CyberArk website screenshot

CyberArk

CyberArk is the global leader in identity security, providing a unified Identity Security Platform that protects human, machine, and application identities across hybrid and multi-cloud environments. Core product lines include Privileged Access Manager (PAM Self-Hosted) and Privilege Cloud for credential vaulting and session management; Conjur Secrets Manager (Open Source, Enterprise, and Cloud) for machine-identity and DevOps secrets; CyberArk Identity for workforce SSO, MFA, and lifecycle; Endpoint Privilege Manager for least-privilege enforcement on Windows / macOS / Linux endpoints; Secure Cloud Access for just-in-time cloud entitlements; and Customer Identity for B2B / B2C identity. CyberArk publishes a canonical OpenAPI 3.1 specification for Conjur Secrets Manager at github.com/cyberark/conjur-openapi-spec, and REST APIs for PAM Self-Hosted, Privilege Cloud, and CyberArk Identity are documented on docs.cyberark.com and developer.cyberark.com.

CyberArk publishes 7 APIs on the APIs.io network, including Authentication API, Health API, Policies API, and 4 more. Tagged areas include Authentication, Cloud Security, Conjur, Credential Vault, and DevOps Secrets.

The CyberArk catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

CyberArk’s developer surface includes authentication, documentation, and 20 more developer resources.

49.4/100 developing ▬ flat Agent 31/100 agent aware Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessSelf serve
10 APIs
AuthenticationCloud SecurityConjurCredential VaultDevOps SecretsEndpoint Privilege ManagementIdentity SecurityMachine IdentityMFAOpenAPIPAMPrivileged AccessPrivileged Access ManagementSecrets ManagementSession ManagementSSOVaultZero Trust

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 49.4/100 · developing
Contract Quality 15.1 / 25
Developer Ergonomics 5.7 / 20
Commercial Clarity 13.7 / 20
Operational Transparency 4.8 / 13
Governance 3.8 / 12
Discoverability 6.5 / 10
Agent readiness — 31/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/cyberark: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 10

Individual APIs this provider publishes, each with its own machine-readable definition.

CyberArk PAM Self-Hosted REST API

The Privileged Access Manager Self-Hosted REST API exposes the Vault for managing accounts, safes, platforms, users, sessions, and applications. Authentication uses the Logon en...

CyberArk Privilege Cloud REST API

The Privilege Cloud Shared Services REST API mirrors the PAM Self-Hosted surface for accounts, safes, platforms, and users while running as a SaaS on the CyberArk Identity Secur...

CyberArk Identity REST API

The CyberArk Identity REST API enables programmatic management of users, roles, applications, MFA policies, SSO, and SCIM-based provisioning across the workforce identity tenant...

CyberArk Authentication API

Authenticate hosts and users, exchange credentials for access tokens.

CyberArk Health API

Health and information endpoints.

CyberArk Policies API

Load, update, and replace Conjur policy YAML.

CyberArk PublicKeys API

Retrieve public keys associated with users and hosts.

CyberArk Resources API

Inspect resources (hosts, users, groups, layers, variables) and check permissions.

CyberArk Roles API

Manage role membership and inspect role information.

CyberArk Secrets API

Store and retrieve secret values bound to variable resources.

Scroll for all 10

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Cyberark Rate Limits

4 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Cyberark Context

29 classes · 0 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

CyberArk API Rules

6 rules · 2 errors 4 warnings

SPECTRAL

CyberArk API Rules

5 rules · 3 warnings 2 info

SPECTRAL

JSON Schema 2

Standalone JSON Schema definitions for this provider's data models.

ConjurResource

5 properties

JSON SCHEMA

PrivilegedAccount

9 properties

JSON SCHEMA

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Cyberark Authentication

http · 1 scheme

SECURITY

Cyberark Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Cyberark Trust Center

SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS, HIPAA, FedRAMP, GDPR, CSA STAR

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Cyberark Agentic Access

13 operations · 5 acting

13 operations · 5 acting

AGENTIC

Resources

Get Started 1

Portal, sign-up, and the first successful call

Documentation 4

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 3

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Commercial 2

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 3

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: cyberark
name: CyberArk
kind: company
description: CyberArk is the global leader in identity security, providing a unified Identity Security Platform that protects
  human, machine, and application identities across hybrid and multi-cloud environments. Core product lines include Privileged
  Access Manager (PAM Self-Hosted) and Privilege Cloud for credential vaulting and session management; Conjur Secrets Manager
  (Open Source, Enterprise, and Cloud) for machine-identity and DevOps secrets; CyberArk Identity for workforce SSO, MFA,
  and lifecycle; Endpoint Privilege Manager for least-privilege enforcement on Windows / macOS / Linux endpoints; Secure Cloud
  Access for just-in-time cloud entitlements; and Customer Identity for B2B / B2C identity. CyberArk publishes a canonical
  OpenAPI 3.1 specification for Conjur Secrets Manager at github.com/cyberark/conjur-openapi-spec, and REST APIs for PAM Self-Hosted,
  Privilege Cloud, and CyberArk Identity are documented on docs.cyberark.com and developer.cyberark.com.
url: https://raw.githubusercontent.com/api-evangelist/cyberark/refs/heads/main/apis.yml
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/cyberark.png
type: Index
access: 3rd-Party
position: Consuming
created: '2026-03-25'
modified: '2026-05-19'
specificationVersion: '0.20'
tags:
- Authentication
- Cloud Security
- Conjur
- Credential Vault
- DevOps Secrets
- Endpoint Privilege Management
- Identity Security
- Machine Identity
- MFA
- OpenAPI
- PAM
- Privileged Access
- Privileged Access Management
- Secrets Management
- Session Management
- SSO
- Vault
- Zero Trust
apis:
- aid: cyberark:pam-self-hosted
  name: CyberArk PAM Self-Hosted REST API
  description: The Privileged Access Manager Self-Hosted REST API exposes the Vault for managing accounts, safes, platforms,
    users, sessions, and applications. Authentication uses the Logon endpoint at /PasswordVault/API/Auth/{provider}/Logon
    to obtain a session token used in the Authorization header for subsequent calls.
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
  humanURL: https://docs.cyberark.com/pam-self-hosted/latest/en/content/webservices/implementing%20privileged%20account%20security%20web%20services%20.htm
  tags:
  - Accounts
  - PAM
  - Privileged Access
  - REST
  - Safes
  - Sessions
  - Vault
  properties:
  - type: Documentation
    url: https://docs.cyberark.com/pam-self-hosted/latest/en/content/webservices/implementing%20privileged%20account%20security%20web%20services%20.htm
  - type: SampleScripts
    url: https://github.com/cyberark/epv-api-scripts
  - type: PowerShellModule
    url: https://github.com/pspete/psPAS
- aid: cyberark:privilege-cloud
  name: CyberArk Privilege Cloud REST API
  description: The Privilege Cloud Shared Services REST API mirrors the PAM Self-Hosted surface for accounts, safes, platforms,
    and users while running as a SaaS on the CyberArk Identity Security Platform. Identities and groups reference the tenant's
    CyberArk Identity directory.
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
  humanURL: https://docs.cyberark.com/privilege-cloud-shared-services/latest/en/content/sdk/sdk-overview.htm
  tags:
  - Accounts
  - PAM
  - Privilege Cloud
  - Safes
  - SaaS
  - Vault
  properties:
  - type: Documentation
    url: https://docs.cyberark.com/privilege-cloud-shared-services/latest/en/content/sdk/sdk-overview.htm
  - type: WhatsNew
    url: https://docs.cyberark.com/privilege-cloud-shared-services/latest/en/content/privilege%20cloud/privcloud-whatsnew-v12.2.htm
- aid: cyberark:identity
  name: CyberArk Identity REST API
  description: The CyberArk Identity REST API enables programmatic management of users, roles, applications, MFA policies,
    SSO, and SCIM-based provisioning across the workforce identity tenant. Tenants are addressed at {tenant}.id.cyberark.cloud
    and authentication uses OAuth2.
  image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
  humanURL: https://docs.cyberark.com/identity/Latest/en/Content/Developer/Developer.htm
  tags:
  - Identity
  - MFA
  - OAuth2
  - SCIM
  - SSO
  - Workforce Identity
  properties:
  - type: Documentation
    url: https://docs.cyberark.com/identity/Latest/en/Content/Developer/Developer.htm
  - type: SCIM
    url: https://docs.cyberark.com/identity/latest/en/content/developer/scim-management/scim-overview.htm
  - type: DeveloperPortal
    url: https://developer.cyberark.com/
- aid: cyberark:cyberark-authentication-api
  name: CyberArk Authentication API
  description: Authenticate hosts and users, exchange credentials for access tokens.
  humanURL: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  baseURL: https://conjur.example.com
  tags:
  - Authentication
  properties:
  - type: OpenAPI
    url: openapi/cyberark-authentication-api-openapi.yml
  - type: Documentation
    url: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  - type: CanonicalOpenAPI
    url: https://github.com/cyberark/conjur-openapi-spec
  - type: Capabilities
    url: capabilities/cyberark-conjur-capabilities.yml
  - type: Rules
    url: rules/cyberark-conjur-rules.yml
  - type: GitHubRepository
    url: https://github.com/cyberark/conjur
  - type: Blog
    url: https://developer.cyberark.com/blog/introducing-the-conjur-openapi-description/
- aid: cyberark:cyberark-health-api
  name: CyberArk Health API
  description: Health and information endpoints.
  humanURL: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  baseURL: https://conjur.example.com
  tags:
  - Health
  properties:
  - type: OpenAPI
    url: openapi/cyberark-health-api-openapi.yml
  - type: Documentation
    url: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  - type: CanonicalOpenAPI
    url: https://github.com/cyberark/conjur-openapi-spec
  - type: Capabilities
    url: capabilities/cyberark-conjur-capabilities.yml
  - type: Rules
    url: rules/cyberark-conjur-rules.yml
  - type: GitHubRepository
    url: https://github.com/cyberark/conjur
  - type: Blog
    url: https://developer.cyberark.com/blog/introducing-the-conjur-openapi-description/
- aid: cyberark:cyberark-policies-api
  name: CyberArk Policies API
  description: Load, update, and replace Conjur policy YAML.
  humanURL: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  baseURL: https://conjur.example.com
  tags:
  - Policies
  properties:
  - type: OpenAPI
    url: openapi/cyberark-policies-api-openapi.yml
  - type: Documentation
    url: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  - type: CanonicalOpenAPI
    url: https://github.com/cyberark/conjur-openapi-spec
  - type: Capabilities
    url: capabilities/cyberark-conjur-capabilities.yml
  - type: Rules
    url: rules/cyberark-conjur-rules.yml
  - type: GitHubRepository
    url: https://github.com/cyberark/conjur
  - type: Blog
    url: https://developer.cyberark.com/blog/introducing-the-conjur-openapi-description/
- aid: cyberark:cyberark-publickeys-api
  name: CyberArk PublicKeys API
  description: Retrieve public keys associated with users and hosts.
  humanURL: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  baseURL: https://conjur.example.com
  tags:
  - PublicKeys
  properties:
  - type: OpenAPI
    url: openapi/cyberark-publickeys-api-openapi.yml
  - type: Documentation
    url: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  - type: CanonicalOpenAPI
    url: https://github.com/cyberark/conjur-openapi-spec
  - type: Capabilities
    url: capabilities/cyberark-conjur-capabilities.yml
  - type: Rules
    url: rules/cyberark-conjur-rules.yml
  - type: GitHubRepository
    url: https://github.com/cyberark/conjur
  - type: Blog
    url: https://developer.cyberark.com/blog/introducing-the-conjur-openapi-description/
- aid: cyberark:cyberark-resources-api
  name: CyberArk Resources API
  description: Inspect resources (hosts, users, groups, layers, variables) and check permissions.
  humanURL: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  baseURL: https://conjur.example.com
  tags:
  - Resources
  properties:
  - type: OpenAPI
    url: openapi/cyberark-resources-api-openapi.yml
  - type: Documentation
    url: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  - type: CanonicalOpenAPI
    url: https://github.com/cyberark/conjur-openapi-spec
  - type: Capabilities
    url: capabilities/cyberark-conjur-capabilities.yml
  - type: Rules
    url: rules/cyberark-conjur-rules.yml
  - type: GitHubRepository
    url: https://github.com/cyberark/conjur
  - type: Blog
    url: https://developer.cyberark.com/blog/introducing-the-conjur-openapi-description/
- aid: cyberark:cyberark-roles-api
  name: CyberArk Roles API
  description: Manage role membership and inspect role information.
  humanURL: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  baseURL: https://conjur.example.com
  tags:
  - Roles
  properties:
  - type: OpenAPI
    url: openapi/cyberark-roles-api-openapi.yml
  - type: Documentation
    url: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  - type: CanonicalOpenAPI
    url: https://github.com/cyberark/conjur-openapi-spec
  - type: Capabilities
    url: capabilities/cyberark-conjur-capabilities.yml
  - type: Rules
    url: rules/cyberark-conjur-rules.yml
  - type: GitHubRepository
    url: https://github.com/cyberark/conjur
  - type: Blog
    url: https://developer.cyberark.com/blog/introducing-the-conjur-openapi-description/
- aid: cyberark:cyberark-secrets-api
  name: CyberArk Secrets API
  description: Store and retrieve secret values bound to variable resources.
  humanURL: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  baseURL: https://conjur.example.com
  tags:
  - Secrets
  properties:
  - type: OpenAPI
    url: openapi/cyberark-secrets-api-openapi.yml
  - type: Documentation
    url: https://docs.cyberark.com/conjur-cloud/latest/en/content/developer/conjur-api-openapi.html
  - type: CanonicalOpenAPI
    url: https://github.com/cyberark/conjur-openapi-spec
  - type: Capabilities
    url: capabilities/cyberark-conjur-capabilities.yml
  - type: Rules
    url: rules/cyberark-conjur-rules.yml
  - type: GitHubRepository
    url: https://github.com/cyberark/conjur
  - type: Blog
    url: https://developer.cyberark.com/blog/introducing-the-conjur-openapi-description/
common:
- type: AgenticAccess
  url: agentic-access/cyberark-agentic-access.yml
- type: TrustCenter
  url: security/cyberark-trust-center.yml
- type: DomainSecurity
  url: security/cyberark-domain-security.yml
- type: Authentication
  url: authentication/cyberark-authentication.yml
- type: LinkedIn
  url: https://www.linkedin.com/company/cyber-ark-software
- type: Website
  url: https://www.cyberark.com
- type: Products
  url: https://www.cyberark.com/products/
- type: Documentation
  url: https://docs.cyberark.com
- type: DeveloperPortal
  url: https://developer.cyberark.com/
- type: GitHubOrganization
  url: https://github.com/cyberark
- type: ConjurOpenAPISpec
  url: https://github.com/cyberark/conjur-openapi-spec
- type: Marketplace
  url: https://marketplace.cyberark.com/
- type: Trust
  url: https://www.cyberark.com/trust/
- type: TermsOfService
  url: https://www.cyberark.com/legal-terms-of-use/
- type: PrivacyPolicy
  url: https://www.cyberark.com/privacy-policy/
- type: JSONLD
  url: json-ld/cyberark-context.jsonld
- type: JSONSchema
  url: json-schema/cyberark-conjur-resource-schema.json
- type: JSONSchema
  url: json-schema/cyberark-privileged-account-schema.json
- type: Vocabulary
  url: vocabulary/cyberark-vocabulary.yml
- type: Capabilities
  url: capabilities/cyberark-conjur-capabilities.yml
- type: Rules
  url: rules/cyberark-conjur-rules.yml
- type: LlmsText
  url: https://developer.cyberark.com/llms.txt
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com