# SPIRE

**Canonical:** https://apis.io/providers/spire/  
**Website:** https://spiffe.io/  
**APIs profiled:** 5

SPIRE (SPIFFE Runtime Environment) is the reference implementation of the SPIFFE standard, providing a toolchain for establishing trust between software systems across a wide variety of hosting platforms through automated attestation and workload identity distribution. SPIRE manages a certificate authority, performs node and workload attestation, and issues SVIDs to workloads through the SPIFFE Workload API.

## Kin Score — 36.8 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 36.8).

| Facet | Score |
|---|---|
| Discoverability | 72.2 |
| Contract Quality | 65.7 |
| Governance | 26.5 |
| Contract Governance | 26.5 |
| Operational Transparency | 36.8 |
| Developer Ergonomics | 26.2 |
| Commercial Clarity | 0.0 |
| Access Clarity | 0.0 |

## Agent readiness — 26.0 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | na |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | na |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | derived |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | na |

## Access

Freemium — onboarding: unknown, pricing: freemium, trial: no (confidence: medium).

## APIs (5)

- **SPIRE Workload API** — The SPIRE Agent exposes the SPIFFE Workload API as a Unix domain socket, allowing workloads running on the same node to request their X.509-SVIDs and JWT-SVIDs without requiring...
- **SPIRE Server API** — The SPIRE Server exposes a gRPC API used by administrators and the SPIRE Agent to manage registration entries, node attestation, bundle federation, and server health. It allows ...
- **SPIRE Discovery API** — OpenID Connect discovery document endpoint that describes the OIDC provider configuration and supported capabilities.
- **SPIRE Health API** — Liveness and readiness health check endpoints for SPIRE Server and SPIRE Agent components, suitable for use as Kubernetes probes.
- **SPIRE Keys API** — JSON Web Key Set endpoint that exposes public keys used to verify JWT-SVIDs issued by SPIRE.

## Agentic access (1)

- **Spire Agentic Access** — 4 operations

## Security (1)

- **Spire Domain Security** — TLSv1.3 · HSTS

## Plans (1)

- **Spire Plans Pricing**

## Tags

Authentication, Cloud-Native, Graduated, Identity, Security, Zero Trust

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/spire/). Scores are computed from the provider's own public artifacts under a published rubric.
