Defakto Security

Defakto (formerly SPIRL) is a non-human identity (NHI) security company that issues short-lived, cryptographically attested identities to workloads, services, CI/CD pipelines and AI agents in place of static secrets, API keys and long-lived service accounts. The platform is built on SPIFFE and ships two products: Mint, which runs Trust Domain Servers and Agents that mint X.509-SVIDs, JWT-SVIDs and proof-of-possession WIT-SVIDs for Kubernetes, Linux, Docker and serverless workloads under a dozen attestation methods; and Ledger, which discovers, risk-scores and eradicates static secrets across AWS, Azure, GCP, Kubernetes, Anthropic, OpenAI, Bedrock AgentCore and Gemini. The control plane is driven by a gRPC management API and the spirlctl CLI, with a Go SDK, an OpenTofu/Terraform provider, workload identity federation into AWS/Azure/GCP, and OCSF 1.8.0 audit logging.

Defakto Security publishes 2 APIs on the APIs.io network. Tagged areas include Security, Identity, Non-Human Identity, Workload Identity, and SPIFFE.

The Defakto Security catalog on APIs.io includes 1 event-driven AsyncAPI specification.

Defakto Security’s developer surface includes documentation, API reference, getting-started guide, engineering blog, support, signup flow, CLI, and 23 more developer resources.

49.6/100 developing ▬ flat Agent 42/100 agent ready Full breakdown ↓
scored 2026-08-17 · rubric v0.11.0
2 APIs
SecurityIdentityNon-Human IdentityWorkload IdentitySPIFFEAuthenticationZero TrustSecrets ManagementKubernetesCI/CDCloud SecuritygRPCMachine IdentityAgentic AI

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-17 · rubric v0.11.0
Composite quality — 49.6/100 · developing
Contract Quality 12.9 / 25
Developer Ergonomics 15.7 / 20
Commercial Clarity 6.8 / 20
Operational Transparency 5.1 / 13
Governance 1.5 / 12
Discoverability 7.6 / 10
Agent readiness — 42/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 0 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 6 / 6
Agent Skills 5 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/defakto-security: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 2

Individual APIs this provider publishes, each with its own machine-readable definition.

Defakto Management API

The Defakto control-plane API. A gRPC service surface of sixteen versioned services covering trust domains, clusters, realms, workloads, access policy, service accounts and sess...

SPIRL Management API (legacy)

The pre-rebrand SPIRL control-plane endpoint, still documented and still serving the legacy app.spirl.com console and the spirlctl CLI alongside the current api.defakto.security...

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Defakto Security Rate Limits

0 limits

RATE LIMITS

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Defakto Security Domain Security

TLSv1.3 · DNSSEC · DMARC

SECURITY

Defakto Security Vulnerability Disclosure

Hackerone · contact published

SECURITY

Resources

Get Started 4

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 5

Pagination, idempotency, versioning, errors, and events

Build 4

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 4

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: defakto-security
name: Defakto Security
description: 'Defakto (formerly SPIRL) is a non-human identity (NHI) security company that issues short-lived, cryptographically
  attested identities to workloads, services, CI/CD pipelines and AI agents in place of static secrets, API keys and long-lived
  service accounts. The platform is built on SPIFFE and ships two products: Mint, which runs Trust Domain Servers and Agents
  that mint X.509-SVIDs, JWT-SVIDs and proof-of-possession WIT-SVIDs for Kubernetes, Linux, Docker and serverless workloads
  under a dozen attestation methods; and Ledger, which discovers, risk-scores and eradicates static secrets across AWS, Azure,
  GCP, Kubernetes, Anthropic, OpenAI, Bedrock AgentCore and Gemini. The control plane is driven by a gRPC management API and
  the spirlctl CLI, with a Go SDK, an OpenTofu/Terraform provider, workload identity federation into AWS/Azure/GCP, and OCSF
  1.8.0 audit logging.'
url: https://raw.githubusercontent.com/api-evangelist/defakto-security/refs/heads/main/apis.yml
image: https://www.defakto.security/wp-content/uploads/2025/09/defakto-logo.svg
x-type: company
x-source: harvest:secondary-market
specificationVersion: '0.20'
created: '2026-08-12'
modified: '2026-08-12'
tags:
- Security
- Identity
- Non-Human Identity
- Workload Identity
- SPIFFE
- Authentication
- Zero Trust
- Secrets Management
- Kubernetes
- CI/CD
- Cloud Security
- gRPC
- Machine Identity
- Agentic AI
apis:
- aid: defakto-security-management-api
  name: Defakto Management API
  description: 'The Defakto control-plane API. A gRPC service surface of sixteen versioned services covering trust domains,
    clusters, realms, workloads, access policy, service accounts and sessions, agent and provider attestation, CI/CD profiles,
    federation, developer identity, managed configuration, alerts, statistics and the Ledger secret scanner. It is the API
    behind the console at console.defakto.security and the spirlctl CLI. There is no REST/OpenAPI surface: the transport is
    gRPC over HTTP/2 on port 443, and the contract is distributed as generated client bindings in the Go SDK rather than as
    published .proto files.'
  humanURL: https://d.defakto.security/
  baseURL: https://api.defakto.security
  tags:
  - Identity
  - Workload Identity
  - gRPC
  - Security
  properties:
  - type: Documentation
    url: https://d.defakto.security/
  - type: GettingStarted
    url: https://d.defakto.security/mint/quick-start.md
  - type: Authentication
    url: authentication/defakto-security-authentication.yml
  - type: Protobuf
    url: grpc/_index.yml
  - type: Protobuf
    url: grpc/defakto-security-trustdomainapi.proto
  - type: Protobuf
    url: grpc/defakto-security-clusterapi.proto
  - type: Protobuf
    url: grpc/defakto-security-accessapi.proto
  - type: Protobuf
    url: grpc/defakto-security-workloadsapi.proto
  - type: Protobuf
    url: grpc/defakto-security-realmapi.proto
  - type: Protobuf
    url: grpc/defakto-security-sessionapi.proto
  - type: Protobuf
    url: grpc/defakto-security-scannerapi.proto
  - type: Protobuf
    url: grpc/defakto-security-configapi.proto
  - type: Protobuf
    url: grpc/defakto-security-federationapi.proto
  - type: Protobuf
    url: grpc/defakto-security-cicdapi.proto
  - type: Protobuf
    url: grpc/defakto-security-devidentityapi.proto
  - type: Protobuf
    url: grpc/defakto-security-agentattestationapi.proto
  - type: Protobuf
    url: grpc/defakto-security-providerattestationapi.proto
  - type: Protobuf
    url: grpc/defakto-security-alertapi.proto
  - type: Protobuf
    url: grpc/defakto-security-statisticsapi.proto
  - type: Protobuf
    url: grpc/defakto-security-listing.proto
  - type: ErrorCatalog
    url: errors/defakto-security-problem-types.yml
  - type: DataModel
    url: data-model/defakto-security-data-model.yml
- aid: defakto-security-legacy-management-api
  name: SPIRL Management API (legacy)
  description: The pre-rebrand SPIRL control-plane endpoint, still documented and still serving the legacy app.spirl.com console
    and the spirlctl CLI alongside the current api.defakto.security host. Same gRPC service surface; Defakto lists both hosts
    in its published network-requirements allowlist, so the legacy host is live rather than retired.
  humanURL: https://d.defakto.security/mint/install/endpoints.md
  baseURL: https://api.spirl.com
  tags:
  - Identity
  - gRPC
  - Legacy
  properties:
  - type: Documentation
    url: https://d.defakto.security/mint/install/endpoints.md
  - type: Lifecycle
    url: lifecycle/defakto-security-lifecycle.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: VulnerabilityDisclosure
  url: security/defakto-security-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/defakto-security-domain-security.yml
- type: Website
  url: https://www.defakto.security/
- type: DeveloperPortal
  url: https://d.defakto.security/
- type: Documentation
  url: https://d.defakto.security/
- type: APIReference
  url: https://d.defakto.security/cli/spirlctl/overview.md
- type: GettingStarted
  url: https://d.defakto.security/mint/quick-start.md
- type: Blog
  url: https://www.defakto.security/blog/
- type: GitHubOrganization
  url: https://github.com/defakto-security
- type: Support
  url: https://www.defakto.security/contact/
- type: SignUp
  url: https://www.defakto.security/demo/
- type: TermsOfService
  url: https://www.defakto.security/terms-of-use/
- type: PrivacyPolicy
  url: https://www.defakto.security/privacy-policy/
- type: Security
  url: https://www.defakto.security/security/
- type: LLMsTxt
  url: llms/defakto-security-llms.txt
- type: Packages
  url: packages/defakto-security-packages.yml
- type: SDKs
  url: packages/defakto-security-packages.yml
- type: CLI
  url: cli/defakto-security-cli.yml
- type: Authentication
  url: authentication/defakto-security-authentication.yml
- type: Conventions
  url: conventions/defakto-security-conventions.yml
- type: Conformance
  url: conformance/defakto-security-conformance.yml
- type: ErrorCatalog
  url: errors/defakto-security-problem-types.yml
- type: Lifecycle
  url: lifecycle/defakto-security-lifecycle.yml
- type: Deprecation
  url: lifecycle/defakto-security-lifecycle.yml
- type: ChangeLog
  url: changelog/defakto-security-changelog.yml
- type: DataModel
  url: data-model/defakto-security-data-model.yml
- type: Sandbox
  url: sandbox/defakto-security-sandbox.yml
- type: Plans
  url: plans/defakto-security-plans-pricing.yml
- type: RateLimits
  url: rate-limits/defakto-security-rate-limits.yml
- type: AgentSkill
  url: skills/_index.yml
x-enrichment:
  date: '2026-08-12'
  status: enriched
  artifacts_added: 39
  pass: local-v1