Ensighten website screenshot

Ensighten

Ensighten is an enterprise tag management, data governance, and client-side website security platform. It gives digital, marketing, and privacy teams centralized control over the third-party tags, scripts, and vendor code that run on their web and mobile properties, enforcing consent and privacy rules (GDPR, CCPA) at the point of data collection. The platform combines server- and client-side tag management, malicious-script and data-leakage detection (client-side security), and consent management. Ensighten was acquired by CHEQ (CHEQ AI Technologies Ltd.) and is now delivered as part of CHEQ's Control & Compliance / Go-to-Market Security suite; the ensighten.com domain 301-redirects to cheq.ai. This company profile was surfaced as an Insight Partners portfolio lead and enriched by the API Evangelist pipeline. Ensighten does publish a public REST contract: the Ensighten Manage API, documented as an API Blueprint at manageexternalapi.docs.apiary.io and served in production from manage-api.ensighten.com. It covers 66 operations across Spaces, Publish Paths, Deployments, Conditions, Data Definitions, Event Definitions, Labels, Users, Roles, SCIM 2.0 user/group provisioning, Git-enabled spaces, and TDN jobs. Authentication is either an X-API-Key API key or an OAuth 2.0 Resource Owner Password Credentials bearer token from /auth/token.

Ensighten publishes 1 API on the APIs.io network: Manage API. Tagged areas include Company, Cybersecurity, Tag Management, Data Governance, and Client-Side Security.

Ensighten’s developer surface includes support, engineering blog, documentation, API reference, getting-started guide, changelog, and 19 more developer resources.

49.7/100 developing ▲ 33.4 Agent 34/100 agent aware Full breakdown ↓
scored 2026-08-17 · rubric v0.11.0
1 APIs
CompanyCybersecurityTag ManagementData GovernanceClient-Side SecurityConsent ManagementPrivacy ComplianceMarketing Technology

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-17 · rubric v0.11.0
Composite quality — 49.7/100 · developing
Contract Quality 12.9 / 25
Developer Ergonomics 9.1 / 20
Commercial Clarity 10.0 / 20
Operational Transparency 6.5 / 13
Governance 2.5 / 12
Discoverability 8.7 / 10
Agent readiness — 34/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 0 / 10
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 5 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/ensighten: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

Ensighten Manage API

The REST Manage API used by Ensighten Manage customers to administer tag management programmatically. Sixty-six operations covering Spaces, Publish Paths, Deployments (create, u...

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Ensighten Rate Limits

1 limits

RATE LIMITS

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Ensighten Authentication

apiKey/http/oauth2 · 3 schemes

SECURITY

Ensighten Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Ensighten Trust Center

SOC 2 Type II, ISO 27001, ISO 27701, ISO 42001, CSA STAR Level 1, GDPR, CCPA

SECURITY

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 3

Pagination, idempotency, versioning, errors, and events

Build 3

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 4

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: ensighten
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source: []
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/ensighten.png
name: Ensighten
description: 'Ensighten is an enterprise tag management, data governance, and client-side website security platform. It gives
  digital, marketing, and privacy teams centralized control over the third-party tags, scripts, and vendor code that run on
  their web and mobile properties, enforcing consent and privacy rules (GDPR, CCPA) at the point of data collection. The platform
  combines server- and client-side tag management, malicious-script and data-leakage detection (client-side security), and
  consent management. Ensighten was acquired by CHEQ (CHEQ AI Technologies Ltd.) and is now delivered as part of CHEQ''s Control
  & Compliance / Go-to-Market Security suite; the ensighten.com domain 301-redirects to cheq.ai. This company profile was
  surfaced as an Insight Partners portfolio lead and enriched by the API Evangelist pipeline. Ensighten does publish a public
  REST contract: the Ensighten Manage API, documented as an API Blueprint at manageexternalapi.docs.apiary.io and served in
  production from manage-api.ensighten.com. It covers 66 operations across Spaces, Publish Paths, Deployments, Conditions,
  Data Definitions, Event Definitions, Labels, Users, Roles, SCIM 2.0 user/group provisioning, Git-enabled spaces, and TDN
  jobs. Authentication is either an X-API-Key API key or an OAuth 2.0 Resource Owner Password Credentials bearer token from
  /auth/token.'
url: https://raw.githubusercontent.com/api-evangelist/ensighten/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- insight-partners
x-tier: enriched
x-tier-reason: Promoted from stub on 2026-08-13. The prior profile recorded "no public REST API"; contract discovery found
  the Ensighten Manage API — 66 operations, first-party, contract updated 2026-07-14 — published as an API Blueprint on Apiary
  and live at manage-api.ensighten.com.
x-parent-company: cheq
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-08-13'
tags:
- Company
- Cybersecurity
- Tag Management
- Data Governance
- Client-Side Security
- Consent Management
- Privacy Compliance
- Marketing Technology
apis:
- aid: ensighten:manage-api
  name: Ensighten Manage API
  description: The REST Manage API used by Ensighten Manage customers to administer tag management programmatically. Sixty-six
    operations covering Spaces, Publish Paths, Deployments (create, update, enable/disable, commit/uncommit, archive, merge
    across spaces), Conditions, Data Definitions, Event Definitions, Labels, Users, Roles, SCIM 2.0 user and group provisioning,
    Git-enabled space commits, and TDN jobs. Authentication is an X-API-Key header key (prefix ens_) or an OAuth 2.0 Resource
    Owner Password Credentials bearer token issued by POST /auth/token. Responses use a consistent {code, message, description}
    error envelope; rate-limited endpoints return X-Rate-Limit-* headers and 429 on exhaustion.
  humanURL: https://manageexternalapi.docs.apiary.io/
  baseURL: https://manage-api.ensighten.com
  tags:
  - Tag Management
  - Deployments
  - SCIM
  - Provisioning
  - Data Governance
  properties:
  - type: OpenAPI
    url: openapi/ensighten-manage-api-openapi.yml
  - type: APIBlueprint
    url: openapi/_original/ensighten-manage-api-apiary-blueprint.json
  - type: Documentation
    url: https://manageexternalapi.docs.apiary.io/
  - type: APIReference
    url: https://manageexternalapi.docs.apiary.io/
  - type: Authentication
    url: authentication/ensighten-authentication.yml
  - type: ErrorCatalog
    url: errors/ensighten-problem-types.yml
  - type: RateLimits
    url: rate-limits/ensighten-rate-limits.yml
  - type: Conventions
    url: conventions/ensighten-conventions.yml
  - type: DataModel
    url: data-model/ensighten-data-model.yml
  - type: Overlay
    url: overlays/ensighten-manage-api-overlay.yaml
  - type: Sandbox
    url: sandbox/ensighten-sandbox.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://cheq.ai/ensighten/
- type: Login
  url: https://manage.ensighten.com/
- type: Support
  url: https://help.ensighten.com/hc/en-us
- type: HelpCenter
  url: https://help.ensighten.com/hc/en-us
- type: Blog
  url: https://cheq.ai/blog/
- type: TermsOfService
  url: https://cheq.ai/cheq-terms-of-service/
- type: PrivacyPolicy
  url: https://cheq.ai/website-privacy-policy/
- type: TrustCenter
  url: https://cheq.ai/trust/
- type: Compliance
  url: https://cheq.ai/trust/
- type: TrustCenter
  name: Ensighten Trust Center (artifact)
  url: security/ensighten-trust-center.yml
- type: DomainSecurity
  url: security/ensighten-domain-security.yml
- type: Documentation
  name: Ensighten Manage API reference
  url: https://manageexternalapi.docs.apiary.io/
- type: APIReference
  url: https://manageexternalapi.docs.apiary.io/
- type: GettingStarted
  url: https://help.ensighten.com/hc/en-us/sections/22957479812369
- type: GitHubOrganization
  url: https://github.com/Ensighten
- type: Packages
  url: packages/ensighten-packages.yml
- type: SDKs
  name: First-party npm packages (React Native bridges to the native mobile SDKs)
  url: packages/ensighten-packages.yml
- type: Conformance
  url: conformance/ensighten-conformance.yml
- type: Lifecycle
  url: lifecycle/ensighten-lifecycle.yml
- type: Deprecation
  name: Bootstrap Version Support Policy (V1-V8 deprecated)
  url: lifecycle/ensighten-lifecycle.yml
- type: Plans
  url: plans/ensighten-plans-pricing.yml
- type: ChangeLog
  url: changelog/ensighten-changelog.yml
- type: LLMsTxt
  url: llms/ensighten-llms.txt
- type: AgentSkill
  url: skills/_index.yml
- type: DataModel
  url: data-model/ensighten-data-model.yml
x-enrichment:
  date: '2026-08-13'
  status: enriched
  artifacts_added: 21
  pass: local-v1
  note: Overturned the prior "no public REST API" finding. STEP 0b contract discovery located the Ensighten Manage API as
    an API Blueprint at https://jsapi.apiary.io/apis/manageexternalapi/blueprint. Ownership proven from the document itself
    (owner "Ensighten", urls.production https://manage-api.ensighten.com/, description "the REST Manage API that can be used
    by Ensighten Manage customers") and confirmed by a live 401 from manage-api.ensighten.com carrying the documented error
    envelope.
x-enrichment-not-emitted:
  note: Pointers deliberately WITHHELD because the underlying surface does not exist. Recorded so a later pass does not re-litigate
    them.
  MCPServer: mcp/ensighten-mcp.yml is a DERIVED candidate with deployment.mode none. No server exists (MCP registry 0 results,
    no npm package, no repo), so no MCPServer pointer is emitted.
  WellKnown: Every /.well-known/ path missed on every host. www.ensighten.com and manage.ensighten.com return HTTP 200 with
    an HTML shell for every path — a soft-200 false positive, recorded as a miss in well-known/ensighten-well-known.yml.
  SecurityTxt: No security.txt is served on any host.
  AgentCard: No agent card at either well-known path on any host.
  Security: No vulnerability disclosure policy, security.txt Policy field, or bug bounty program was found.
  Idempotency: The contract documents no idempotency support of any kind — no Idempotency-Key header and no de-duplication
    window.
  Webhooks: No webhook, callback or event surface exists; async work is polled.
  StatusPage: status.ensighten.com does not resolve; status.cheq.ai returns 403.
  Pricing: cheq.ai/pricing/ returns 404; enterprise contact-sales only.
  Postman: No public Postman collection or workspace was found.