Defakto Security website screenshot

Defakto Security

Defakto (formerly SPIRL) is a non-human identity (NHI) security company that issues short-lived, cryptographically attested identities to workloads, services, CI/CD pipelines and AI agents in place of static secrets, API keys and long-lived service accounts. The platform is built on SPIFFE and ships two products: Mint, which runs Trust Domain Servers and Agents that mint X.509-SVIDs, JWT-SVIDs and proof-of-possession WIT-SVIDs for Kubernetes, Linux, Docker and serverless workloads under a dozen attestation methods; and Ledger, which discovers, risk-scores and eradicates static secrets across AWS, Azure, GCP, Kubernetes, Anthropic, OpenAI, Bedrock AgentCore and Gemini. The control plane is driven by a gRPC management API and the spirlctl CLI, with a Go SDK, an OpenTofu/Terraform provider, workload identity federation into AWS/Azure/GCP, and OCSF 1.8.0 audit logging.

Defakto Security publishes 2 APIs on the APIs.io network. Tagged areas include Security, Identity, Non-Human Identity, Workload Identity, and SPIFFE.

The Defakto Security catalog on APIs.io includes 1 event-driven AsyncAPI specification.

Defakto Security’s developer surface includes documentation, API reference, getting-started guide, engineering blog, support, signup flow, CLI, and 23 more developer resources.

46.7/100 developing ▬ flat Agent 26/100 agent aware saas Full breakdown ↓
scored 2026-09-08 · rubric v0.20.0
AccessApproval
2 APIs
SecurityIdentityNon-Human IdentityWorkload IdentitySPIFFEAuthenticationZero TrustSecrets ManagementKubernetesCI/CDCloud SecuritygRPCMachine IdentityAgentic AI

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-08 · rubric v0.20.0
Create-or-Update Ergonomics could not be measured. We hold no machine-readable contract for this provider to read, so there is nothing to measure a write surface against. Excluded rather than scored zero: never-measured and measured-empty are different facts. Publishing an OpenAPI is what makes this facet — and several others — scorable at all.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/defakto-security: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 2

Individual APIs this provider publishes, each with its own machine-readable definition.

Defakto Management API

The Defakto control-plane API. A gRPC service surface of sixteen versioned services covering trust domains, clusters, realms, workloads, access policy, service accounts and sess...

SPIRL Management API (legacy)

The pre-rebrand SPIRL control-plane endpoint, still documented and still serving the legacy app.spirl.com console and the spirlctl CLI alongside the current api.defakto.security...

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Defakto Security Rate Limits

0 limits

RATE LIMITS

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Defakto Security Domain Security

TLSv1.3 · DNSSEC · DMARC

SECURITY

Defakto Security Vulnerability Disclosure

Hackerone · contact published

SECURITY

Resources

Get Started 4

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 5

Pagination, idempotency, versioning, errors, and events

Build 4

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 4

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: defakto-security
name: Defakto Security
description: 'Defakto (formerly SPIRL) is a non-human identity (NHI) security company that issues short-lived, cryptographically
  attested identities to workloads, services, CI/CD pipelines and AI agents in place of static secrets, API keys and long-lived
  service accounts. The platform is built on SPIFFE and ships two products: Mint, which runs Trust Domain Servers and Agents
  that mint X.509-SVIDs, JWT-SVIDs and proof-of-possession WIT-SVIDs for Kubernetes, Linux, Docker and serverless workloads
  under a dozen attestation methods; and Ledger, which discovers, risk-scores and eradicates static secrets across AWS, Azure,
  GCP, Kubernetes, Anthropic, OpenAI, Bedrock AgentCore and Gemini. The control plane is driven by a gRPC management API and
  the spirlctl CLI, with a Go SDK, an OpenTofu/Terraform provider, workload identity federation into AWS/Azure/GCP, and OCSF
  1.8.0 audit logging.'
url: https://raw.githubusercontent.com/api-evangelist/defakto-security/refs/heads/main/apis.yml
deliveryModel:
  model: saas
  open_source: false
  commercial: true
  callable_host: false
  label: Hosted service · you call their endpoint
  confidence: medium
  source:
  - pricing
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: unknown
  onboarding: approval
  trial: false
  try_now: false
  public: false
  label: Requires approval
  confidence: medium
  source:
  - plans
  - authentication
  - rate-limits
  - security
  - sandbox
  generated: '2026-09-03'
  method: derived
image: https://www.defakto.security/wp-content/uploads/2025/09/defakto-logo.svg
x-type: company
x-source: harvest:secondary-market
specificationVersion: '0.23'
created: '2026-08-12'
modified: '2026-08-12'
tags:
- Security
- Identity
- Non-Human Identity
- Workload Identity
- SPIFFE
- Authentication
- Zero Trust
- Secrets Management
- Kubernetes
- CI/CD
- Cloud Security
- gRPC
- Machine Identity
- Agentic AI
apis:
- aid: defakto-security-management-api
  name: Defakto Management API
  description: 'The Defakto control-plane API. A gRPC service surface of sixteen versioned services covering trust domains,
    clusters, realms, workloads, access policy, service accounts and sessions, agent and provider attestation, CI/CD profiles,
    federation, developer identity, managed configuration, alerts, statistics and the Ledger secret scanner. It is the API
    behind the console at console.defakto.security and the spirlctl CLI. There is no REST/OpenAPI surface: the transport is
    gRPC over HTTP/2 on port 443, and the contract is distributed as generated client bindings in the Go SDK rather than as
    published .proto files.'
  humanURL: https://d.defakto.security/
  baseURL: https://api.defakto.security
  tags:
  - Identity
  - Workload Identity
  - gRPC
  - Security
  properties:
  - type: Documentation
    url: https://d.defakto.security/
  - type: GettingStarted
    url: https://d.defakto.security/mint/quick-start.md
  - type: Authentication
    url: authentication/defakto-security-authentication.yml
  - type: Protobuf
    url: grpc/_index.yml
  - type: Protobuf
    url: grpc/defakto-security-trustdomainapi.proto
  - type: Protobuf
    url: grpc/defakto-security-clusterapi.proto
  - type: Protobuf
    url: grpc/defakto-security-accessapi.proto
  - type: Protobuf
    url: grpc/defakto-security-workloadsapi.proto
  - type: Protobuf
    url: grpc/defakto-security-realmapi.proto
  - type: Protobuf
    url: grpc/defakto-security-sessionapi.proto
  - type: Protobuf
    url: grpc/defakto-security-scannerapi.proto
  - type: Protobuf
    url: grpc/defakto-security-configapi.proto
  - type: Protobuf
    url: grpc/defakto-security-federationapi.proto
  - type: Protobuf
    url: grpc/defakto-security-cicdapi.proto
  - type: Protobuf
    url: grpc/defakto-security-devidentityapi.proto
  - type: Protobuf
    url: grpc/defakto-security-agentattestationapi.proto
  - type: Protobuf
    url: grpc/defakto-security-providerattestationapi.proto
  - type: Protobuf
    url: grpc/defakto-security-alertapi.proto
  - type: Protobuf
    url: grpc/defakto-security-statisticsapi.proto
  - type: Protobuf
    url: grpc/defakto-security-listing.proto
  - type: ErrorCatalog
    url: errors/defakto-security-problem-types.yml
  - type: DataModel
    url: data-model/defakto-security-data-model.yml
- aid: defakto-security-legacy-management-api
  name: SPIRL Management API (legacy)
  description: The pre-rebrand SPIRL control-plane endpoint, still documented and still serving the legacy app.spirl.com console
    and the spirlctl CLI alongside the current api.defakto.security host. Same gRPC service surface; Defakto lists both hosts
    in its published network-requirements allowlist, so the legacy host is live rather than retired.
  humanURL: https://d.defakto.security/mint/install/endpoints.md
  baseURL: https://api.spirl.com
  tags:
  - Identity
  - gRPC
  - Legacy
  properties:
  - type: Documentation
    url: https://d.defakto.security/mint/install/endpoints.md
  - type: Lifecycle
    url: lifecycle/defakto-security-lifecycle.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: VulnerabilityDisclosure
  url: security/defakto-security-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/defakto-security-domain-security.yml
- type: Website
  url: https://www.defakto.security/
- type: DeveloperPortal
  url: https://d.defakto.security/
- type: Documentation
  url: https://d.defakto.security/
- type: APIReference
  url: https://d.defakto.security/cli/spirlctl/overview.md
- type: GettingStarted
  url: https://d.defakto.security/mint/quick-start.md
- type: Blog
  url: https://www.defakto.security/blog/
- type: GitHubOrganization
  url: https://github.com/defakto-security
- type: Support
  url: https://www.defakto.security/contact/
- type: SignUp
  url: https://www.defakto.security/demo/
- type: TermsOfService
  url: https://www.defakto.security/terms-of-use/
- type: PrivacyPolicy
  url: https://www.defakto.security/privacy-policy/
- type: Security
  url: https://www.defakto.security/security/
- type: LLMsTxt
  url: llms/defakto-security-llms.txt
- type: Packages
  url: packages/defakto-security-packages.yml
- type: SDKs
  url: packages/defakto-security-packages.yml
- type: CLI
  url: cli/defakto-security-cli.yml
- type: Authentication
  url: authentication/defakto-security-authentication.yml
- type: Conventions
  url: conventions/defakto-security-conventions.yml
- type: Conformance
  url: conformance/defakto-security-conformance.yml
- type: ErrorCatalog
  url: errors/defakto-security-problem-types.yml
- type: Lifecycle
  url: lifecycle/defakto-security-lifecycle.yml
- type: Deprecation
  url: lifecycle/defakto-security-lifecycle.yml
- type: ChangeLog
  url: changelog/defakto-security-changelog.yml
- type: DataModel
  url: data-model/defakto-security-data-model.yml
- type: Sandbox
  url: sandbox/defakto-security-sandbox.yml
- type: Plans
  url: plans/defakto-security-plans-pricing.yml
- type: RateLimits
  url: rate-limits/defakto-security-rate-limits.yml
- type: AgentSkill
  url: skills/_index.yml
x-enrichment:
  date: '2026-08-12'
  status: enriched
  artifacts_added: 39
  pass: local-v1

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/defakto-security"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/defakto-security/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/defakto-security/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.