# Opal Security

**Canonical:** https://apis.io/providers/opal-security/  
**Website:** https://opal.dev/  
**APIs profiled:** 22

Opal Security (legal entity Perma Security, Inc.) is a next-generation access management and identity security platform that gives enterprises comprehensive visibility into access across their systems, orchestrates just-in-time and least-privilege access, designs intelligent access policies, and automates user access reviews (UARs). Opal exposes a RESTful API at https://api.opal.dev/v1 covering apps, resources, groups, users, bundles, access requests, access rules, owners, events, event streaming, sessions, and tokens, plus official SDKs (Python, Go), a CLI, a Terraform provider, and three hosted Model Context Protocol (MCP) servers for AI agents. Backed by Greylock. Sector: cybersecurity.

## Kin Score — 59.8 / 100 (strong)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 59.8).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 67.3 |
| Governance | 11.5 |
| Operational Transparency | 47.4 |
| Developer Ergonomics | 76.1 |
| Commercial Clarity | 60.5 |

## Agent readiness — 52.3 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| MCP Server | yes |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | verified |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | yes |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (22)

- **Opal Security access-rules API** — Operations related to access rules
- **Opal Security apps API** — Operations related to apps
- **Opal Security bundles API** — Operations related to bundles
- **Opal Security configuration-templates API** — Operations related to configuration templates
- **Opal Security delegations API** — Operations related to request reviewer delegations
- **Opal Security event-streams API** — Operations related to event streaming connections
- **Opal Security events API** — Operations related to events
- **Opal Security group-bindings API** — Operations related to group bindings
- **Opal Security groups API** — Operations related to groups
- **Opal Security idp-group-mappings API** — Operations related to IDP group mappings
- **Opal Security message-channels API** — Operations related to message channels
- **Opal Security non-human-identities API** — Operations related to non-human identities
- **Opal Security on-call-schedules API** — Operations related to on-call schedules
- **Opal Security opal-queries API** — Operations related to OpalQuery
- **Opal Security owners API** — Operations related to owners
- **Opal Security requests API** — Operations related to requests
- **Opal Security resources API** — Operations related to resources
- **Opal Security sessions API** — Operations related to sessions
- **Opal Security tags API** — Operations related to tags
- **Opal Security tokens API** — Operations related to API tokens
- **Opal Security uars API** — Operations related to UARs
- **Opal Security users API** — Operations related to users

## MCP servers (1)

- **opal-security-mcp.yml**

## Security (4)

- **Opal Security Authentication** — http · 1 scheme
- **Opal Security Domain Security** — TLSv1.3 · HSTS · DMARC
- **Opal Security Vulnerability Disclosure** — Hackerone
- **Opal Security Trust Center** — trust center published

## Tags

Company, Cybersecurity, Access Management, Identity and Access Management, Least Privilege, Access Reviews, Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/opal-security/). Scores are computed from the provider's own public artifacts under a published rubric.
