# Rapid7

**Canonical:** https://apis.io/providers/rapid7/  
**Website:** https://www.rapid7.com  
**APIs profiled:** 50

Rapid7 is a cybersecurity company providing the Insight Platform with products for vulnerability management (InsightVM), SIEM/XDR (InsightIDR), application security (InsightAppSec), cloud security (InsightCloudSec), and SOAR (InsightConnect). The Rapid7 Command/Insight Platform API exposes REST endpoints across regional hosts such as us.api.insight.rapid7.com for managing assets, vulnerabilities, investigations, and integrations. Authentication is performed with an organization or user API key passed in the `X-Api-Key` header.

## Kin Score — 43.1 / 100 (developing)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 43.1).

| Facet | Score |
|---|---|
| Discoverability | 50.0 |
| Contract Quality | 64.0 |
| Governance | 9.8 |
| Contract Governance | 9.8 |
| Operational Transparency | 39.5 |
| Developer Ergonomics | 26.2 |
| Commercial Clarity | 52.6 |
| Access Clarity | 52.6 |

## Agent readiness — 46.0 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | verified |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Free · Self-serve signup — onboarding: self-serve, pricing: free, trial: no (confidence: high).

## APIs (50)

- **Rapid7 InsightVM Cloud API** — REST API for the InsightVM vulnerability management product, exposing assets, scans, vulnerabilities, remediation projects, and reports. Authentication uses an Insight Platform ...
- **Rapid7 Insight Platform API** — Cross-product REST API for the Insight Platform that covers user and key management, organizations, audit logs, and platform-level integrations. Authentication uses `X-Api-Key` ...
- **Rapid7 InsightIDR API** — REST API for the InsightIDR SIEM/XDR product covering investigations, alerts, log search, threats, and SOC workflows. Authentication uses `X-Api-Key` against the regional Insigh...
- **Rapid7 Accounts API** — An API used to find and search InsightIDR accounts. See https://docs.rapid7.com/insightidr/users-and-accounts-on-your-domain for further information on accounts.
- **Rapid7 Administration API** — Provides access administrative operations and procedures.
- **Rapid7 Apps API** — An App <i>owns</i> Scan Configs, Schedules, Scans and Vulnerabilities; you must create an App in order to create any of these other resources. Consequently, if an App is deleted...
- **Rapid7 Asset API** — Resources and operations for managing assets. Assets can be created under the <a href="#operation/createAssetUsingPOST">Site Assets</a> resource.
- **Rapid7 Asset Discovery API** — Resources for managing and viewing the mechanisms used to automatically discover assets.
- **Rapid7 Asset Group API** — Resources and operations for managing asset groups.
- **Rapid7 Assets API** — An API used to find and search InsightIDR assets. See https://docs.rapid7.com/insightidr/assets-on-your-domain for further information on assets.
- **Rapid7 Attachments API** — An API used to upload, list, download and delete attachments. For example, the create API can be used to upload an attachment.
- **Rapid7 Attack Templates API** — An Attack Template describes <i>if</i> and <i>how</i> Attacks should be executed during the execution of a Scan. There exist pre-defined, system-provided and immutable templates...
- **Rapid7 Blackouts API** — A blackout is a period of time when all scanning activities for the specified scope are blocked. A blackout can be scoped globally or to a specific App, this is implied by the <...
- **Rapid7 Collectors API** — An API used to manage collectors for an organization.
- **Rapid7 Comments API** — An API used to find, create, and delete comments. For example, these APIs can be used to create a comment for a particular investigation.
- **Rapid7 Community Threats API** — An API used to add and replace indicators for Community Threats. See https://insightidr.help.rapid7.com/docs/threats#section-threat-api for further information on how to generat...
- **Rapid7 Credential API** — Resources and operations for managing shared credentials.
- **Rapid7 Engine Groups API** — An Engine Group is a resource which defines a container for a logical grouping of Engines and therefore the purpose of assigning Scans to one of those Engines. Any created Engin...
- **Rapid7 Engines API** — An Engine encapsulates the state and high-level attributes of the components which may be installed and running on a specific On-Premise host. The status of an Engine is not mut...
- **Rapid7 Files API** — Files are used primarily to manage content that can be required to successfully scan an App. For example, many supported methods of configuring authentication in a Scan Config r...
- **Rapid7 Health Metrics API** — An API used to retrieve health metrics of an organization.
- **Rapid7 Investigations API** — The Investigations API from Rapid7 — 4 operation(s) for investigations.
- **Rapid7 Local Accounts API** — An API used to find and search InsightIDR local accounts. See https://docs.rapid7.com/insightidr/users-and-accounts-on-your-domain for further information on local accounts.
- **Rapid7 Policy API** — Resources and operations for managing policies.
- **Rapid7 Policy Override API** — Policy Override Resource Controller
- **Rapid7 Remediation API** — Resources for determining the details required to remediate vulnerabilities.
- **Rapid7 Report API** — Resources and operations for managing and generating reports. Reports are broadly categorized into `document`, `export`, and `file` types. `document` reports use section-based r...
- **Rapid7 Reports API** — Reports provide the ability to share information with stakeholders at both scan and app levels. The following table lists the report templates and the various formats that are a...
- **Rapid7 Root API** — Provides access to primary entry point for discovering the available resources in this API.
- **Rapid7 Scan API** — Resources and operations for managing scans.
- **Rapid7 Scan Configs API** — A Scan Config defines all the necessary information required to perform a Scan of an App. An App <i>must</i> be created prior to creating a Scan Config. It is the main document ...
- **Rapid7 Scan Engine API** — Resources and operations for managing scan engines.
- **Rapid7 Scan Template API** — Scan Template Resource Controller
- **Rapid7 Scans API** — A Scan encapsulates all the information for a single execution of the criteria defined in the provided Scan Config. An App and a Scan Config <i>must</i> be created prior to subm...
- **Rapid7 Schedules API** — A Schedule defines the automated execution of a Scan, using a specified Scan Config. Both the App and Scan Config must be created prior to creating a Schedule. There are two opt...
- **Rapid7 Search API** — A global Search API is exposed to facilitate the execution of user-defined queries that can perform a Search across the supported resource types exposed via the API. Each Search...
- **Rapid7 Site API** — Resources and operations for managing sites.
- **Rapid7 Tag API** — Resources and operations for managing tags.
- **Rapid7 Tags API** — Tags are customer-defined labels that can be used for a variety of purposes. The management of Tags is performed by this API, and other APIs facilitate applying these Tags to ot...
- **Rapid7 Targets API** — A Target essentially specifies an allowlisted Fully Qualified Domain Name (FQDN) which can be Scanned by InsightAppSec. A Target can be created, edited and deleted by an API con...
- …and 10 more, listed in full on the page.

## MCP servers (1)

- **MCP Server**

## Agentic access (1)

- **Rapid7 Agentic Access** — 459 operations · 221 acting · 5 human-in-the-loop

## Security (3)

- **Rapid7 Authentication** — http · 1 scheme
- **Rapid7 Domain Security** — TLSv1.3 · HSTS · DMARC
- **Rapid7 Vulnerability Disclosure** — disclosure policy published

## Plans (1)

- **Rapid7 Plans Pricing**

## Tags

Security, Vulnerability Management, SIEM, XDR, Cloud Security, SOAR, Application Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/rapid7/). Scores are computed from the provider's own public artifacts under a published rubric.
