SafeLine website screenshot

SafeLine

SafeLine is an open-source self-hosted Web Application Firewall (WAF) and reverse proxy developed by Chaitin Technology that protects web applications and APIs from attacks including SQL injection, XSS, code injection, OS command injection, SSRF, path traversal, and RCE. With over 180,000 installations protecting more than 1 million websites, SafeLine handles over 30 billion HTTP requests daily. It provides rate limiting, anti-bot defenses, dynamic code protection, and integrates with API gateways including Apache APISIX and Kong. SafeLine exposes a management API on port 9443 and supports MCP server implementations for AI-assisted management.

SafeLine publishes 8 APIs on the APIs.io network, including ACL Rules API, Authentication API, Reports API, and 5 more. Tagged areas include Proxy, WAF, Security, Open Source, and Reverse Proxy.

The SafeLine catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

SafeLine’s developer surface includes authentication, documentation, and 14 more developer resources.

46.7/100 developing ▼ -5.4 Agent 31/100 agent aware Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
9 APIs
ProxyWAFSecurityOpen SourceReverse ProxyAPI Gateway

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 46.7/100 · developing
Contract Quality 15.4 / 25
Developer Ergonomics 3.9 / 20
Commercial Clarity 7.9 / 20
Operational Transparency 4.8 / 13
Governance 8.3 / 12
Discoverability 6.5 / 10
Agent readiness — 31/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/safeline: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 9

Individual APIs this provider publishes, each with its own machine-readable definition.

SafeLine MCP Server

SafeLine provides two MCP (Model Context Protocol) Server implementations for AI-assisted WAF management: a Python MCP Server for tool-based API management and a Go MCP Server f...

SafeLine ACL Rules API

Access control list rules for blocking and allowing traffic

SafeLine Authentication API

Login and session management

SafeLine Reports API

Security report generation and retrieval

SafeLine Security Policies API

Security policy and rule group management

SafeLine SSL Certificates API

SSL/TLS certificate management

SafeLine System API

System configuration and administration

SafeLine Users API

User account and permission management

SafeLine Websites API

Protected website (application) management

Scroll for all 9

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

SafeLine Management API

OPEN COLLECTION

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Safeline Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Safeline Context

26 classes · 0 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

SafeLine API Rules

5 rules · 4 warnings 1 info

SPECTRAL

SafeLine API Rules

8 rules · 2 errors 3 warnings 3 info

SPECTRAL

JSON Schema 2

Standalone JSON Schema definitions for this provider's data models.

SafeLine ACL Rule

6 properties

JSON SCHEMA

SafeLine Protected Website

9 properties

JSON SCHEMA

JSON Structure 2

JSON Structure definitions describing this provider's data shapes.

Safeline Acl Rule Structure

0 properties

JSON STRUCTURE

Safeline Website Structure

0 properties

JSON STRUCTURE

Examples 3

Example request and response payloads for these APIs.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Safeline Authentication

apiKey · 1 scheme

SECURITY

Safeline Domain Security

TLSv1.3 · DMARC

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Safeline Agentic Access

30 operations · 18 acting · 1 human-in-the-loop

30 operations · 18 acting

AGENTIC

Resources

Get Started 1

Portal, sign-up, and the first successful call

Documentation 4

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 5

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Company 1

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: safeline
name: SafeLine
description: SafeLine is an open-source self-hosted Web Application Firewall (WAF) and reverse proxy developed by Chaitin
  Technology that protects web applications and APIs from attacks including SQL injection, XSS, code injection, OS command
  injection, SSRF, path traversal, and RCE. With over 180,000 installations protecting more than 1 million websites, SafeLine
  handles over 30 billion HTTP requests daily. It provides rate limiting, anti-bot defenses, dynamic code protection, and
  integrates with API gateways including Apache APISIX and Kong. SafeLine exposes a management API on port 9443 and supports
  MCP server implementations for AI-assisted management.
type: Index
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/safeline.png
tags:
- Proxy
- WAF
- Security
- Open Source
- Reverse Proxy
- API Gateway
url: https://raw.githubusercontent.com/api-evangelist/safeline/refs/heads/main/apis.yml
created: '2026-03-27'
modified: '2026-05-19'
specificationVersion: '0.19'
apis:
- aid: safeline:mcp-server
  name: SafeLine MCP Server
  description: 'SafeLine provides two MCP (Model Context Protocol) Server implementations for AI-assisted WAF management:
    a Python MCP Server for tool-based API management and a Go MCP Server for high-performance management. These servers expose
    tools for application management, security rule configuration, and attack event analysis.'
  humanURL: https://github.com/chaitin/SafeLine
  tags:
  - WAF
  - MCP
  - AI
  - Security
  properties:
  - type: GitHubRepository
    url: https://github.com/chaitin/SafeLine
- aid: safeline:safeline-acl-rules-api
  name: SafeLine ACL Rules API
  description: Access control list rules for blocking and allowing traffic
  humanURL: https://waf.chaitin.com/
  tags:
  - ACL Rules
  properties:
  - type: OpenAPI
    url: openapi/safeline-acl-rules-api-openapi.yml
  - type: Documentation
    url: https://docs.waf.chaitin.com/
  - type: GettingStarted
    url: https://docs.waf.chaitin.com/en/getting-started
  - type: GitHubRepository
    url: https://github.com/chaitin/SafeLine
- aid: safeline:safeline-authentication-api
  name: SafeLine Authentication API
  description: Login and session management
  humanURL: https://waf.chaitin.com/
  tags:
  - Authentication
  properties:
  - type: OpenAPI
    url: openapi/safeline-authentication-api-openapi.yml
  - type: Documentation
    url: https://docs.waf.chaitin.com/
  - type: GettingStarted
    url: https://docs.waf.chaitin.com/en/getting-started
  - type: GitHubRepository
    url: https://github.com/chaitin/SafeLine
- aid: safeline:safeline-reports-api
  name: SafeLine Reports API
  description: Security report generation and retrieval
  humanURL: https://waf.chaitin.com/
  tags:
  - Reports
  properties:
  - type: OpenAPI
    url: openapi/safeline-reports-api-openapi.yml
  - type: Documentation
    url: https://docs.waf.chaitin.com/
  - type: GettingStarted
    url: https://docs.waf.chaitin.com/en/getting-started
  - type: GitHubRepository
    url: https://github.com/chaitin/SafeLine
- aid: safeline:safeline-security-policies-api
  name: SafeLine Security Policies API
  description: Security policy and rule group management
  humanURL: https://waf.chaitin.com/
  tags:
  - Security Policies
  properties:
  - type: OpenAPI
    url: openapi/safeline-security-policies-api-openapi.yml
  - type: Documentation
    url: https://docs.waf.chaitin.com/
  - type: GettingStarted
    url: https://docs.waf.chaitin.com/en/getting-started
  - type: GitHubRepository
    url: https://github.com/chaitin/SafeLine
- aid: safeline:safeline-ssl-certificates-api
  name: SafeLine SSL Certificates API
  description: SSL/TLS certificate management
  humanURL: https://waf.chaitin.com/
  tags:
  - SSL Certificates
  properties:
  - type: OpenAPI
    url: openapi/safeline-ssl-certificates-api-openapi.yml
  - type: Documentation
    url: https://docs.waf.chaitin.com/
  - type: GettingStarted
    url: https://docs.waf.chaitin.com/en/getting-started
  - type: GitHubRepository
    url: https://github.com/chaitin/SafeLine
- aid: safeline:safeline-system-api
  name: SafeLine System API
  description: System configuration and administration
  humanURL: https://waf.chaitin.com/
  tags:
  - System
  properties:
  - type: OpenAPI
    url: openapi/safeline-system-api-openapi.yml
  - type: Documentation
    url: https://docs.waf.chaitin.com/
  - type: GettingStarted
    url: https://docs.waf.chaitin.com/en/getting-started
  - type: GitHubRepository
    url: https://github.com/chaitin/SafeLine
- aid: safeline:safeline-users-api
  name: SafeLine Users API
  description: User account and permission management
  humanURL: https://waf.chaitin.com/
  tags:
  - Users
  properties:
  - type: OpenAPI
    url: openapi/safeline-users-api-openapi.yml
  - type: Documentation
    url: https://docs.waf.chaitin.com/
  - type: GettingStarted
    url: https://docs.waf.chaitin.com/en/getting-started
  - type: GitHubRepository
    url: https://github.com/chaitin/SafeLine
- aid: safeline:safeline-websites-api
  name: SafeLine Websites API
  description: Protected website (application) management
  humanURL: https://waf.chaitin.com/
  tags:
  - Websites
  properties:
  - type: OpenAPI
    url: openapi/safeline-websites-api-openapi.yml
  - type: Documentation
    url: https://docs.waf.chaitin.com/
  - type: GettingStarted
    url: https://docs.waf.chaitin.com/en/getting-started
  - type: GitHubRepository
    url: https://github.com/chaitin/SafeLine
common:
- type: AgenticAccess
  url: agentic-access/safeline-agentic-access.yml
- type: DomainSecurity
  url: security/safeline-domain-security.yml
- type: Authentication
  url: authentication/safeline-authentication.yml
- type: Website
  url: https://waf.chaitin.com/
- type: Documentation
  url: https://docs.waf.chaitin.com/
- type: GitHubOrganization
  url: https://github.com/chaitin/SafeLine
- type: Demo
  url: https://demo.waf.chaitin.com/
- type: OpenAPI
  url: openapi/safeline-management-openapi.yml
- type: SpectralRules
  url: rules/safeline-rules.yml
- type: JSONSchema
  url: json-schema/safeline-website-schema.json
- type: JSONSchema
  url: json-schema/safeline-acl-rule-schema.json
- type: JSONStructure
  url: json-structure/safeline-website-structure.json
- type: JSONStructure
  url: json-structure/safeline-acl-rule-structure.json
- type: JSONLDContext
  url: json-ld/safeline-context.jsonld
- type: Vocabulary
  url: vocabulary/safeline-vocabulary.yml
- type: Capabilities
  url: capabilities/waf-protection-management.yaml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com