# MirrorTab

**Canonical:** https://apis.io/providers/mirrortab/  
**Website:** https://www.mirrortab.com  
**APIs profiled:** 1

MirrorTab is a cybersecurity company that stops automated attacks against web applications and APIs by serving the application through an isolated, server-side rendered browser session so the DOM, code, and data are never exposed to the end browser. Rather than detecting bots, it removes the surface they operate on, blocking credential stuffing, agentic-AI automation, man-in-the-browser attacks, malicious extensions, XSS, formjacking, clickjacking, and CSRF without endpoint agents or application code changes. MirrorTab is edge-driven and integrates alongside existing CDNs, WAFs, and fraud platforms. Founded by the CTO and co-founder of Honey (acquired by PayPal), the company also publishes a public v1 REST API to programmatically create, list, and remove MirrorTab browser sessions.

## Kin Score — 35.9 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 35.9).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 57.3 |
| Governance | 16.7 |
| Contract Governance | 16.7 |
| Operational Transparency | 2.6 |
| Developer Ergonomics | 30.4 |
| Commercial Clarity | 27.6 |
| Access Clarity | 27.6 |

## Agent readiness — 27.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **MirrorTab Sessions API** — Create, list, and remove MirrorTab browser sessions.

## MCP servers (1)

- **MirrorTab MCP Server**

## Agentic access (1)

- **Mirrortab Agentic Access** — 3 operations · 3 acting

## Security (2)

- **Mirrortab Authentication** — apiKey · 1 scheme
- **Mirrortab Domain Security** — TLSv1.3 · HSTS · DMARC

## Tags

Company, Enterprise, Security, Cybersecurity, Bot Mitigation, Fraud Prevention, Browser Isolation, Anti-Automation

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/mirrortab/). Scores are computed from the provider's own public artifacts under a published rubric.
