# CyberArk

**Canonical:** https://apis.io/providers/cyberark/  
**Website:** https://www.cyberark.com  
**APIs profiled:** 10

CyberArk is the global leader in identity security, providing a unified Identity Security Platform that protects human, machine, and application identities across hybrid and multi-cloud environments. Core product lines include Privileged Access Manager (PAM Self-Hosted) and Privilege Cloud for credential vaulting and session management; Conjur Secrets Manager (Open Source, Enterprise, and Cloud) for machine-identity and DevOps secrets; CyberArk Identity for workforce SSO, MFA, and lifecycle; Endpoint Privilege Manager for least-privilege enforcement on Windows / macOS / Linux endpoints; Secure Cloud Access for just-in-time cloud entitlements; and Customer Identity for B2B / B2C identity. CyberArk publishes a canonical OpenAPI 3.1 specification for Conjur Secrets Manager at github.com/cyberark/conjur-openapi-spec, and REST APIs for PAM Self-Hosted, Privilege Cloud, and CyberArk Identity are documented on docs.cyberark.com and developer.cyberark.com.

## Kin Score — 37.0 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 37.0).

| Facet | Score |
|---|---|
| Discoverability | 64.8 |
| Contract Quality | 57.3 |
| Governance | 60.6 |
| Contract Governance | 60.6 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 11.9 |
| Commercial Clarity | 15.8 |
| Access Clarity | 15.8 |

## Agent readiness — 29.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: high).

## APIs (10)

- **CyberArk PAM Self-Hosted REST API** — The Privileged Access Manager Self-Hosted REST API exposes the Vault for managing accounts, safes, platforms, users, sessions, and applications. Authentication uses the Logon en...
- **CyberArk Privilege Cloud REST API** — The Privilege Cloud Shared Services REST API mirrors the PAM Self-Hosted surface for accounts, safes, platforms, and users while running as a SaaS on the CyberArk Identity Secur...
- **CyberArk Identity REST API** — The CyberArk Identity REST API enables programmatic management of users, roles, applications, MFA policies, SSO, and SCIM-based provisioning across the workforce identity tenant...
- **CyberArk Authentication API** — Authenticate hosts and users, exchange credentials for access tokens.
- **CyberArk Health API** — Health and information endpoints.
- **CyberArk Policies API** — Load, update, and replace Conjur policy YAML.
- **CyberArk PublicKeys API** — Retrieve public keys associated with users and hosts.
- **CyberArk Resources API** — Inspect resources (hosts, users, groups, layers, variables) and check permissions.
- **CyberArk Roles API** — Manage role membership and inspect role information.
- **CyberArk Secrets API** — Store and retrieve secret values bound to variable resources.

## Agentic access (1)

- **Cyberark Agentic Access** — 13 operations · 5 acting

## Security (3)

- **Cyberark Authentication** — http · 1 scheme
- **Cyberark Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Cyberark Trust Center** — SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS, HIPAA, FedRAMP, GDPR, CSA STAR

## Plans (1)

- **Cyberark Plans Pricing**

## Tags

Authentication, Cloud Security, Conjur, Credential Vault, DevOps Secrets, Endpoint Privilege Management, Identity Security, Machine Identity, MFA, OpenAPI, PAM, Privileged Access, Privileged Access Management, Secrets Management, Session Management, SSO, Vault, Zero Trust

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/cyberark/). Scores are computed from the provider's own public artifacts under a published rubric.
