# Koi Security

**Canonical:** https://apis.io/providers/koi-security/  
**Website:** https://www.koi.ai/  
**APIs profiled:** 1

Koi (formerly Koi Security, now operating as koi.ai) is an endpoint security platform built for non-binary software — browser extensions, IDE and editor extensions, open-source packages, MCP servers, AI models, AI agents, and containers — the install surface that traditional EDR and MDM tooling was never designed to govern. The platform ships three products: Koi Endpoint (agentless discovery and governance of every binary and non-binary install across macOS, Windows, and Linux), Koi Wings (continuous risk evaluation of code, behavior, publisher ownership changes, and update channels), and Koi Gateway (a network-based gate in front of marketplaces, app stores, and registries). Koi is widely known for the security research it publishes on software supply-chain attacks including GlassWorm, Shai-Hulud, PhantomRaven, GreedyBear, and the first malicious MCP server found in the wild. Koi also operates ExtensionTotal, a free community risk-scoring service for Visual Studio Code extensions that exposes a public HTTP API and a first-party VS Code extension. Koi raised $48M and has been acquired by Palo Alto Networks.

## Kin Score — 37.7 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 37.7).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 61.5 |
| Governance | 16.7 |
| Contract Governance | 16.7 |
| Operational Transparency | 2.6 |
| Developer Ergonomics | 28.0 |
| Commercial Clarity | 34.2 |
| Access Clarity | 34.2 |

## Agent readiness — 37.8 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | verified |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **Koi Security Risk API** — Extension risk assessment.

## MCP servers (1)

- **Koi Security MCP Server**

## Security (2)

- **Koi Security Authentication** — apiKey · 1 scheme
- **Koi Security Domain Security** — TLSv1.3 · HSTS · DMARC

## Tags

Company, Security, Endpoint Security, Supply Chain Security, Browser Extensions, Developer Tools, Threat Intelligence, MCP Security, Risk Scoring

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/koi-security/). Scores are computed from the provider's own public artifacts under a published rubric.
