# Scanner

**Canonical:** https://apis.io/providers/scanner/  
**Website:** https://scanner.dev/  
**APIs profiled:** 6

Scanner is a cloud-native security data platform that indexes security logs directly in Amazon S3 to deliver full-text search across petabytes, continuous streaming threat detection, and programmatic and agent-native access to security data — an alternative to traditional SIEMs and data lakes. Its REST API (v1) covers searchable indexes, detection rules, event sinks, lookup tables, ad hoc queries, and query-capacity info, and it ships a hosted Model Context Protocol (MCP) server plus a detection-rules-as-code CLI (scanner-cli). Authentication is a Scanner API key presented as an HTTP Bearer token; console SSO is brokered by Stytch (Okta, Google Workspace, Microsoft Entra, SCIM). SOC 2 Type II certified and GDPR compliant. Backed by CRV.

## Kin Score — 41.7 / 100 (developing)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 41.7).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 26.8 |
| Governance | 30.3 |
| Contract Governance | 30.3 |
| Operational Transparency | 23.7 |
| Developer Ergonomics | 61.3 |
| Commercial Clarity | 39.5 |
| Access Clarity | 39.5 |

## Agent readiness — 40.7 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | documented |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (6)

- **Scanner Ad Hoc Queries API** — Run asynchronous or blocking full-text queries over indexed logs.
- **Scanner Detection Rules API** — Create, list, update, and delete streaming detection rules.
- **Scanner Event Sinks API** — Manage alert destinations (Slack, Webhook, PagerDuty).
- **Scanner Indexes API** — List and retrieve searchable indexes for a tenant.
- **Scanner Info API** — Account and query-capacity metrics.
- **Scanner Lookup Tables API** — Upload, manage, and download lookup table files for enrichment.

## MCP servers (1)

- **Scanner MCP Server**

## Agentic access (1)

- **Scanner Agentic Access** — 25 operations · 13 acting

## Security (3)

- **Scanner Authentication** — http · 1 scheme
- **Scanner Domain Security** — TLSv1.3 · HSTS · DMARC
- **Scanner Trust Center** — SOC 2 Type II, GDPR

## Tags

Company, Security, SIEM, Log Analytics, Threat Detection, Security Operations, Observability, MCP

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/scanner/). Scores are computed from the provider's own public artifacts under a published rubric.
