# Kubescape

**Canonical:** https://apis.io/providers/kubescape/  
**Website:** https://kubescape.io  
**APIs profiled:** 7

Kubescape is an open-source (Apache 2.0) Kubernetes security platform and CNCF incubating project, originally contributed by ARMO. It provides risk analysis, security and compliance posture scanning, misconfiguration detection, image and runtime vulnerability scanning, and eBPF-based runtime threat detection across the IDE, CI/CD pipelines, and live clusters. The core Kubescape is a CLI and an in-cluster Operator whose components expose OpenAPI/Swagger-documented HTTP APIs in-cluster (there is no single hosted public REST endpoint for the open-source tool). ARMO Platform is the commercial multi-cluster, multi-cloud SaaS built on Kubescape and exposes a documented hosted Customer API (base https://api.armosec.io) for posture, compliance, vulnerabilities, runtime incidents, attack paths, network policies, and registry/repository scanning, authenticated with an X-API-KEY access key.

## Kin Score — 37.8 / 100 (thin)

Scored 2026-08-25 under rubric 0.14.0. Trend: flat (+0.0 from 37.8).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 53.1 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 34.2 |
| Developer Ergonomics | 23.8 |
| Commercial Clarity | 39.5 |
| Access Clarity | 39.5 |

## Agent readiness — 19.8 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (7)

- **Kubescape In-Cluster Component API (Open Source)** — The open-source Kubescape Operator's in-cluster components (storage, kubevuln, gateway, operator, node-agent) each expose an OpenAPI/Swagger-documented HTTP API reachable inside...
- **Kubescape Access Keys API** — Agent access keys and exception policies.
- **Kubescape Network Policies API** — Generated NetworkPolicies and seccomp profiles.
- **Kubescape Posture & Compliance API** — Framework, control, and resource posture results.
- **Kubescape Registry & Repository API** — Registry scans and Git repository posture.
- **Kubescape Runtime Security API** — Runtime incidents, attack chains, and security risks.
- **Kubescape Vulnerabilities API** — Image and workload vulnerability scanning and results.

## Agentic access (1)

- **Kubescape Agentic Access** — 23 operations · 18 acting · 4 human-in-the-loop

## Security (2)

- **Kubescape Authentication** — apiKey · 1 scheme
- **Kubescape Domain Security** — TLSv1.3 · HSTS · DMARC

## Plans (1)

- **Kubescape Plans Pricing**

## Tags

Kubernetes Security, Cloud Native Security, Container Security, DevSecOps, Kubernetes, Vulnerability Scanning, Compliance, Runtime Security, CNCF, Open-Source

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/kubescape/). Scores are computed from the provider's own public artifacts under a published rubric.
