# Contrast Security

**Canonical:** https://apis.io/providers/contrast-security/  
**Website:** https://www.contrastsecurity.com  
**APIs profiled:** 5

Contrast Security is an application security platform that uses instrumentation-based agents to provide Interactive Application Security Testing (IAST), Runtime Application Self-Protection (RASP), and Software Composition Analysis (SCA) across Java, .NET, Node.js, Python, PHP, Go, and Ruby applications. The platform identifies, prioritizes, and defends against vulnerabilities and attacks in real time from inside running applications. Contrast's REST API enables programmatic access to TeamServer applications, libraries, vulnerabilities, and traces, authenticated via API key plus Authorization header (Base64 of username:service_key) and an Organization ID.

## Kin Score — 28.6 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 28.6).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 55.2 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 0.0 |
| Developer Ergonomics | 23.8 |
| Commercial Clarity | 13.2 |
| Access Clarity | 13.2 |

## Agent readiness — 43.2 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | na |
| MCP Server | documented |
| Auth Clarity | yes |
| Idempotency | na |
| Error Semantics | no |
| OpenAPI Examples | verified |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | na |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (5)

- **Contrast TeamServer REST API** — REST API for interacting with Contrast TeamServer to manage applications, libraries, vulnerabilities, traces, servers, agents, and organization settings. Requires an API key, Au...
- **Contrast Security Applications API** — An application represents an executable unit of code that can be instrumented at runtime by an agent in Contrast. This can be a web app, microservice, or other runnable code and...
- **Contrast Security Organizations API** — An organization represents a grouping of user accounts in Contrast.
- **Contrast Security Rules API** — A rule defines a data flow pattern used to categorize vulnerability and attack types. Some common rules are sql-injection, ssrf, and reflected-xss.
- **Contrast Security Vulnerabilities API** — Vulnerabilities detected in runtime by Contrast Assess are weaknesses in the application code that allow an attacker to cause harm.

## MCP servers (2)

- **MCP Server**
- **MCP Server Source**

## Agentic access (1)

- **Contrast Security Agentic Access** — 8 operations

## Security (3)

- **Contrast Security Authentication** — apiKey · 2 schemes
- **Contrast Security Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Contrast Security Vulnerability Disclosure** — security.txt · contact published

## Tags

Application Security, AppSec, IAST, RASP, SCA, DevSecOps, Runtime Protection

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/contrast-security/). Scores are computed from the provider's own public artifacts under a published rubric.
