security
  - CWPP
  - Image Assurance
  - Kubernetes
  - Serverless
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-workload-protection-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-workload-protection-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-network-security-api
  name: CloudGuard Network Security API
  description: Cloud network security - AWS/Azure security group policies, cloud security groups, IP lists, IP address metadata
    and access leases for just-in-time network access.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Cloud Firewall
  - Network Security
  - Security Groups
  - Access Lease
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-network-security-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-network-security-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-identity-api
  name: CloudGuard Identity API
  description: IAM Safe identity protection - lease-based elevation of IAM entities and the identity surface CloudGuard uses
    to broker temporary cloud permissions.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Identity
  - IAM
  - Least Privilege
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-identity-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-identity-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-intelligence-api
  name: CloudGuard Intelligence API
  description: Cloud intelligence and CDR - account onboarding for the Intelligence (Magellan) service, usage quota notification
    rates and intelligence views over cloud activity logs.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Intelligence
  - CDR
  - Threat Detection
  - Logs
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-intelligence-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-intelligence-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-api
  name: CloudGuard Inventory API
  description: Cross-cloud protected-asset inventory - entity reports and the generic inventory surface CloudGuard exposes
    over everything it has fetched from onboarded accounts.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - Protected Assets
  - Multi-Cloud
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-aws-global-api
  name: CloudGuard Inventory - AWS Global API
  description: Global AWS inventory entities - organizational units, regions and account-wide objects CloudGuard fetches from
    onboarded AWS accounts.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - AWS
  - Organizational Units
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-aws-global-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-aws-global-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-aws-iam-api
  name: CloudGuard Inventory - AWS IAM API
  description: AWS IAM inventory - users, roles, policies, virtual MFA devices and credential objects CloudGuard fetches for
    identity posture analysis.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - AWS
  - IAM
  - Identity
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-aws-iam-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-aws-iam-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-aws-compute-api
  name: CloudGuard Inventory - AWS Compute and Containers API
  description: AWS compute and container inventory - EC2 instances, Lambda functions, ECS/EKS objects and the images and configurations
    attached to them.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - AWS
  - Compute
  - Containers
  - Lambda
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-aws-compute-and-containers-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-aws-compute-and-containers-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-aws-networking-api
  name: CloudGuard Inventory - AWS Networking and Content Delivery API
  description: AWS networking inventory - VPCs, subnets, route tables, load balancers, Route 53 domains and CloudFront distributions.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - AWS
  - Networking
  - VPC
  - Route 53
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-aws-networking-and-content-delivery-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-aws-networking-and-content-delivery-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-aws-storage-api
  name: CloudGuard Inventory - AWS Storage API
  description: AWS storage inventory - S3 buckets, EBS volumes and backup vaults as CloudGuard protected assets.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - AWS
  - Storage
  - S3
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-aws-storage-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-aws-storage-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-aws-analytics-api
  name: CloudGuard Inventory - AWS Analytics API
  description: AWS analytics inventory - EMR clusters, Kinesis streams, Athena and related analytics services CloudGuard tracks
    as protected assets.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - AWS
  - Analytics
  - EMR
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-aws-analytics-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-aws-analytics-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-aws-management-tools-api
  name: CloudGuard Inventory - AWS Management Tools API
  description: AWS management-tooling inventory - AWS Config settings, CloudTrail and related governance services.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - AWS
  - Governance
  - CloudTrail
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-aws-management-tools-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-aws-management-tools-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-aws-ml-api
  name: CloudGuard Inventory - AWS Machine Learning API
  description: AWS machine-learning inventory - SageMaker resources CloudGuard tracks as protected assets.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - AWS
  - Machine Learning
  - SageMaker
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-aws-machine-learning-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-aws-machine-learning-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-aws-app-integration-api
  name: CloudGuard Inventory - AWS Application Integration API
  description: AWS application-integration inventory - SNS topics, SQS queues and related messaging services.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - AWS
  - Messaging
  - SNS
  - SQS
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-aws-application-integration-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-aws-application-integration-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-aws-security-api
  name: CloudGuard Inventory - AWS Security, Identity and Compliance API
  description: AWS security-service inventory - KMS keys, Secrets Manager and related security services as CloudGuard protected
    assets.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - AWS
  - Security
  - KMS
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-aws-security-identity-and-compliance-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-aws-security-identity-and-compliance-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-azure-api
  name: CloudGuard Inventory - Azure API
  description: Azure inventory - virtual machines, web apps, storage, networking, policy assignments, analysis services and
    45 more Azure resource types CloudGuard fetches as protected assets. 52 operations.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - Azure
  - Protected Assets
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-azure-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-azure-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-gcp-api
  name: CloudGuard Inventory - GCP API
  description: Google Cloud inventory - networks, Pub/Sub topics, compute, storage and IAM objects CloudGuard fetches from
    onboarded GCP projects.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - GCP
  - Google Cloud
  - Protected Assets
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-gcp-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-gcp-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-inventory-oci-api
  name: CloudGuard Inventory - OCI API
  description: Oracle Cloud Infrastructure inventory - compartments and OCI resources CloudGuard fetches from onboarded OCI
    tenancies.
  humanURL: https://docs.cgn.portal.checkpoint.com/reference
  tags:
  - Inventory
  - OCI
  - Oracle Cloud
  baseURL: https://api.dome9.com
  properties:
  - type: OpenAPI
    url: openapi/cloudguard-inventory-oci-openapi.yml
  - type: Overlay
    url: overlays/cloudguard-inventory-oci-overlay.yaml
  - type: Documentation
    url: https://docs.cgn.portal.checkpoint.com/reference
  - type: APIReference
    url: https://docs.cgn.portal.checkpoint.com/reference/introduction
  - type: Authentication
    url: https://docs.cgn.portal.checkpoint.com/reference/authentication
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
- aid: cloudguard:cloudguard-waf-api
  name: CloudGuard WAF API
  description: CloudGuard WAF (formerly CloudGuard AppSec) protects web applications and APIs with contextual machine-learning
    threat prevention. Its management API is GraphQL, reached through the Check Point Infinity Portal gateway; Check Point
    publishes no GraphQL schema document or REST contract for it, but does ship an official MCP server that wraps it.
  humanURL: https://waf-doc.inext.checkpoint.com/
  tags:
  - API Security
  - WAF
  - Web Application Firewall
  - GraphQL
  properties:
  - type: Documentation
    url: https://waf-doc.inext.checkpoint.com/
  - type: MCPServer
    url: mcp/cloudguard-mcp.yml
  - type: ToolCrosswalk
    url: mcp/cloudguard-tool-crosswalk.yml
  - type: SourceCode
    url: https://github.com/CheckPointSW/mcp-servers/tree/main/packages/checkpoint-waf
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
  baseURL: https://cloudinfra-gw.portal.checkpoint.com
  x-baseURL-note: Regional Infinity Portal gateway. The Check Point WAF API is GraphQL behind this host; the regional variants
    (cloudinfra-gw-us, cloudinfra-gw.ap, cloudinfra-gw.in, cloudinfra-gw.ae, cloudinfra-gw.ca) are documented in the official
    @chkp/checkpoint-waf-mcp README. No GraphQL schema document is published.
- aid: cloudguard:cloudguard-code-security-api
  name: CloudGuard Code Security (Spectral) API
  description: CloudGuard Code Security (formerly Spectral) provides developer-first secrets detection, infrastructure-as-code
    scanning and SCA. It is a CLI-driven toolchain wired into CI/CD rather than a REST API; the platform side is reached through
    the ShiftLeft account and policy operations of the CloudGuard Workload Protection API.
  humanURL: https://sc1.checkpoint.com/documents/CloudGuard_Dome9/Documentation/Code-Security-Spectral/Code-Security-Introduction.htm
  tags:
  - Code Security
  - Secrets Detection
  - SAST
  - IaC
  - CI/CD
  properties:
  - type: Documentation
    url: https://sc1.checkpoint.com/documents/CloudGuard_Dome9/Documentation/Code-Security-Spectral/Code-Security-Introduction.htm
  - type: CLI
    url: cli/cloudguard-cli.yml
  - type: GettingStarted
    url: https://sc1.checkpoint.com/documents/CloudGuard_Dome9/Documentation/Code-Security-Spectral/Get-Started-ShiftLeft.htm
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cloudguard.png
common:
- type: Website
  url: https://www.checkpoint.com/cloudguard/
- type: Documentation
  url: https://docs.cgn.portal.checkpoint.com/
- type: DeveloperPortal
  url: https://docs.cgn.portal.checkpoint.com/reference
- type: APIReference
  url: https://docs.cgn.portal.checkpoint.com/reference/introduction
- type: GettingStarted
  url: https://docs.cgn.portal.checkpoint.com/docs/getting-started-with-cloudguard
- type: Authentication
  url: https://docs.cgn.portal.checkpoint.com/reference/authentication
- type: SignUp
  url: https://portal.checkpoint.com/create-account
- type: Support
  url: https://support.checkpoint.com/
- type: Community
  url: https://community.checkpoint.com/
- type: Blog
  url: https://blog.checkpoint.com/feed/
- type: StatusPage
  url: https://status.checkpoint.com/
- type: PrivacyPolicy
  url: https://www.checkpoint.com/privacy/
- type: GitHubOrganization
  url: https://github.com/CheckPointSW
- type: Terraform Provider
  url: https://registry.terraform.io/providers/dome9/dome9/latest/docs
- type: Authentication
  url: authentication/cloudguard-authentication.yml
- type: AgenticAccess
  url: agentic-access/cloudguard-agentic-access.yml
- type: DomainSecurity
  url: security/cloudguard-domain-security.yml
- type: Packages
  url: packages/cloudguard-packages.yml
- type: SDKs
  url: packages/cloudguard-packages.yml
- type: CLI
  url: cli/cloudguard-cli.yml
- type: MCPServer
  url: mcp/cloudguard-mcp.yml
- type: ToolCrosswalk
  url: mcp/cloudguard-tool-crosswalk.yml
- type: AgentSkill
  url: skills/_index.yml
- type: LLMsTxt
  url: llms/cloudguard-llms.txt
- type: Conventions
  url: conventions/cloudguard-conventions.yml
- type: ErrorCatalog
  url: errors/cloudguard-problem-types.yml
- type: DataModel
  url: data-model/cloudguard-data-model.yml
- type: Conformance
  url: conformance/cloudguard-conformance.yml
- type: Lifecycle
  url: lifecycle/cloudguard-lifecycle.yml
- type: ChangeLog
  url: changelog/cloudguard-changelog.yml
- type: Webhooks
  url: asyncapi/cloudguard-webhooks.yml
- type: RateLimits
  url: rate-limits/cloudguard-rate-limits.yml
- type: Plans
  url: plans/cloudguard-plans-pricing.yml
- type: FinOps
  url: finops/cloudguard-finops.yml
- type: JSONLD
  url: json-ld/cloudguard-context.jsonld
- type: Spectral
  url: rules/cloudguard-rules.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
specificationVersion: '0.23'
x-enrichment:
  date: '2026-09-05'
  status: enriched
  artifacts_added: 88
  pass: local-v3
x-parent: checkpoint
x-relationship: product

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/cloudguard"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/cloudguard/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/cloudguard/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.