# SmallStep

**Canonical:** https://apis.io/providers/smallstep/  
**Website:** http://www.smallstep.com  
**APIs profiled:** 6

Smallstep operates the world's first Device Identity Platform. It issues hardware-backed, short-lived X.509 and SSH certificates that cryptographically prove what is acting and from where — for devices, humans, workloads, AI agents, and MCP toolchains. Smallstep co-developed ACME Device Attestation (ACME DA) with Google through the IETF, using TPM and Secure Enclave co-processors to bind non-exportable credentials to specific devices at issuance. Its OpenAPI-conformant Platform API (gateway.smallstep.com) manages device inventory, PKI (certificate authorities and provisioners), certificate issuance and revocation, credentials, and protected resources such as Wi-Fi, VPN, and SSO. Smallstep also maintains the widely used open-source step CLI and step-ca certificate authority.

## Kin Score — 56.9 / 100 (strong)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 56.9).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 71.6 |
| Governance | 11.5 |
| Operational Transparency | 55.3 |
| Developer Ergonomics | 66.8 |
| Commercial Clarity | 44.7 |

## Agent readiness — 40.3 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (6)

- **SmallStep Authentication API** — Create API tokens
- **SmallStep Certificates API** — Query certificates and their statuses issued by authorities
- **SmallStep Credentials API** — Manage credentials
- **SmallStep Device Inventory API** — Manage your device inventory
- **SmallStep PKI Architecture API** — Manage certificate authorities and provisioners
- **SmallStep Protect API** — Manage access to protected resources

## Agentic access (1)

- **Smallstep Agentic Access** — 74 operations · 44 acting · 1 human-in-the-loop

## Security (3)

- **Smallstep Authentication** — http/mutualTLS · 2 schemes
- **Smallstep Domain Security** — TLSv1.3 · HSTS · DMARC
- **Smallstep Vulnerability Disclosure** — security.txt · contact published

## Tags

Company, Developer Tools, Certificate Authority, PKI, Device Identity, Zero Trust, Certificate Management, mTLS, ACME, SSH, Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/smallstep/). Scores are computed from the provider's own public artifacts under a published rubric.
