# Promptfoo

**Canonical:** https://apis.io/providers/promptfoo/  
**Website:** https://www.promptfoo.dev/  
**APIs profiled:** 6

Promptfoo is an open-source LLM evaluation and red-teaming framework distributed as a TypeScript CLI and Node.js library under the MIT license. Developers use it to evaluate prompts, models, and RAG pipelines side by side, run automated red team attacks against LLM applications, scan code for LLM vulnerabilities in IDE and CI, and proxy Model Context Protocol traffic. Promptfoo also operates a commercial Enterprise platform at promptfoo.app for teams that need centralized governance, remediation reports, and shared evaluation history.

## Kin Score — 34.6 / 100 (thin)

Scored 2026-08-25 under rubric 0.14.0. Trend: flat (+0.0 from 34.6).

| Facet | Score |
|---|---|
| Discoverability | 64.8 |
| Contract Quality | 6.7 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 39.5 |
| Developer Ergonomics | 52.4 |
| Commercial Clarity | 53.9 |
| Access Clarity | 53.9 |

## Agent readiness — 3.8 (human-only)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | documented |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Free — onboarding: unknown, pricing: free, trial: no (confidence: medium).

## APIs (6)

- **Promptfoo CLI** — The Promptfoo CLI is the primary entry point for running prompt and model evaluations from the command line or CI. It is installable via npm, Homebrew, pip, or npx and reads a Y...
- **Promptfoo Node.js Library** — The Promptfoo Node.js package exposes the same evaluation engine programmatically so developers can embed evaluations, assertions, and dataset runs directly into JavaScript and ...
- **Promptfoo Red Team** — Promptfoo Red Team generates adversarial test cases against LLM applications targeting prompt injection, jailbreaks, PII leakage, bias, and other OWASP LLM Top 10 categories. Ru...
- **Promptfoo Enterprise** — Promptfoo Enterprise is the commercial SaaS at promptfoo.app providing centralized evaluation history, shared red team findings, remediation reports, role-based access control, ...
- **Promptfoo MCP Proxy** — MCP Proxy is Promptfoo's security gateway for Model Context Protocol traffic, inspecting tool calls and responses flowing between agents and MCP servers to enforce policies and ...
- **Promptfoo Code Scanning** — Promptfoo Code Scanning analyzes source code in IDEs and CI pipelines to find LLM-related vulnerabilities including unsafe prompt construction, missing guardrails, and risky too...

## Security (2)

- **Promptfoo Domain Security** — TLSv1.3 · DMARC
- **Promptfoo Trust Center** — SOC 2, ISO 27001

## Plans (1)

- **Promptfoo Plans Pricing**

## Use cases (5)

- **Prompt Iteration** — Compare prompt variants against datasets to choose the best-performing version.
- **Model Selection** — Benchmark candidate models across providers before committing to one in production.
- **RAG Quality Assurance** — Evaluate chunking, retrieval, and generation choices in RAG systems.
- **AI Red Teaming** — Probe pre-production LLM applications for adversarial failure modes.
- **Continuous LLM Testing** — Wire evaluations and red team scans into CI so regressions block deploys.

## Tags

LLM Evaluation, Red Teaming, AI Security, Guardrails, Open-Source, CLI, Developer Tools

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/promptfoo/). Scores are computed from the provider's own public artifacts under a published rubric.
