# Spring Security

**Canonical:** https://apis.io/providers/spring-security/  
**Website:** https://spring.io/projects/spring-security  
**APIs profiled:** 12

Spring Security is a powerful and highly customizable authentication and access-control framework for Java applications. It is the de-facto standard for securing Spring-based applications, providing comprehensive security services including authentication, authorization, protection against common exploits (CSRF, session fixation, clickjacking), OAuth 2.0, OpenID Connect, SAML 2.0, LDAP, and WebFlux reactive security.

## Kin Score — 30.3 / 100 (thin)

Scored 2026-08-25 under rubric 0.14.0. Trend: flat (+0.0 from 30.3).

| Facet | Score |
|---|---|
| Discoverability | 72.2 |
| Contract Quality | 52.9 |
| Governance | 13.6 |
| Contract Governance | 13.6 |
| Operational Transparency | 21.1 |
| Developer Ergonomics | 14.3 |
| Commercial Clarity | 13.2 |
| Access Clarity | 13.2 |

## Agent readiness — 19.8 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Enterprise · Open access — onboarding: open, pricing: enterprise, trial: no (confidence: high).

## APIs (12)

- **Spring Security Core** — Core security features for authentication and authorization. Provides UserDetailsService, password encoding, security context management, method security, and HTTP security conf...
- **Spring Security SAML2** — SAML 2.0 Service Provider support for Spring Security. Enables SSO integration with SAML identity providers, handling authentication requests, assertions, and SLO (Single Logout).
- **Spring Security LDAP** — LDAP authentication and authorization support for Spring Security. Supports LDAP bind authentication, password comparison, and user details loading from directory services.
- **Spring Security WebFlux** — Reactive security for Spring WebFlux applications. Provides non-blocking authentication, authorization, OAuth2 reactive client support, and CSRF protection for reactive web stacks.
- **Spring Security Authorization API** — The Authorization API from Spring Security — 1 operation(s) for authorization.
- **Spring Security Client Management API** — The Client Management API from Spring Security — 1 operation(s) for client management.
- **Spring Security Device API** — The Device API from Spring Security — 1 operation(s) for device.
- **Spring Security Discovery API** — The Discovery API from Spring Security — 2 operation(s) for discovery.
- **Spring Security Keys API** — The Keys API from Spring Security — 1 operation(s) for keys.
- **Spring Security OpenID Connect API** — The OpenID Connect API from Spring Security — 2 operation(s) for openid connect.
- **Spring Security Session API** — The Session API from Spring Security — 2 operation(s) for session.
- **Spring Security Token API** — The Token API from Spring Security — 3 operation(s) for token.

## Agentic access (1)

- **Spring Security Agentic Access** — 23 operations · 11 acting · 2 human-in-the-loop

## Security (3)

- **Spring Security Authentication** — http · 2 schemes
- **Spring Security Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Spring Security Vulnerability Disclosure** — security.txt · contact published

## Plans (1)

- **Spring Security Plans Pricing**

## Tags

Authentication, Authorization, Java, JWT, OpenID Connect, SAML, Security, Spring Framework

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/spring-security/). Scores are computed from the provider's own public artifacts under a published rubric.
