# Jit (fka Cbrix)

**Canonical:** https://apis.io/providers/jit-fka-cbrix/  
**Website:** https://www.jit.io/  
**APIs profiled:** 1

Jit is an AI-powered Application Security Posture Management (ASPM) and DevSecOps orchestration platform for modern engineering teams. It unifies open-source and proprietary security scanners (Semgrep, Prowler, KICS, OWASP ZAP, Trivy, npm-audit, Wiz and more) behind one control plane, correlates their signals, prioritizes findings by policy, and drives fix-focused remediation directly in the developer workflow. Jit exposes a REST API at api.jit.io with OAuth2 client-credentials (JWT bearer) authentication and a fine-grained jit.* permission model covering findings, artifacts, teams, plans, policies, workflows, integrations, and scan execution. Formerly Cbrix, Jit is backed by Insight Partners and integrates across GitHub, GitLab, Bitbucket, Azure DevOps, AWS, GCP, and Azure.

## Kin Score — 25.2 / 100 (emerging)

Scored 2026-08-21 under rubric 0.12.0. Trend: flat (+0.0 from 25.2).

| Facet | Score |
|---|---|
| Discoverability | 87.0 |
| Contract Quality | 0.0 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 2.6 |
| Developer Ergonomics | 33.3 |
| Commercial Clarity | 36.8 |
| Access Clarity | 36.8 |

## Agent readiness — 8.5 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **Jit API** — Jit REST API for programmatic access to security findings, artifacts (SBOM, scan results), teams, plans, policies, workflows, integrations, billing metrics, and on-demand scan e...

## MCP servers (1)

- **Jit (fka Cbrix) MCP Server**

## Security (3)

- **Jit Fka Cbrix Authentication** — oauth2/http · 2 schemes
- **Jit Fka Cbrix Domain Security** — TLSv1.3 · HSTS · DMARC
- **Jit Fka Cbrix Trust Center** — SOC 2 Type 2

## Tags

Company, Cybersecurity, Application Security, DevSecOps, ASPM, Security, Vulnerability Management

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/jit-fka-cbrix/). Scores are computed from the provider's own public artifacts under a published rubric.
