iboss

iboss, Inc. is a Boston-headquartered cybersecurity company founded in 2003 that operates an AI-powered, cloud-native Zero Trust SASE (Secure Access Service Edge) platform used by more than 4,000 enterprise, US federal, state and local government, and K-12 education organizations. The platform consolidates Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), Data Loss Prevention (DLP), Remote Browser Isolation (RBI), SaaS Security Posture Management (SSPM), DNS security, SD-WAN and AI chat monitoring into a single containerized service in which each customer receives dedicated gateway containers rather than shared infrastructure. iboss is FedRAMP and StateRAMP authorized and holds SOC 2 Type II, FIPS 140-2, HIPAA, CJIS, FERPA and GDPR alignment. Platform administration and reporting run over an authenticated REST surface at api.ibosscloud.com/ibcloud/web, which third parties including Datadog, Axonius, Google Security Operations and D3 Security integrate against; iboss publishes no public OpenAPI definition, developer portal or API reference, and its documentation host redirects to a sign-in-gated GitBook space.

iboss publishes 1 API on the APIs.io network. Tagged areas include Company, Security, Cybersecurity, Zero Trust, and SASE.

iboss’ developer surface includes support, engineering blog, pricing, authentication, and 18 more developer resources.

23.4/100 emerging ▬ flat Agent 5/100 human only Full breakdown ↓
scored 2026-08-25 · rubric v0.14.0
1 APIs
CompanySecurityCybersecurityZero TrustSASESecure Web GatewayCASBZTNAData Loss PreventionNetwork SecurityCloud SecurityCompliance

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-25 · rubric v0.14.0
Composite quality — 23.4/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 2.4 / 20
Access Clarity 9.2 / 20
Operational Transparency 2.1 / 13
Contract Governance 2.2 / 12
Discoverability 7.6 / 10
Agent readiness — 5/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 10
Documented Reversibility 0 / 6
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Delegated User Identity 0 / 6
Protected Resource Metadata 0 / 5
Registration Without a Human 0 / 6
Agentic Commerce Surface 0 / 5
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/iboss: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

iboss Zero Trust SSE Platform API

Authenticated REST administration and reporting surface for the iboss Zero Trust SASE/SSE cloud platform, served under the /ibcloud/web path on the iboss cloud gateway hosts. Pr...

Pricing Plans 1

Published pricing tiers and plan structures.

Iboss Plans Pricing

3 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Iboss Rate Limits

0 limits

RATE LIMITS

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Iboss Authentication

2 schemes

SECURITY

Iboss Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Iboss Trust Center

SOC 1 Type II, SOC 2 Type II, ISO 27001, ISO 9001, FedRAMP Authorized, StateRAMP Authorized, CJIS, CSA STAR Level 1, CSA STAR Level 2, Cyber Essentials, CMMC 2.0, FIPS 140-2, HI...

SECURITY

Resources

Get Started 1

Portal, sign-up, and the first successful call

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 3

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 4

Status, limits, changes, and where to get help

Commercial 4

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: iboss
name: iboss
description: iboss, Inc. is a Boston-headquartered cybersecurity company founded in 2003 that operates an AI-powered, cloud-native
  Zero Trust SASE (Secure Access Service Edge) platform used by more than 4,000 enterprise, US federal, state and local government,
  and K-12 education organizations. The platform consolidates Secure Web Gateway (SWG), Cloud Access Security Broker (CASB),
  Zero Trust Network Access (ZTNA), Data Loss Prevention (DLP), Remote Browser Isolation (RBI), SaaS Security Posture Management
  (SSPM), DNS security, SD-WAN and AI chat monitoring into a single containerized service in which each customer receives
  dedicated gateway containers rather than shared infrastructure. iboss is FedRAMP and StateRAMP authorized and holds SOC
  2 Type II, FIPS 140-2, HIPAA, CJIS, FERPA and GDPR alignment. Platform administration and reporting run over an authenticated
  REST surface at api.ibosscloud.com/ibcloud/web, which third parties including Datadog, Axonius, Google Security Operations
  and D3 Security integrate against; iboss publishes no public OpenAPI definition, developer portal or API reference, and
  its documentation host redirects to a sign-in-gated GitBook space.
image: https://www.iboss.com/favicon.ico
url: https://raw.githubusercontent.com/api-evangelist/iboss/refs/heads/main/apis.yml
x-type: company
x-source: harvest:secondary-market
specificationVersion: '0.20'
created: '2026-08-22'
modified: '2026-08-22'
tags:
- Company
- Security
- Cybersecurity
- Zero Trust
- SASE
- Secure Web Gateway
- CASB
- ZTNA
- Data Loss Prevention
- Network Security
- Cloud Security
- Compliance
apis:
- name: iboss Zero Trust SSE Platform API
  description: Authenticated REST administration and reporting surface for the iboss Zero Trust SASE/SSE cloud platform, served
    under the /ibcloud/web path on the iboss cloud gateway hosts. Probed anonymously it answers HTTP 401 and issues XSRF-TOKEN
    and JSESSIONID cookies scoped to /ibcloud, confirming a live authenticated API rather than a static site. iboss publishes
    no public OpenAPI/Swagger definition and no public API reference; access requires an active iboss Zero Trust SSE account
    with administrative privileges. Recorded here from probe evidence only — no contract was found, and none has been authored
    on the provider's behalf.
  humanURL: https://www.iboss.com/support
  baseURL: https://api.ibosscloud.com/ibcloud/web
  tags:
  - Security
  - Zero Trust
  - SASE
  - Administration
  properties:
  - type: Authentication
    url: authentication/iboss-authentication.yml
  - type: Login
    url: https://accounts.iboss.com/ibossauth/index.html
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: DomainSecurity
  url: security/iboss-domain-security.yml
- type: Website
  url: https://www.iboss.com
- type: Support
  url: https://www.iboss.com/support
- type: HelpCenter
  url: https://support.ibosscloud.com/hc/en-us
- type: Blog
  url: https://www.iboss.com/blog
- type: BlogRSS
  url: https://www.iboss.com/rss.xml
- type: Pricing
  url: https://www.iboss.com/pricing
- type: Login
  url: https://accounts.iboss.com/ibossauth/index.html
- type: TermsOfService
  url: https://www.iboss.com/terms
- type: PrivacyPolicy
  url: https://www.iboss.com/privacy-policy
- type: StatusPage
  url: https://status.iboss.com/ibcloud/app/cloudStatus.html
- type: Compliance
  url: https://www.iboss.com/compliance
- type: LLMsTxt
  url: llms/iboss-llms.txt
- type: WellKnown
  url: well-known/iboss-well-known.yml
- type: Authentication
  url: authentication/iboss-authentication.yml
- type: Conformance
  url: conformance/iboss-conformance.yml
- type: Lifecycle
  url: lifecycle/iboss-lifecycle.yml
- type: Conventions
  url: conventions/iboss-conventions.yml
- type: RateLimits
  url: rate-limits/iboss-rate-limits.yml
- type: Plans
  url: plans/iboss-plans-pricing.yml
- type: TrustCenter
  url: security/iboss-trust-center.yml
- type: Packages
  url: packages/iboss-packages.yml
x-enrichment:
  date: '2026-08-22'
  status: enriched
  artifacts_added: 13
  pass: local-v1
x-coverage:
  state: gated
  reason: customer-only-docs
  detail: 'iboss runs a live platform API — api.ibosscloud.com/ibcloud/web answers HTTP 401 with XSRF-TOKEN and JSESSIONID
    cookies and a "Server: iboss cloud" header — but publishes no contract for it: docs.iboss.com 307-redirects to a sign-in-gated
    app.gitbook.com space rather than a published docs site, and the 344-URL sitemap contains no /api, /developer or /reference
    route.'
  evidence:
  - url: https://api.ibosscloud.com/ibcloud/web/users
    status: 401
  - url: https://docs.iboss.com
    status: 307
  - url: https://api.ibosscloud.com/openapi.json
    status: 404
  - url: https://www.iboss.com/llms.txt
    status: 200
  checked: '2026-08-22'

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/iboss"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/iboss/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/iboss/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.