# Qwiet Ai

**Canonical:** https://apis.io/providers/qwiet-ai/  
**Website:** https://qwiet.ai  
**APIs profiled:** 27

Qwiet AI (by Harness, formerly ShiftLeft) is an application security testing platform that unifies SAST, SCA, secrets, IaC, and container scanning with AI-assisted AutoFix remediation. The Qwiet AI API v4 (https://app.shiftleft.io/api/v4) lets teams programmatically manage applications, run and read code scans, work with findings and source-to-sink data flows, request and apply AutoFix recommendations, look up package CVEs (Intelligent SCA), manage RBAC/teams/tokens, and configure alerting webhooks and Slack notifications. Qwiet also ships a first-party CLI (`sl`), a published MCP server (harness-code-security-mcp), and packaged agent skills, making its code-security workflows agent-ready. Surfaced as a portfolio company of Mayfield and enriched from the provider's public developer surface.

## Kin Score — 56.3 / 100 (strong)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 56.3).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 64.2 |
| Governance | 11.5 |
| Operational Transparency | 36.8 |
| Developer Ergonomics | 84.8 |
| Commercial Clarity | 44.7 |

## Agent readiness — 54.5 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | yes |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | derived |
| Agent Skills | yes |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (27)

- **Qwiet Ai alerting API** — Notification and alerting related endpoints (such as webhooks)
- **Qwiet Ai analyze API** — The analyze API from Qwiet Ai — 2 operation(s) for analyze.
- **Qwiet Ai app_groups API** — The user-created groups of applications. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-3251cbed-4ae3-4b06-8cad-c8748e49c...
- **Qwiet Ai app_labels API** — The user-created application labels. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/30743751-da3c929b-651f-414c-993c-ee2b2573b2f4...
- **Qwiet Ai apps API** — The applications submitted for analysis. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829310-e9d0bf19-30bd-46f4-b40c-9df03d2a4...
- **Qwiet Ai autofix API** — The AutoFix suggestions for findings in applications. Harness SAST and SCA AutoFix uses large language models (LLMs) to generate potential code fix suggestions for findings prod...
- **Qwiet Ai azureboard API** — The endpoints to manage the Azure Boards integration.
- **Qwiet Ai branches API** — The branch information for scans of applications.
- **Qwiet Ai comments API** — The text threads (with individual comments ordered by time) attached to findings. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/...
- **Qwiet Ai compounds API** — Multi-Language Apps are groups of applications that are scanned together as a single application. This is useful for applications that are a compound of various programming lang...
- **Qwiet Ai findings API** — The results of a scan (which can include vulnerabilities, secrets, or insights). [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9...
- **Qwiet Ai org_backup API** — The endpoints for downloading backups of an organization's data.
- **Qwiet Ai orgs API** — The logical grouping (e.g., tenant/account) within Qwiet that defines a set of users, teams, and applications. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.g...
- **Qwiet Ai rbac API** — Roles-based access control (RBAC) allows you to control the permissions users in an organization are granted. The permissions granted to a user are additive. The base level of a...
- **Qwiet Ai reports API** — The summaries of applications and their findings for a specific organization. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/9829...
- **Qwiet Ai SAML API** — The integration endpoints allowing orgs to configure Qwiet to act as a SAML service provider (SP) that uses the customer's identity provider (IdP) to log users in. [![Run in Pos...
- **Qwiet Ai sarif API** — The integration endpoints for generating and downloading SARIF reports for applications.
- **Qwiet Ai saved_searches API** — The saved searches endpoints allow users to save specific search queries for organization and app findings
- **Qwiet Ai sca API** — The summaries of software composition analysis (SCA) results for apps in an organization. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-col...
- **Qwiet Ai scans API** — The instances where Qwiet AI by Harness is invoked to identify findings in an application. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-co...
- **Qwiet Ai scopes API** — Scopes define the type of resource and the operation that you can perform with the access token you bear. For example, `scans:create` means that the bearer of the token with thi...
- **Qwiet Ai slack API** — The integration endpoints enabling users to set up a Slack integration.
- **Qwiet Ai team_config API** — The endpoints to manage team-level configuration.
- **Qwiet Ai tokens API** — Used to authenticate with the API. Can be issued by org admins. Each access token is owned by the org that issued it. [![Run in Postman](https://run.pstmn.io/button.svg)](https:...
- **Qwiet Ai users API** — Users pertains the users in general as qwiet.ai users and of each org as organization users.
- **Qwiet Ai versions API** — The specific instances of an application scanned using Qwiet AI by Harness. [![Run in Postman](https://run.pstmn.io/button.svg)](https://god.gw.postman.com/run-collection/982931...
- **Qwiet Ai wiz API** — The endpoints to manage the Wiz integration.

## MCP servers (1)

- **qwiet-ai-mcp.yml**

## Agentic access (1)

- **Qwiet Ai Agentic Access** — 145 operations · 59 acting · 2 human-in-the-loop

## Security (2)

- **Qwiet Ai Authentication** — http · 1 scheme
- **Qwiet Ai Domain Security** — TLSv1.3 · HSTS · DMARC

## Tags

Company, Security, Application Security, SAST, SCA, Code Security, Vulnerability Management, DevSecOps, AutoFix

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/qwiet-ai/). Scores are computed from the provider's own public artifacts under a published rubric.
