Home
Providers
Nord Security
Nord Security
Nord Security is a Lithuania-founded digital security and privacy company whose consumer and business portfolio spans NordVPN, NordPass, NordLocker, NordLayer (network access security for business), NordProtect/Coveron, Saily (eSIM) and NordStellar (external threat exposure management). Its developer-facing surface is concentrated in NordStellar, which publishes five OpenAPI-described enterprise APIs — the Enterprise Data (Dark Web) API, Company Risk Scoring API, Cybersec API, Partners API and Platform Integrations API — plus a remote MCP server, sixteen provider-published agent skills, an n8n community node and SIEM integrations (Microsoft Sentinel, CrowdStrike). NordLayer adds SCIM 2.0 user provisioning and a partner/MSP API key surface, while the NordSecurity GitHub organization publishes the NordVPN Linux client together with 43 gRPC/protobuf service definitions covering the daemon, meshnet, fileshare, norduser and telemetry surfaces.
Nord Security publishes 30 APIs on the APIs.io network, including API User Management API, Applications API, AUC API, and 27 more. Tagged areas include Cybersecurity, Threat Intelligence, Dark Web Monitoring, Attack Surface Management, and Breach Intelligence.
Nord Security’s developer surface includes documentation, API reference, getting-started guide, support, engineering blog, pricing, signup flow, and 45 more developer resources.
7 APIs
2 MCP Servers
On this page
Kin Score Standards 1
APIs 35
Open Collections 7
MCP Servers 2
Rate Limits 1
Security Posture 4
Resources 52
apis.yml
32 Operational Transparency
0 Create-or-Update Ergonomics
Composite quality — 54.7/100 · strong
Agent readiness — 44/100 · agent ready
Interfaces this provider implements that became standards by being copied rather than ratified. Each is profiled by the API Commons , and the evidence column says how the claim was established — not that it was made.
prose — states compatibility; nothing published to check it against
Individual APIs this provider publishes, each with its own machine-readable definition.
Remote MCP server that lets any MCP-compatible assistant query the NordStellar platform in natural language. Clients connect through the open-source nordstellar-mcp auth proxy (...
Partner-facing API behind the NordLayer Service Management Portal. API keys are self-issued in the SMP Integrations tab with expiry and one-time visibility, and let MSPs create ...
SCIM-based user provisioning surface used to create users, update user attributes, deactivate users and push groups from Okta and Microsoft Entra ID into NordLayer. The SCIM sec...
Usage-reporting API for NordPass provider/MSP partners, documented in the NordPass help centre. NordPass separately supports SCIM provisioning from Okta and Microsoft Entra ID f...
Unauthenticated JSON API that NordVPN's own clients and the open-source Linux client use to enumerate the server estate — servers, countries, cities, groups and technologies. It...
Endpoints for administering API keys, and web hook settings. These operations enable administrators to list and manage API keys, update webhook configuration.
The Applications API from Nord Security — 1 operation(s) for applications.
The AUC API from Nord Security — 2 operation(s) for auc.
Endpoints for retrieving detailed metadata about breach origins, including databases. These operations provide comprehensive context about database breach incidents, affected pl...
The Company Details API from Nord Security — 4 operation(s) for company details.
Endpoints for comprehensive cookie data monitoring in data breaches, including zero-knowledge search capabilities. These operations enable robust cookie security protection and ...
The Cookies API from Nord Security — 1 operation(s) for cookies.
Endpoints for retrieving detailed metadata about breach origins, including credential lists. These operations provide comprehensive context about credential list breach incident...
Endpoints for comprehensive credit card data monitoring in data breaches, including zero-knowledge search capabilities. These operations enable robust credit card security prote...
The Crypto Addresses API from Nord Security — 1 operation(s) for crypto addresses.
Endpoints for searching scraped content from the dark web
Endpoints for investigating domain exposure in data breaches, including detailed breach information and compromise analysis. These operations support protection against domain h...
Endpoints for comprehensive email address monitoring in data breaches, including detailed breach information, password exposure, and statistical analysis. These operations enabl...
The Events API from Nord Security — 36 operation(s) for events.
The Files API from Nord Security — 8 operation(s) for files.
The Lists API from Nord Security — 3 operation(s) for lists.
Endpoints for retrieving detailed metadata about breach origins, including malware logs. These operations provide comprehensive context about malware logs breach incidents, affe...
The ML Models API from Nord Security — 2 operation(s) for ml models.
Endpoints for comprehensive national identification number data monitoring in data breaches, including zero-knowledge search capabilities. These operations enable robust nationa...
The Partners API from Nord Security — 4 operation(s) for partners.
Endpoints for comprehensive password data monitoring in data breaches, including zero-knowledge search capabilities. These operations enable robust password security protection ...
Endpoints for investigating phone number exposure in data breaches, including detailed breach information and compromise analysis. These operations support protection against SI...
Endpoints for generating OSINT-based profiling reports on email addresses and phone numbers. Reports aggregate data from external intelligence sources, enrich it with internal b...
The Projects API from Nord Security — 6 operation(s) for projects.
The Results API from Nord Security — 8 operation(s) for results.
The Scanning API from Nord Security — 2 operation(s) for scanning.
Endpoints for managing user subscriptions to data breach monitoring services. These operations enable administrators to create, update, and delete subscriptions for email addres...
The URL scanner API from Nord Security — 1 operation(s) for url scanner.
The Urls API from Nord Security — 4 operation(s) for urls.
Utility endpoints for supporting zero-knowledge functionalities, such as retrieving salts. These operations are essential for the proper functioning of zero-knowledge security f...
Scroll for all 35
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Scroll for all 7
Model Context Protocol servers that expose these APIs to AI agents.
Documented rate limits and quota policies.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Get Started 4
Portal, sign-up, and the first successful call
Documentation 3
Reference material describing how the API behaves
Agent Surfaces 5
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 5
Pagination, idempotency, versioning, errors, and events
Build 5
SDKs, sample code, and the tooling you integrate with
Access & Security 8
Authentication, authorization, and security posture
Scroll for all 8
Operate 7
Status, limits, changes, and where to get help
Scroll for all 7
Commercial 4
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 9
Properties that don't map to a standard resource type
Scroll for all 9
Source (apis.yml)
aid: nord-security
name: Nord Security
description: Nord Security is a Lithuania-founded digital security and privacy company whose consumer and business portfolio
spans NordVPN, NordPass, NordLocker, NordLayer (network access security for business), NordProtect/Coveron, Saily (eSIM)
and NordStellar (external threat exposure management). Its developer-facing surface is concentrated in NordStellar, which
publishes five OpenAPI-described enterprise APIs — the Enterprise Data (Dark Web) API, Company Risk Scoring API, Cybersec
API, Partners API and Platform Integrations API — plus a remote MCP server, sixteen provider-published agent skills, an
n8n community node and SIEM integrations (Microsoft Sentinel, CrowdStrike). NordLayer adds SCIM 2.0 user provisioning and
a partner/MSP API key surface, while the NordSecurity GitHub organization publishes the NordVPN Linux client together with
43 gRPC/protobuf service definitions covering the daemon, meshnet, fileshare, norduser and telemetry surfaces.
deliveryModel:
model: open-core
license: GPL-3.0
open_source: true
commercial: true
callable_host: false
label: Open core · an OSS project plus a commercial hosted product
confidence: high
source:
- license
- pricing
generated: '2026-08-28'
method: derived
accessModel:
pricing: unknown
onboarding: unknown
trial: false
try_now: false
public: false
label: Unknown
confidence: low
source:
- authentication
- rate-limits
- security
generated: '2026-09-03'
method: derived
image: https://res.cloudinary.com/nordsec/image/upload/q_auto,f_auto/v1/nord-security-web/global/meta/social-logo.png
url: https://raw.githubusercontent.com/api-evangelist/nord-security/refs/heads/main/apis.yml
x-type: company
x-source: harvest:secondary-market
x-tier: profiled
x-tier-reason: enrichment
specificationVersion: '0.23'
created: '2026-08-01'
modified: '2026-08-01'
tags:
- Cybersecurity
- Threat Intelligence
- Dark Web Monitoring
- Attack Surface Management
- Breach Intelligence
- VPN
- Password Management
- Network Security
- Zero Trust
- Privacy
- MCP
- Agent Skills
- gRPC
- Company
apis:
- name: NordStellar MCP Server
description: Remote MCP server that lets any MCP-compatible assistant query the NordStellar platform in natural language.
Clients connect through the open-source nordstellar-mcp auth proxy (PyPI, run via uvx, or a one-click .mcpb bundle for
Claude Desktop), which performs a browser login and stores session tokens in the OS credential store. The server fronts
NordStellar's GraphQL core and exposes graphql_query, graphql_batch, search_types and get_type_definition. Live tools/list
is auth-gated (HTTP 401 "no bearer token").
humanURL: https://docs.nordstellar.com/platform/mcp
baseURL: https://platform-mcp.nordstellar.com/mcp
tags:
- MCP
- agent-native
- Threat Intelligence
- GraphQL
tags_raw:
- mcp
- agent-native
- threat-intelligence
- graphql
properties:
- type: MCPServer
url: mcp/nord-security-mcp.yml
- type: ToolCrosswalk
url: mcp/nord-security-tool-crosswalk.yml
- type: MCPServer
url: https://platform-mcp.nordstellar.com/mcp
- type: Documentation
url: https://docs.nordstellar.com/platform/mcp/setup
- type: AgentSkill
url: skills/_index.yml
- type: SourceCode
url: https://github.com/NordStellar/nordstellar-mcp
- name: NordLayer Partner / MSP API
description: Partner-facing API behind the NordLayer Service Management Portal. API keys are self-issued in the SMP Integrations
tab with expiry and one-time visibility, and let MSPs create client organizations, retrieve account details and statuses,
and track license usage. The help centre links a "NordLayer MSP API Documentation" PDF for the full specification, but
that published link currently returns 404, so no machine-readable contract is publicly retrievable.
humanURL: https://help.nordlayer.com/docs/api-key-management-for-smp
baseURL: https://api.nordlayer.com/
tags:
- MSP
- Partner API
- Provisioning
- Network Security
tags_raw:
- msp
- partner-api
- provisioning
- network-security
properties:
- type: Documentation
url: https://help.nordlayer.com/docs/api-key-management-for-smp
- type: Authentication
url: authentication/nord-security-authentication.yml
x-evidence:
fetched: '2026-08-01'
base_url_probe:
url: https://api.nordlayer.com/
http_status: 404
content_type: application/json
body: '{"code":404,"message":"Resource not found"}'
note: Host resolves and answers a JSON error envelope; individual endpoint paths are not published outside the partner-gated
MSP API PDF.
spec_link:
url: https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/NordLayer%20MSP%20API%20Documentation.pdf
http_status: 404
note: Linked from help.nordlayer.com/docs/api-key-management-for-smp; asset no longer present.
- name: NordLayer SCIM 2.0 Provisioning
description: SCIM-based user provisioning surface used to create users, update user attributes, deactivate users and push
groups from Okta and Microsoft Entra ID into NordLayer. The SCIM secret token is issued in the NordLayer Control Panel
under Settings > Access management; the endpoint is configured through the identity provider's NordLayer application rather
than published as a standalone base URL.
humanURL: https://help.nordlayer.com/docs/user-provisioning
baseURL: https://api.nordlayer.com/
tags:
- SCIM
- Provisioning
- Identity
- SSO
tags_raw:
- scim
- provisioning
- identity
- sso
properties:
- type: Documentation
url: https://help.nordlayer.com/docs/user-provisioning
- type: Conformance
url: conformance/nord-security-conformance.yml
- name: NordPass Provider API
description: Usage-reporting API for NordPass provider/MSP partners, documented in the NordPass help centre. NordPass separately
supports SCIM provisioning from Okta and Microsoft Entra ID for NordPass Business. The provider API reference sits behind
a bot-protected help centre and no machine-readable contract is published.
humanURL: https://support.nordpass.com/hc/en-us/articles/23164869782801-Provider-API-for-Usage-Reporting
baseURL: https://api.nordpass.com/
tags:
- MSP
- usage-reporting
- Password Management
- SCIM
tags_raw:
- msp
- usage-reporting
- password-management
- scim
properties:
- type: Documentation
url: https://support.nordpass.com/hc/en-us/articles/23164869782801-Provider-API-for-Usage-Reporting
x-evidence:
fetched: '2026-08-01'
base_url_probe:
url: https://api.nordpass.com/
http_status: 403
content_type: application/json
body: '{"status":403,"title":"Access Forbidden","type":"https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/403"}'
note: Host resolves and answers a problem-shaped JSON envelope; endpoint paths are not published.
- name: NordVPN Public Server API
description: Unauthenticated JSON API that NordVPN's own clients and the open-source Linux client use to enumerate the server
estate — servers, countries, cities, groups and technologies. It is publicly reachable and widely consumed, but Nord Security
publishes no developer documentation, no OpenAPI and no terms for it, so it should be treated as an internal client API
rather than a supported product API.
humanURL: https://github.com/NordSecurity/nordvpn-linux
baseURL: https://api.nordvpn.com/v1
tags:
- VPN
- server-directory
- Undocumented
tags_raw:
- vpn
- server-directory
- undocumented
properties:
- type: SourceCode
url: https://github.com/NordSecurity/nordvpn-linux
x-evidence:
fetched: '2026-08-01'
probes:
- url: https://api.nordvpn.com/v1/servers/countries
http_status: 200
content_type: application/json
- url: https://api.nordvpn.com/v1/technologies
http_status: 200
content_type: application/json
- url: https://api.nordvpn.com/openapi.json
http_status: 403
note: No OpenAPI published; host bot-protects non-client paths.
- aid: nord-security:nord-security-api-user-management-api
name: Nord Security API User Management API
description: 'Endpoints for administering API keys, and web hook settings.
These operations enable administrators to list and manage API keys, update webhook configuration.'
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- API User Management
properties:
- type: OpenAPI
url: openapi/nord-security-api-user-management-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-applications-api
name: Nord Security Applications API
description: The Applications API from Nord Security — 1 operation(s) for applications.
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- Application
tags_raw:
- Applications
properties:
- type: OpenAPI
url: openapi/nord-security-applications-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-auc-api
name: Nord Security AUC API
description: The AUC API from Nord Security — 2 operation(s) for auc.
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- AUC
properties:
- type: OpenAPI
url: openapi/nord-security-auc-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-breached-databases-api
name: Nord Security Breached Databases API
description: 'Endpoints for retrieving detailed metadata about breach origins, including databases.
These operations provide comprehensive context about database breach incidents, affected platforms, and exposure scope
to support your security investigations.'
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- Breached Databases
properties:
- type: OpenAPI
url: openapi/nord-security-breached-databases-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-company-details-api
name: Nord Security Company Details API
description: The Company Details API from Nord Security — 4 operation(s) for company details.
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- Company Details
properties:
- type: OpenAPI
url: openapi/nord-security-company-details-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-cookie-intelligence-api
name: Nord Security Cookie Intelligence API
description: 'Endpoints for comprehensive cookie data monitoring in data breaches, including zero-knowledge search capabilities.
These operations enable robust cookie security protection and exposure assessment.'
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- Cookie Intelligence
properties:
- type: OpenAPI
url: openapi/nord-security-cookie-intelligence-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-cookies-api
name: Nord Security Cookies API
description: The Cookies API from Nord Security — 1 operation(s) for cookies.
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- Cookies
properties:
- type: OpenAPI
url: openapi/nord-security-cookies-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-credential-lists-api
name: Nord Security Credential Lists API
description: 'Endpoints for retrieving detailed metadata about breach origins, including credential lists.
These operations provide comprehensive context about credential list breach incidents, affected platforms, and exposure
scope to support your security investigations.'
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- Credential Lists
properties:
- type: OpenAPI
url: openapi/nord-security-credential-lists-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-credit-card-intelligence-api
name: Nord Security Credit Card Intelligence API
description: 'Endpoints for comprehensive credit card data monitoring in data breaches, including zero-knowledge search
capabilities.
These operations enable robust credit card security protection and exposure assessment.'
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- Credit Card Intelligence
properties:
- type: OpenAPI
url: openapi/nord-security-credit-card-intelligence-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-crypto-addresses-api
name: Nord Security Crypto Addresses API
description: The Crypto Addresses API from Nord Security — 1 operation(s) for crypto addresses.
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- Crypto Addresses
properties:
- type: OpenAPI
url: openapi/nord-security-crypto-addresses-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-dark-web-intelligence-api
name: Nord Security Dark Web Intelligence API
description: Endpoints for searching scraped content from the dark web
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- Dark Web Intelligence
properties:
- type: OpenAPI
url: openapi/nord-security-dark-web-intelligence-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-domain-intelligence-api
name: Nord Security Domain Intelligence API
description: 'Endpoints for investigating domain exposure in data breaches, including detailed breach information and compromise
analysis.
These operations support protection against domain hijacking, phishing attacks, and other threats targeting domain owners.'
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- Domain Intelligence
properties:
- type: OpenAPI
url: openapi/nord-security-domain-intelligence-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-email-intelligence-api
name: Nord Security Email Intelligence API
description: 'Endpoints for comprehensive email address monitoring in data breaches, including detailed breach information,
password exposure, and statistical analysis.
These operations enable robust email security protection, account takeover prevention, and exposure assessment at both
individual and domain-wide levels.'
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- Email Intelligence
properties:
- type: OpenAPI
url: openapi/nord-security-email-intelligence-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-events-api
name: Nord Security Events API
description: The Events API from Nord Security — 36 operation(s) for events.
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- Event
tags_raw:
- Events
properties:
- type: OpenAPI
url: openapi/nord-security-events-api-openapi.yml
- type: Documentation
url: https://docs.nordstellar.com/enterprise-apis/product-integrations
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/swagger
- type: Authentication
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/authentication
- type: RateLimits
url: rate-limits/nord-security-rate-limits.yml
- type: Examples
url: https://docs.nordstellar.com/enterprise-apis/product-integrations/code-examples
- type: DataModel
url: data-model/nord-security-data-model.yml
- type: ErrorCatalog
url: errors/nord-security-problem-types.yml
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/crs/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/cybersec/swagger
- type: APIReference
url: https://docs.nordstellar.com/enterprise-apis/partner/swagger
- type: Documentation
url: https://docs.nordstellar.com/platform/integrations-api
- type: APIReference
url: https://docs.nordstellar.com/platform/integrations-api/swagger
- type: Examples
url: https://docs.nordstellar.com/platform/integrations-api/code-examples
- aid: nord-security:nord-security-files-api
name: Nord Security Files API
description: The Files API from Nord Security — 8 operation(s) for files.
humanURL: https://docs.nordstellar.com/enterprise-apis/product-integrations
baseURL: https://enterprise-data-api.nordstellar.com
tags:
- File
tags_raw:
- Files
properties:
- type: OpenAPI
url: openapi/nord-security-files-api-openapi.yml
# --- truncated at 32 KB (64 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/nord-security/refs/heads/main/apis.yml
Every provider here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for providers
9 MCP tools reach this
find_providersBrowse and filter every provider in the catalog.
get_provider_artifactsEvery artifact this provider publishes, grouped by type.
get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
get_provider_ratingPRO — composite, band, trend and facet scores.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This provider
curl "https://apis.io/api/v1/providers/nord-security"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/nord-security/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/nord-security/evidence"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms .
A second provider on the same verified email joins the account you already have.