Opal Security website screenshot

Opal Security

Opal Security (legal entity Perma Security, Inc.) is a next-generation access management and identity security platform that gives enterprises comprehensive visibility into access across their systems, orchestrates just-in-time and least-privilege access, designs intelligent access policies, and automates user access reviews (UARs). Opal exposes a RESTful API at https://api.opal.dev/v1 covering apps, resources, groups, users, bundles, access requests, access rules, owners, events, event streaming, sessions, and tokens, plus official SDKs (Python, Go), a CLI, a Terraform provider, and three hosted Model Context Protocol (MCP) servers for AI agents. Backed by Greylock. Sector: cybersecurity.

Opal Security publishes 22 APIs on the APIs.io network, including access-rules API, apps API, bundles API, and 19 more. Tagged areas include Company, Cybersecurity, Access Management, Identity and Access Management, and Least Privilege.

The Opal Security catalog on APIs.io includes 1 event-driven AsyncAPI specification.

Opal Security’s developer surface includes authentication, CLI, changelog, documentation, API reference, getting-started guide, engineering blog, and 22 more developer resources.

50.3/100 developing ▬ flat Agent 40/100 agent ready saas Full breakdown ↓
scored 2026-09-06 · rubric v0.19.0
1 APIs 1 MCP Servers
CompanyCybersecurityAccess ManagementIdentity and Access ManagementLeast PrivilegeAccess ReviewsSecurity

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-06 · rubric v0.19.0
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/opal-security: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 22

Individual APIs this provider publishes, each with its own machine-readable definition.

Opal Security access-rules API

Operations related to access rules

Opal Security apps API

Operations related to apps

Opal Security bundles API

Operations related to bundles

Opal Security configuration-templates API

Operations related to configuration templates

Opal Security delegations API

Operations related to request reviewer delegations

Opal Security event-streams API

Operations related to event streaming connections

Opal Security events API

Operations related to events

Opal Security group-bindings API

Operations related to group bindings

Opal Security groups API

Operations related to groups

Opal Security idp-group-mappings API

Operations related to IDP group mappings

Opal Security message-channels API

Operations related to message channels

Opal Security non-human-identities API

Operations related to non-human identities

Opal Security on-call-schedules API

Operations related to on-call schedules

Opal Security opal-queries API

Operations related to OpalQuery

Opal Security owners API

Operations related to owners

Opal Security requests API

Operations related to requests

Opal Security resources API

Operations related to resources

Opal Security sessions API

Operations related to sessions

Opal Security tags API

Operations related to tags

Opal Security tokens API

Operations related to API tokens

Opal Security uars API

Operations related to UARs

Opal Security users API

Operations related to users

Scroll for all 22

Open Collections 23

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

API Collection

OPEN COLLECTION

Opal access-rules API

OPEN COLLECTION

Scroll for all 23

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

Opal Security MCP Server

Opal Security hosts three specialized, self-hosted Model Context Protocol (MCP) servers that let AI agents interact with the Opal access-management platform through its REST API...

MCP SERVER

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Opal Security Authentication

http · 1 scheme

SECURITY

Opal Security Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Opal Security Trust Center

trust center published

SECURITY

Resources

Get Started 3

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 2

Pagination, idempotency, versioning, errors, and events

Build 4

SDKs, sample code, and the tooling you integrate with

Access & Security 6

Authentication, authorization, and security posture

Operate 3

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: opal-security
name: Opal Security
description: 'Opal Security (legal entity Perma Security, Inc.) is a next-generation access management and identity security
  platform that gives enterprises comprehensive visibility into access across their systems, orchestrates just-in-time and
  least-privilege access, designs intelligent access policies, and automates user access reviews (UARs). Opal exposes a RESTful
  API at https://api.opal.dev/v1 covering apps, resources, groups, users, bundles, access requests, access rules, owners,
  events, event streaming, sessions, and tokens, plus official SDKs (Python, Go), a CLI, a Terraform provider, and three hosted
  Model Context Protocol (MCP) servers for AI agents. Backed by Greylock. Sector: cybersecurity.'
url: https://raw.githubusercontent.com/api-evangelist/opal-security/refs/heads/main/apis.yml
deliveryModel:
  model: saas
  open_source: false
  commercial: true
  callable_host: true
  label: Hosted service · you call their endpoint
  confidence: high
  source:
  - openapi
  - pricing
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source:
  - authentication
  - security
  generated: '2026-09-03'
  method: derived
image: https://framerusercontent.com/images/HHjnsz66kJwSMAe0rpzp3eREB2k.png
x-type: company
x-source: vc-portfolio
x-backed-by:
- greylock
x-tier: stub
x-tier-reason: portfolio-lead
specificationVersion: '0.23'
created: '2026-07-17'
modified: '2026-07-20'
tags:
- Company
- Cybersecurity
- Access Management
- Identity and Access Management
- Least Privilege
- Access Reviews
- Security
apis:
- aid: opal-security:opal-security-access-rules-api
  name: Opal Security access-rules API
  description: Operations related to access rules
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Access Rules
  tags_raw:
  - access-rules
  properties:
  - type: OpenAPI
    url: openapi/opal-security-access-rules-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-apps-api
  name: Opal Security apps API
  description: Operations related to apps
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Application
  tags_raw:
  - apps
  properties:
  - type: OpenAPI
    url: openapi/opal-security-apps-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-bundles-api
  name: Opal Security bundles API
  description: Operations related to bundles
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Bundles
  tags_raw:
  - bundles
  properties:
  - type: OpenAPI
    url: openapi/opal-security-bundles-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-configuration-templates-api
  name: Opal Security configuration-templates API
  description: Operations related to configuration templates
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Configuration Templates
  tags_raw:
  - configuration-templates
  properties:
  - type: OpenAPI
    url: openapi/opal-security-configuration-templates-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-delegations-api
  name: Opal Security delegations API
  description: Operations related to request reviewer delegations
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Delegations
  tags_raw:
  - delegations
  properties:
  - type: OpenAPI
    url: openapi/opal-security-delegations-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-event-streams-api
  name: Opal Security event-streams API
  description: Operations related to event streaming connections
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Event Streams
  tags_raw:
  - event-streams
  properties:
  - type: OpenAPI
    url: openapi/opal-security-event-streams-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-events-api
  name: Opal Security events API
  description: Operations related to events
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Event
  tags_raw:
  - events
  properties:
  - type: OpenAPI
    url: openapi/opal-security-events-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-group-bindings-api
  name: Opal Security group-bindings API
  description: Operations related to group bindings
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - group-bindings
  properties:
  - type: OpenAPI
    url: openapi/opal-security-group-bindings-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-groups-api
  name: Opal Security groups API
  description: Operations related to groups
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Group
  tags_raw:
  - groups
  properties:
  - type: OpenAPI
    url: openapi/opal-security-groups-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-idp-group-mappings-api
  name: Opal Security idp-group-mappings API
  description: Operations related to IDP group mappings
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - idp-group-mappings
  properties:
  - type: OpenAPI
    url: openapi/opal-security-idp-group-mappings-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-message-channels-api
  name: Opal Security message-channels API
  description: Operations related to message channels
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - message-channels
  properties:
  - type: OpenAPI
    url: openapi/opal-security-message-channels-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-non-human-identities-api
  name: Opal Security non-human-identities API
  description: Operations related to non-human identities
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - non-human-identities
  properties:
  - type: OpenAPI
    url: openapi/opal-security-non-human-identities-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-on-call-schedules-api
  name: Opal Security on-call-schedules API
  description: Operations related to on-call schedules
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - On-Call Schedules
  tags_raw:
  - on-call-schedules
  properties:
  - type: OpenAPI
    url: openapi/opal-security-on-call-schedules-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-opal-queries-api
  name: Opal Security opal-queries API
  description: Operations related to OpalQuery
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - opal-queries
  properties:
  - type: OpenAPI
    url: openapi/opal-security-opal-queries-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-owners-api
  name: Opal Security owners API
  description: Operations related to owners
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Owners
  tags_raw:
  - owners
  properties:
  - type: OpenAPI
    url: openapi/opal-security-owners-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-requests-api
  name: Opal Security requests API
  description: Operations related to requests
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Requests
  tags_raw:
  - requests
  properties:
  - type: OpenAPI
    url: openapi/opal-security-requests-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-resources-api
  name: Opal Security resources API
  description: Operations related to resources
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Resources
  tags_raw:
  - resources
  properties:
  - type: OpenAPI
    url: openapi/opal-security-resources-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-sessions-api
  name: Opal Security sessions API
  description: Operations related to sessions
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Sessions
  tags_raw:
  - sessions
  properties:
  - type: OpenAPI
    url: openapi/opal-security-sessions-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-tags-api
  name: Opal Security tags API
  description: Operations related to tags
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Tags
  tags_raw:
  - tags
  properties:
  - type: OpenAPI
    url: openapi/opal-security-tags-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-tokens-api
  name: Opal Security tokens API
  description: Operations related to API tokens
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - Tokens
  tags_raw:
  - tokens
  properties:
  - type: OpenAPI
    url: openapi/opal-security-tokens-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-uars-api
  name: Opal Security uars API
  description: Operations related to UARs
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - uars
  properties:
  - type: OpenAPI
    url: openapi/opal-security-uars-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- aid: opal-security:opal-security-users-api
  name: Opal Security users API
  description: Operations related to users
  humanURL: https://docs.opal.dev/
  baseURL: https://api.opal.dev/v1
  tags:
  - User
  tags_raw:
  - users
  properties:
  - type: OpenAPI
    url: openapi/opal-security-users-api-openapi.yml
  - type: ErrorCatalog
    url: errors/opal-security-problem-types.yml
  - type: DataModel
    url: data-model/opal-security-data-model.yml
  - type: Conventions
    url: conventions/opal-security-conventions.yml
  - type: Webhooks
    url: asyncapi/opal-security-events-webhooks.yml
  - type: Documentation
    url: https://docs.opal.dev/
  - type: APIReference
    url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Overlay
  url: overlays/opal-security-openapi-overlay.yaml
- type: DomainSecurity
  url: security/opal-security-domain-security.yml
- type: Authentication
  url: authentication/opal-security-authentication.yml
- type: LLMsTxt
  url: llms/opal-security-llms.txt
- type: Packages
  url: packages/opal-security-packages.yml
- type: SDKs
  url: packages/opal-security-packages.yml
- type: MCPServer
  url: mcp/opal-security-mcp.yml
- type: CLI
  url: cli/opal-security-cli.yml
- type: ChangeLog
  url: changelog/opal-security-changelog.yml
- type: Lifecycle
  url: lifecycle/opal-security-lifecycle.yml
- type: StatusPage
  url: https://status.opal.dev/
- type: Conformance
  url: conformance/opal-security-conformance.yml
- type: Compliance
  url: security/opal-security-trust-center.yml
- type: TrustCenter
  url: security/opal-security-trust-center.yml
- type: VulnerabilityDisclosure
  url: security/opal-security-vulnerability-disclosure.yml
- type: Security
  url: security/opal-security-vulnerability-disclosure.yml
- type: AgentSkill
  url: skills/_index.yml
- type: Website
  url: https://opal.dev/
- type: DeveloperPortal
  url: https://docs.opal.dev/
- type: Documentation
  url: https://docs.opal.dev/
- type: APIReference
  url: https://docs.opal.dev/api-reference/access-rules/get-access-rules
- type: GettingStarted
  url: https://docs.opal.dev/
- type: Changelog
  url: https://docs.opal.dev/changelog/changelog
- type: Blog
  url: https://opal.dev/blog
- type: Pricing
  url: https://opal.dev/pricing
- type: GitHubOrganization
  url: https://github.com/opalsecurity
- type: SignUp
  url: https://app.opal.dev/
- type: TermsOfService
  url: https://opal.dev/terms-of-service
- type: PrivacyPolicy
  url: https://opal.dev/privacy-policy
x-enrichment:
  date: '2026-07-20'
  status: enriched
  pass: local-v1
  artifacts_added: 20

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/opal-security"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/opal-security/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/opal-security/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.