# Finite State

**Canonical:** https://apis.io/providers/finite-state/  
**Website:** https://finitestate.io  
**APIs profiled:** 3

Finite State is a product security platform for connected-device and embedded software manufacturers. It performs binary and firmware composition analysis, source-code scanning and third-party scan ingestion, SBOM generation and lifecycle management (CycloneDX and SPDX), VEX, EPSS- and reachability-based vulnerability prioritization, license-policy enforcement, and evidence-backed compliance reporting for regimes such as the EU Cyber Resilience Act, FDA 524B, ISO 21434 and IEC 62443. Programmatic access is offered through a token-authenticated REST API on the platform host, a legacy GraphQL API with an official Python SDK, the fs-cli command-line tool, and CI/CD integrations for GitHub Actions, Jenkins and Azure DevOps. Finite State also publishes an anonymous, read-only A2A JSON-RPC content API described by an agent card at its canonical well-known path.

## Kin Score — 39.3 / 100 (thin)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 39.3).

| Facet | Score |
|---|---|
| Discoverability | 92.6 |
| Contract Quality | 0.0 |
| Governance | 12.5 |
| Operational Transparency | 44.7 |
| Developer Ergonomics | 69.0 |
| Commercial Clarity | 44.7 |

## Agent readiness — 27.3 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| MCP Server | derived |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | yes |
| Consent Identity | no |
| Agent Card | conformant |
| Dry Run Mode | no |

## APIs (3)

- **Finite State Platform API** — Token-authenticated REST API for the Finite State platform, served under /api/public/v0 on the platform host. Interactive Swagger documentation is published per organization at ...
- **Finite State A2A Content API** — Public, anonymous, read-only JSON-RPC 2.0 API exposing Finite State's published content: blog posts, resources, videos, events, podcasts and press articles. Four allowlisted met...
- **Finite State GraphQL API** — GraphQL API historically documented at https://platform.finitestate.io/api/v1/graphql and still the transport used by the official Python SDK, which authenticates via a client-c...

## MCP servers (1)

- **finite-state-mcp.yml**

## Security (2)

- **Finite State Authentication** — apiKey/http/oauth2 · 4 schemes
- **Finite State Domain Security** — TLSv1.3 · HSTS · DMARC

## Tags

Product Security, Software Supply Chain Security, SBOM, Firmware Analysis, Vulnerability Management, Binary Analysis, Connected Devices, Compliance, Cybersecurity, IoT

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/finite-state/). Scores are computed from the provider's own public artifacts under a published rubric.
