# LevelBlue

**Canonical:** https://apis.io/providers/levelblue/  
**Website:** https://docs.levelblue.com/documentation  
**APIs profiled:** 4

LevelBlue is a pure-play managed security service provider (MSSP), formed from AT&T Cybersecurity and the AlienVault platform it acquired, delivering managed detection and response, managed cloud and network security, incident readiness and response, cyber advisory, exposure management and email security, backed by SpiderLabs threat intelligence. Its developer surface is the USM Anywhere v2.0 REST API — a per-tenant, OAuth 2.0 client-credentials API over alarms and normalized security events, with HAL pagination and a webhook connector for pushing third-party events into the platform — alongside the LevelBlue Open Threat Exchange (OTX) DirectConnect API for community threat intelligence.

## Kin Score — 52.2 / 100 (developing)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 52.2).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 66.8 |
| Governance | 11.5 |
| Operational Transparency | 55.3 |
| Developer Ergonomics | 62.5 |
| Commercial Clarity | 31.6 |

## Agent readiness — 47.1 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| MCP Server | derived |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | verified |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (4)

- **LevelBlue Open Threat Exchange (OTX) DirectConnect API** — The OTX DirectConnect API provides programmatic access to the LevelBlue Open Threat Exchange, an open community threat-intelligence platform. It exposes indicators (IPs, domains...
- **LevelBlue Alarms API** — Endpoints for managing and searching alarm messages.
- **LevelBlue Events API** — Endpoints for managing and searching events.
- **LevelBlue OAuth API** — Endpoint for OAuth 2.0 functionality.

## MCP servers (1)

- **levelblue-mcp.yml**

## Security (3)

- **Levelblue Authentication** — http · 2 schemes
- **Levelblue Domain Security** — TLSv1.3 · HSTS · DMARC
- **Levelblue Vulnerability Disclosure** — Hackerone · security.txt · contact published

## Tags

Company, Enterprise, Cybersecurity, Security, Threat Intelligence, Managed Security, SIEM, Threat Detection, Incident Response, Compliance

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/levelblue/). Scores are computed from the provider's own public artifacts under a published rubric.
