# Kondukto

**Canonical:** https://apis.io/providers/kondukto/  
**Website:** https://kondukto.io  
**APIs profiled:** 11

Kondukto — now shipped as Invicti ASPM following Invicti Security's acquisition of the company — is an Application Security Posture Management platform that centralizes and automates the AppSec vulnerability management lifecycle. It ingests, deduplicates and correlates findings from more than eighty security scanners across SAST, DAST, SCA, container, infrastructure and pentest testing, enriches them with CWE, CVSS, EPSS, CISA KEV, EUVD threat intelligence and VEX exploitability data, and routes them to owning teams through Jira, GitLab, ServiceNow and webhook issue managers. Kondukto publishes a documented REST API v2 covering projects, products, teams, labels, scans and vulnerabilities, an open-source Go command-line client (KDT) that drives the same API from CI/CD pipelines, and a webhook surface for both outbound platform events and customer-hosted issue managers. The platform is deployed per customer, so the API host is deployment-specific.

## Kin Score — 66.5 / 100 (exemplar)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 66.5).

| Facet | Score |
|---|---|
| Discoverability | 92.6 |
| Contract Quality | 70.6 |
| Governance | 11.5 |
| Operational Transparency | 55.3 |
| Developer Ergonomics | 73.4 |
| Commercial Clarity | 81.6 |

## Agent readiness — 49.3 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | derived |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | verified |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Paid · Self-serve signup — onboarding: self-serve, pricing: paid, trial: no (confidence: high).

## APIs (11)

- **Kondukto Authorization Managers API** — The Authorization Managers API from Kondukto — 1 operation(s) for authorization managers.
- **Kondukto Events API** — The Events API from Kondukto — 1 operation(s) for events.
- **Kondukto Health API** — The Health API from Kondukto — 1 operation(s) for health.
- **Kondukto Labels API** — The Labels API from Kondukto — 3 operation(s) for labels.
- **Kondukto Products API** — The Products API from Kondukto — 2 operation(s) for products.
- **Kondukto Projects API** — The Projects API from Kondukto — 7 operation(s) for projects.
- **Kondukto Scanners API** — The Scanners API from Kondukto — 1 operation(s) for scanners.
- **Kondukto Scans API** — The Scans API from Kondukto — 10 operation(s) for scans.
- **Kondukto Teams API** — The Teams API from Kondukto — 5 operation(s) for teams.
- **Kondukto Users API** — The Users API from Kondukto — 2 operation(s) for users.
- **Kondukto Vulnerabilities API** — The Vulnerabilities API from Kondukto — 9 operation(s) for vulnerabilities.

## MCP servers (1)

- **kondukto-mcp.yml**

## Agentic access (1)

- **Kondukto Agentic Access** — 51 operations · 21 acting

## Security (4)

- **Kondukto Authentication** — apiKey · 1 scheme
- **Kondukto Domain Security** — TLSv1.3 · HSTS · DMARC
- **Kondukto Vulnerability Disclosure** — security.txt · contact published
- **Kondukto Trust Center** — SOC 2 Type 2, ISO 27001:2025

## Plans (1)

- **Kondukto Plans**

## Tags

Company, Application Security, ASPM, Vulnerability Management, DevSecOps, Security Orchestration, SAST, DAST, SCA, Software Composition Analysis, Container Security, SBOM, Security Testing, CI/CD, Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/kondukto/). Scores are computed from the provider's own public artifacts under a published rubric.
