# Panther

**Canonical:** https://apis.io/providers/panther/  
**Website:** https://www.panther.com/  
**APIs profiled:** 21

Panther is a cloud-native, code-driven detection and response platform and AI-powered SOC that ingests and normalizes security logs at petabyte scale into a security data lake (customer-connected AWS/Snowflake/Databricks or Panther-hosted). It offers Python detection-as-code, AI-generated detections, correlation and scheduled rules, cloud-security policies, and an AI SOC agent that auto-triages and investigates alerts. Developers automate it through a REST API (X-API-Key), a GraphQL API, Terraform, the panther_analysis_tool CLI, and official local and remote MCP servers. Backed by ICONIQ Capital and Lightspeed Venture Partners.

## Kin Score — 53.9 / 100 (developing)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 53.9).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 59.4 |
| Governance | 20.8 |
| Operational Transparency | 28.9 |
| Developer Ergonomics | 62.5 |
| Commercial Clarity | 60.5 |

## Agent readiness — 55.2 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | yes |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (21)

- **Panther alert API** — The alert api handles all operations for alerts
- **Panther api token API** — The api token api handles all operations for api tokens
- **Panther aws cloud account API** — The AWS Cloud Account API handles all operations for AWS Cloud Account scanner integrations
- **Panther comment API** — The comment api handles all operations for alerts comments
- **Panther contexttag API** — The context tag API handles all operations for alert context tags
- **Panther correlation rule API** — The correlation rule api handles all operations for correlation rules
- **Panther data model API** — The data model api handles all operations for data models
- **Panther gcs source API** — The GCS source API handles all operations for Google Cloud Storage log sources
- **Panther global API** — The global api handles all operations for globals
- **Panther http source API** — The http source api handles all operations for http sources
- **Panther log forwarder source API** — The log forwarder source api handles all operations for log forwarder sources
- **Panther log source alarm API** — Manage the drop-off alarm (SOURCE_NO_DATA) for log source integrations. Other alarm types shown in the Panther UI (permissions checks, classification failures, log-processing er...
- **Panther policy API** — The policy api handles all operations for policies
- **Panther pub/sub source API** — The Pub/Sub source API handles all operations for GCP Pub/Sub log sources
- **Panther query API** — The query api handles operations for queries
- **Panther role API** — The role api handles all operations for roles
- **Panther rule API** — The rule api handles all operations for rules
- **Panther s3 source API** — The S3 source API handles all operations for AWS S3 log sources
- **Panther scheduled rule API** — The scheduled rule api handles all operations for scheduled rules
- **Panther simple rule API** — The simple rule api handles all operations for simple rules
- **Panther user API** — The user api handles all operations for users

## MCP servers (1)

- **panther-mcp.yml**

## Agentic access (1)

- **Panther Agentic Access** — 96 operations · 61 acting

## Security (3)

- **Panther Authentication** — apiKey · 1 scheme
- **Panther Domain Security** — TLSv1.3 · HSTS · DMARC
- **Panther Trust Center** — SOC 2 Type II, ISO 27001, PCI DSS

## Tags

Company, Security, SIEM, Detection and Response, Security Operations, Threat Detection, Log Management, Data Lake, Cloud Security, Developer Tools

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/panther/). Scores are computed from the provider's own public artifacts under a published rubric.
