# Infra

**Canonical:** https://apis.io/providers/infra/  
**Website:** https://infrahq.com  
**APIs profiled:** 1

Infra is open-source authentication and access management for infrastructure. It grants short-lived, identity-based access to Kubernetes clusters, servers, and databases by connecting an organization's OIDC identity providers (Okta, Google, Azure AD, and others) to fine-grained grants on destination resources. Users and groups receive least-privilege roles, access keys are issued for CI/CD and API automation, and the `infra` CLI lets engineers list and switch into destinations. The project was originally added to the API Evangelist network as an 8vc portfolio lead; the hosted service at api.infrahq.com has since wound down (infrahq.com now redirects to the GitHub repository), but the source, OpenAPI spec, CLI, and Go client remain available under the Elastic License 2.0 (core) and MIT (SDK and connectors). Final release: v0.21.0.

## Kin Score — 35.2 / 100 (thin)

Scored 2026-08-30 under rubric 0.17.2. Trend: flat (+1.1 from 34.1).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 46.9 |
| Governance | 4.5 |
| Contract Governance | 4.5 |
| Operational Transparency | 18.4 |
| Developer Ergonomics | 56.5 |
| Commercial Clarity | 0.0 |
| Access Clarity | 0.0 |

## Agent readiness — 24.6 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (8)

- **Infra Authentication API** — The Authentication API from Infra — 9 operation(s) for authentication.
- **Infra Destinations API** — The Destinations API from Infra — 3 operation(s) for destinations.
- **Infra Grants API** — The Grants API from Infra — 2 operation(s) for grants.
- **Infra Groups API** — The Groups API from Infra — 3 operation(s) for groups.
- **Infra Organizations API** — The Organizations API from Infra — 3 operation(s) for organizations.
- **Infra Providers API** — The Providers API from Infra — 2 operation(s) for providers.
- **Infra Settings API** — The Settings API from Infra — 2 operation(s) for settings.
- **Infra Users API** — The Users API from Infra — 4 operation(s) for users.

## MCP servers (1)

- **Infra MCP Server**

## Security (2)

- **Infra Authentication** — http-bearer · 4 schemes
- **Infra Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC

## Tags

Company, Identity, Access Management, Authentication, Authorization, Infrastructure, Kubernetes, OIDC, Security, Open-Source

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/infra/). Scores are computed from the provider's own public artifacts under a published rubric.
