# JupiterOne

**Canonical:** https://apis.io/providers/jupiterone/  
**Website:** https://www.jupiterone.com/  
**APIs profiled:** 1

JupiterOne is a cyber asset attack surface management (CAASM) and security asset intelligence platform that maps an organization's entire digital environment — cloud resources, devices, users, code repositories, findings, and the relationships between them — into a single queryable graph. Its public GraphQL API and the J1QL query language let teams query the graph, create and mutate entities and relationships, ingest data through sync jobs, run alert rules with webhook/SNS/SQS/Slack/Jira actions, manage IAM and questions, and automate compliance evidence collection. JupiterOne was founded in 2018 and is headquartered in Morrisville, North Carolina.

## Kin Score — 54.2 / 100 (developing)

Scored 2026-08-30 under rubric 0.17.2. Trend: flat (+0.0 from 54.2).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 42.7 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 84.2 |
| Developer Ergonomics | 66.7 |
| Commercial Clarity | 47.4 |
| Access Clarity | 47.4 |

## Agent readiness — 25.8 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **JupiterOne GraphQL API** — JupiterOne's public GraphQL API for querying the security asset graph with J1QL, managing entities and relationships, running alert rules, ingesting data via sync jobs, and admi...

## MCP servers (1)

- **JupiterOne MCP Server** — Official Model Context Protocol server for JupiterOne. Exposes JupiterOne account rules and rule details to MCP-compatible agents and clients.

## Security (4)

- **Jupiterone Authentication** — http · 2 schemes
- **Jupiterone Domain Security** — TLSv1.3 · DMARC
- **Jupiterone Vulnerability Disclosure** — contact published
- **Jupiterone Trust Center** — SOC 2 Type 2, ISO 27001, CSA STAR, PCI DSS

## Tags

Company, Security, CAASM, Cyber Asset Management, Attack Surface Management, Cloud Security, Graph, GraphQL, Compliance, Asset Intelligence

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/jupiterone/). Scores are computed from the provider's own public artifacts under a published rubric.
