OpenText Cybersecurity

OpenText Cybersecurity is the security business of OpenText, assembled from the Micro Focus security portfolio (Fortify application security, ArcSight threat detection and response, NetIQ identity and access management, Voltage data privacy) and the SMB/MSP brands OpenText acquired through Webroot, Carbonite and Zix — endpoint protection, DNS protection, EDR/MDR, email threat protection and encryption, security awareness training, backup and disaster recovery. Two product lines expose a public developer surface. OpenText Core Application Security (Fortify on Demand) publishes a live Swagger 2.0 contract with 159 operations across applications, releases, static/dynamic/mobile scans, vulnerabilities, reports and tenant administration, served per region from api.ams / api.emea / api.apac.fortify.com. The Webroot Unity API is the multi-tenant REST platform managed service providers use to run Secure Cloud sites, endpoints, policies, licensing and near-real-time event notifications. Fortify also ships a first-party CLI (fcli), a first-party MCP server inside that CLI, and a published set of Agent Skills for Claude Code, GitHub Copilot, Codex and Gemini CLI.

OpenText Cybersecurity publishes 1 API on the APIs.io network: OpenText Core Application Security (Fortify on Demand) API. Tagged areas include Cybersecurity, Application Security, Vulnerability Management, SAST, and DAST.

The OpenText Cybersecurity catalog on APIs.io includes 1 event-driven AsyncAPI specification.

OpenText Cybersecurity’s developer surface includes documentation, API reference, getting-started guide, support, engineering blog, signup flow, pricing, and 36 more developer resources.

54.2/100 developing Agent 32/100 agent ready Full breakdown ↓
scored 2026-09-14 · rubric v0.22.0
1 APIs 1 MCP Servers
CybersecurityApplication SecurityVulnerability ManagementSASTDASTEndpoint SecurityThreat DetectionEmail SecurityBackup and RecoveryManaged Service ProvidersIdentity and AccessData PrivacyEnterprise Software

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-14 · rubric v0.22.0
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it carries 10 points of the composite. It is scored from the published contracts themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in front of it, and the first time that check is skipped a duplicate record is created. Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet, not penalised by it.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/opentext-cybersecurity: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 2

Individual APIs this provider publishes, each with its own machine-readable definition.

OpenText Core Application Security (Fortify on Demand) API

The REST API behind OpenText Core Application Security, still branded Fortify on Demand across the contract and the tooling. 159 operations over 125 paths cover applications, re...

Webroot Unity API

The Webroot Unity API is the multi-tenant REST platform OpenText Cybersecurity partners and managed service providers use to reach Webroot and Secure Cloud services — endpoint s...

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Opentext Cybersecurity Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Opentext Cybersecurity Scopes

OAuth 2.0 · no documented scopes

0 scopes

SCOPES

Resources

Get Started 4

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 6

Pagination, idempotency, versioning, errors, and events

Build 5

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 7

Status, limits, changes, and where to get help

Scroll for all 7

Commercial 4

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 6

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: opentext-cybersecurity
name: OpenText Cybersecurity
description: OpenText Cybersecurity is the security business of OpenText, assembled from the Micro Focus security portfolio
  (Fortify application security, ArcSight threat detection and response, NetIQ identity and access management, Voltage data
  privacy) and the SMB/MSP brands OpenText acquired through Webroot, Carbonite and Zix — endpoint protection, DNS protection,
  EDR/MDR, email threat protection and encryption, security awareness training, backup and disaster recovery. Two product
  lines expose a public developer surface. OpenText Core Application Security (Fortify on Demand) publishes a live Swagger
  2.0 contract with 159 operations across applications, releases, static/dynamic/mobile scans, vulnerabilities, reports and
  tenant administration, served per region from api.ams / api.emea / api.apac.fortify.com. The Webroot Unity API is the multi-tenant
  REST platform managed service providers use to run Secure Cloud sites, endpoints, policies, licensing and near-real-time
  event notifications. Fortify also ships a first-party CLI (fcli), a first-party MCP server inside that CLI, and a published
  set of Agent Skills for Claude Code, GitHub Copilot, Codex and Gemini CLI.
image: https://cari01mstrop62eprod.dxcloud.episerver.net/globalassets/smb-media/images/banners/csot-homepage-hero-2.webp
url: https://raw.githubusercontent.com/api-evangelist/opentext-cybersecurity/refs/heads/main/apis.yml
x-type: company
x-source: harvest:absent-parent
specificationVersion: '0.20'
created: '2026-09-13'
modified: '2026-09-13'
position: Producing
tags:
- Cybersecurity
- Application Security
- Vulnerability Management
- SAST
- DAST
- Endpoint Security
- Threat Detection
- Email Security
- Backup and Recovery
- Managed Service Providers
- Identity and Access
- Data Privacy
- Enterprise Software
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
apis:
- aid: opentext-cybersecurity:fortify-on-demand-api
  name: OpenText Core Application Security (Fortify on Demand) API
  description: The REST API behind OpenText Core Application Security, still branded Fortify on Demand across the contract
    and the tooling. 159 operations over 125 paths cover applications, releases, static, dynamic, mobile and open-source scans,
    vulnerability audit and triage, reports, API keys, personal access tokens, users and tenant entitlements. The spec is
    served live and unauthenticated from every regional API host and every operation declares its required OAuth scope in
    its description.
  humanURL: https://api.ams.fortify.com/swagger/ui/index
  baseURL: https://api.ams.fortify.com
  tags:
  - Application Security
  - SAST
  - DAST
  - Software Composition Analysis
  - Vulnerability Management
  properties:
  - url: openapi/opentext-cybersecurity-fortify-on-demand-openapi.json
    type: OpenAPI
  - url: overlays/opentext-cybersecurity-fortify-on-demand-overlay.yaml
    type: Overlay
  - url: https://api.ams.fortify.com/swagger/ui/index
    type: APIReference
  - url: https://community.opentext.com/cybersec/fortify/productdocs
    type: Documentation
  - url: https://community.opentext.com/cybersec/fortify
    type: DeveloperPortal
  - url: https://status.fortify.com/
    type: StatusPage
- aid: opentext-cybersecurity:webroot-unity-api
  name: Webroot Unity API
  description: The Webroot Unity API is the multi-tenant REST platform OpenText Cybersecurity partners and managed service
    providers use to reach Webroot and Secure Cloud services — endpoint status, Global Site Manager console site/user/policy/endpoint/group
    management, DNS Protection, Web Threat Shield, security awareness training reporting, usage reporting, eCommerce licensing,
    and Secure Cloud customers and usage. It also carries a documented event-notification surface with fetch and webhook delivery.
    Access is OAuth 2.0 and credentials must be issued by a Webroot representative or enabled from a GSM console, so no machine-readable
    contract is published anonymously.
  humanURL: https://unityapi.webrootcloudav.com/Docs/en/APIDoc
  baseURL: https://unityapi.webrootcloudav.com
  tags:
  - Endpoint Security
  - DNS Protection
  - Managed Service Providers
  - Licensing
  - Webhook
  tags_raw:
  - Endpoint Security
  - DNS Protection
  - Managed Service Providers
  - Licensing
  - Webhooks
  properties:
  - url: https://unityapi.webrootcloudav.com/Docs/en/APIDoc/APIReference
    type: APIReference
  - url: https://unityapi.webrootcloudav.com/Docs/en/APIDoc
    type: Documentation
  - url: https://unityapi.webrootcloudav.com/Docs/en/APIDoc/GettingStarted
    type: GettingStarted
  - url: https://unityapi.webrootcloudav.com/Docs/en/APIDoc/ChangeHistory
    type: ChangeLog
  - url: asyncapi/opentext-cybersecurity-webroot-unity-webhooks.yml
    type: Webhooks
common:
- type: DomainSecurity
  url: security/opentext-cybersecurity-domain-security.yml
- url: https://cybersecurity.opentext.com/
  type: Website
- url: https://community.opentext.com/cybersec/fortify
  type: DeveloperPortal
- url: https://community.opentext.com/cybersec/fortify/productdocs
  type: Documentation
- url: https://api.ams.fortify.com/swagger/ui/index
  type: APIReference
- url: https://unityapi.webrootcloudav.com/Docs/en/APIDoc/GettingStarted
  type: GettingStarted
- url: https://cybersecurity.opentext.com/support/
  type: Support
- url: https://community.opentext.com/cybersec/fortify/f/discussions
  type: Community
- url: https://cybersecurity.opentext.com/blog/
  type: Blog
- url: https://github.com/fortify
  type: GitHubOrganization
- url: https://status.fortify.com/
  type: StatusPage
- url: https://status.opentext.com/
  type: StatusPage
- url: https://cybersecurity.opentext.com/account-login/
  type: SignUp
- url: https://my.webrootanywhere.com/
  type: Login
- url: https://cybersecurity.opentext.com/legal/sdk-and-api-agreement/
  type: TermsOfService
- url: https://www.opentext.com/about/privacy
  type: PrivacyPolicy
- url: https://cybersecurity.opentext.com/contact-us/
  type: Pricing
- url: llms/opentext-cybersecurity-llms.txt
  type: LLMsTxt
- url: packages/opentext-cybersecurity-packages.yml
  type: Packages
- url: packages/opentext-cybersecurity-packages.yml
  type: SDKs
- url: cli/opentext-cybersecurity-cli.yml
  type: CLI
- url: mcp/opentext-cybersecurity-mcp.yml
  type: MCPServer
- url: mcp/opentext-cybersecurity-tool-crosswalk.yml
  type: ToolCrosswalk
- url: skills/_index.yml
  type: AgentSkill
- url: authentication/opentext-cybersecurity-authentication.yml
  type: Authentication
- url: scopes/opentext-cybersecurity-scopes.yml
  type: OAuthScopes
- url: conventions/opentext-cybersecurity-conventions.yml
  type: Conventions
- url: errors/opentext-cybersecurity-problem-types.yml
  type: ErrorCatalog
- url: lifecycle/opentext-cybersecurity-lifecycle.yml
  type: Lifecycle
- url: lifecycle/opentext-cybersecurity-lifecycle.yml
  type: Deprecation
- url: data-model/opentext-cybersecurity-data-model.yml
  type: DataModel
- url: rate-limits/opentext-cybersecurity-rate-limits.yml
  type: RateLimits
- url: plans/opentext-cybersecurity-plans-pricing.yml
  type: Plans
- url: changelog/opentext-cybersecurity-changelog.yml
  type: ChangeLog
- url: conformance/opentext-cybersecurity-conformance.yml
  type: Conformance
- url: conformance/opentext-cybersecurity-conformance.yml
  type: Compliance
- url: asyncapi/opentext-cybersecurity-webroot-unity-webhooks.yml
  type: Webhooks
- url: grpc/opentext-cybersecurity-aviator-issue.proto
  type: Protobuf
- url: grpc/opentext-cybersecurity-aviator-correlation.proto
  type: Protobuf
- url: grpc/opentext-cybersecurity-aviator-application.proto
  type: Protobuf
- url: grpc/opentext-cybersecurity-aviator-entitlement.proto
  type: Protobuf
- url: grpc/opentext-cybersecurity-aviator-dast-entitlement.proto
  type: Protobuf
- url: grpc/opentext-cybersecurity-aviator-accesstoken.proto
  type: Protobuf
x-enrichment:
  date: '2026-09-13'
  status: enriched
  artifacts_added: 40
  pass: local-v3
x-coverage:
  state: covered
  reason: null
  detail: 'Live first-party contract found and saved: a Swagger 2.0 document with 159 operations served unauthenticated from
    every Fortify on Demand regional API host, plus six first-party Aviator .proto service definitions, a provider-published
    llms.txt, and a provider-published Agent Skills package.'
  checked: '2026-09-13'

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/opentext-cybersecurity"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/opentext-cybersecurity/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/opentext-cybersecurity/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.