Falco
Falco is a cloud-native runtime security tool that detects unexpected application behavior and alerts on threats at runtime using eBPF. It is a CNCF graduated project that continuously monitors Linux kernel syscalls and compares them against configurable security rules to detect intrusions, privilege escalation, and other suspicious behaviors.
Falco publishes 3 APIs on the APIs.io network: Health API, Rules API, and Version API. Tagged areas include Cloud Native, eBPF, Runtime Security, Security, and Threat Detection.
The Falco catalog on APIs.io includes 1 JSON-LD context and 1 Spectral governance ruleset.
Falco’s developer surface includes documentation, engineering blog, getting-started guide, changelog, and 8 more developer resources.
Kin Score
APIs 5
Individual APIs this provider publishes, each with its own machine-readable definition.
Falco Plugin API
The Falco Plugin API provides a C ABI interface for developing plugins that extend Falco with new event sources and field extractors. Plugins are shared libraries that implement...
Falco gRPC API
The Falco gRPC API provided a streaming interface for consuming Falco alert outputs and querying version information from a running Falco instance. The embedded gRPC server and ...
Falco Health API
Health check endpoints
Falco Rules API
Rules management endpoints
Falco Version API
Version information
Open Collections 1
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Falco HTTP API
OPEN COLLECTIONPricing Plans 1
Published pricing tiers and plan structures.
Falco Plans Pricing
PLANSRate Limits 1
Documented rate limits and quota policies.
Falco Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Falco Finops
FINOPSSemantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Falco Context
JSON-LDSpectral Rules 1
Spectral governance rulesets for linting and validating these APIs.
Falco API Rules
SPECTRALJSON Schema 2
Standalone JSON Schema definitions for this provider's data models.
Falco Alert Output
JSON SCHEMAFalco Rules File
JSON SCHEMASecurity Posture 1
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 1
Pagination, idempotency, versioning, errors, and events
Build 2
SDKs, sample code, and the tooling you integrate with
Access & Security 1
Authentication, authorization, and security posture
Operate 2
Status, limits, changes, and where to get help
Company 3
The organization behind the API