# Splunk SOAR

**Canonical:** https://apis.io/providers/splunk-soar/  
**Website:** https://help.splunk.com/en/splunk-soar/soar-cloud  
**APIs profiled:** 1

Splunk SOAR, built on the Phantom platform Splunk acquired in 2018 and now part of Cisco through the 2024 Splunk acquisition, is a security orchestration, automation and response platform. It runs playbooks across hundreds of connected security tools, and exposes a REST API for containers, artifacts, playbooks, actions, assets, indicators, evidence, vault files, workbooks and case management, served from each customer's own tenant at https://{soar-host}/rest/ rather than a shared API host. Authentication is HTTP Basic or a ph-auth-token automation token. Splunk publishes a documented app/connector SDK on PyPI with the soarapps CLI, a first-party VS Code extension, and 529 open connector repositories, but no anonymously fetchable OpenAPI document, no MCP server for SOAR, and no published rate limits or pricing.

## Kin Score — 44.5 / 100 (developing)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 44.5).

| Facet | Score |
|---|---|
| Discoverability | 87.0 |
| Contract Quality | 0.0 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 55.3 |
| Developer Ergonomics | 71.4 |
| Commercial Clarity | 60.5 |
| Access Clarity | 60.5 |

## Agent readiness — 17.5 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## APIs (1)

- **Splunk SOAR REST API** — The Splunk SOAR REST API creates, updates, queries and selectively removes the objects the platform automates against — containers, artifacts, playbooks, action runs, apps, asse...

## Security (4)

- **Splunk Soar Authentication** — http/apiKey · 2 schemes
- **Splunk Soar Domain Security** — TLSv1.3 · HSTS · DMARC
- **Splunk Soar Vulnerability Disclosure** — security.txt · contact published
- **Splunk Soar Trust Center** — SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS, HIPAA, FedRAMP, GDPR, CSA STAR

## Plans (1)

- **Splunk Soar Plans Pricing**

## Tags

Security, SOAR, Automation, Orchestration, Incident Response, SOC, Security Operations, Playbooks, Case Management, Threat Intelligence

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/splunk-soar/). Scores are computed from the provider's own public artifacts under a published rubric.
