Cybersecurity and Infrastructure Security Agency
The Cybersecurity and Infrastructure Security Agency (CISA) is the United States federal civilian cybersecurity agency, part of the Department of Homeland Security. CISA reduces cybersecurity and physical security risk for the nation, coordinates federal civilian cyber defense, and partners with state, local, tribal, and territorial governments and the private sector. CISA publishes a number of public, unauthenticated machine-readable feeds, including the Known Exploited Vulnerabilities (KEV) catalog (mandatorily remediated by federal civilian agencies under Binding Operational Directive 22-01), Cybersecurity Advisories, and Common Security Advisory Framework (CSAF) advisories. CISA also operates an Automated Indicator Sharing (AIS) TAXII 2.1 server that delivers STIX cyber threat indicators to vetted partners under a Terms of Use and Interconnection Agreement.
Cybersecurity and Infrastructure Security Agency publishes 2 APIs on the APIs.io network: KEV API and Schema API. Tagged areas include Advisories, AIS, Binding Operational Directive, CSAF, and CVE.
The Cybersecurity and Infrastructure Security Agency catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
Cybersecurity and Infrastructure Security Agency’s developer surface includes engineering blog and 19 more developer resources.
Kin Score
APIs 4
Individual APIs this provider publishes, each with its own machine-readable definition.
CISA Automated Indicator Sharing (AIS) TAXII Server
CISA's Automated Indicator Sharing (AIS) program uses a TAXII 2.1 server to deliver STIX-formatted cyber threat indicators (CTI) and defensive measures (DM) to vetted partners. ...
CISA Cybersecurity Advisories
CISA publishes Cybersecurity Advisories (CSAs), Industrial Control Systems Advisories (ICSAs), and Common Security Advisory Framework (CSAF) JSON documents describing tactics, t...
Cybersecurity and Infrastructure Security Agency KEV API
Known Exploited Vulnerabilities catalog feed
Cybersecurity and Infrastructure Security Agency Schema API
JSON Schema for the KEV catalog
Open Collections 1
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
CISA Known Exploited Vulnerabilities (KEV) Catalog API
OPEN COLLECTIONPricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
FinOps 1
Cost, billing, and metering signals for API financial operations.
Semantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Cisa Context
JSON-LDSpectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
JSON Schema 1
Standalone JSON Schema definitions for this provider's data models.
KevVulnerability
JSON SCHEMASecurity Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Cybersecurity And Infrastructure Security Agency Domain Security
TLSv1.3 · HSTS · DNSSEC · DMARC
SECURITYCybersecurity And Infrastructure Security Agency Vulnerability Disclosure
security.txt · contact published
SECURITYAgentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 3
Pagination, idempotency, versioning, errors, and events
Build 2
SDKs, sample code, and the tooling you integrate with
Access & Security 2
Authentication, authorization, and security posture
Operate 1
Status, limits, changes, and where to get help
Commercial 1
Pricing, plans, and the legal terms of use
Company 4
The organization behind the API
Other 5
Properties that don't map to a standard resource type