SmallStep
Smallstep operates the world's first Device Identity Platform. It issues hardware-backed, short-lived X.509 and SSH certificates that cryptographically prove what is acting and from where — for devices, humans, workloads, AI agents, and MCP toolchains. Smallstep co-developed ACME Device Attestation (ACME DA) with Google through the IETF, using TPM and Secure Enclave co-processors to bind non-exportable credentials to specific devices at issuance. Its OpenAPI-conformant Platform API (gateway.smallstep.com) manages device inventory, PKI (certificate authorities and provisioners), certificate issuance and revocation, credentials, and protected resources such as Wi-Fi, VPN, and SSO. Smallstep also maintains the widely used open-source step CLI and step-ca certificate authority.
SmallStep publishes 6 APIs on the APIs.io network, including Authentication API, Certificates API, Credentials API, and 3 more. Tagged areas include Company, Developer Tools, Certificate Authority, PKI, and Device Identity.
The SmallStep catalog on APIs.io includes 1 event-driven AsyncAPI specification.
SmallStep’s developer surface includes documentation, API reference, getting-started guide, engineering blog, support, pricing, authentication, and 26 more developer resources.
Kin Score
APIs 6
Individual APIs this provider publishes, each with its own machine-readable definition.
SmallStep Authentication API
Create API tokens
SmallStep Certificates API
Query certificates and their statuses issued by authorities
SmallStep Credentials API
Manage credentials
SmallStep Device Inventory API
Manage your device inventory
SmallStep PKI Architecture API
Manage certificate authorities and provisioners
SmallStep Protect API
Manage access to protected resources
Event Specifications 1
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Smallstep Webhooks
ASYNCAPISecurity Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 3
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 5
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 6
Pagination, idempotency, versioning, errors, and events
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 5
Authentication, authorization, and security posture
Operate 3
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API