# Spyderbat

**Canonical:** https://apis.io/providers/spyderbat/  
**Website:** https://spyderbat.com/  
**APIs profiled:** 2

Spyderbat is an Austin, Texas cloud-native runtime security company whose platform delivers cloud detection and response (CDR) for Linux servers, containers and Kubernetes. A lightweight eBPF-based Nano Agent captures kernel-level process, connection, container and Kubernetes activity and streams it into Spyderbat's causal-graph backend, where Spydertraces link related processes, network connections and red flags into scored, attack-path units that analysts can replay at any point in the past. The platform spans Scout (behavioral detection and custom flags), Flashback (time-travel investigations), Guardian (workload and ruleset policies that lock down critical workloads), suppression, notifications, dashboards and SIEM forwarding. Everything the console does is backed by a public REST API at api.prod.spyderbat.com, documented by a published OpenAPI 3.0.1 contract of 197 operations across 30 resource groups, authenticated with a bearer API key bound to an RBAC role. Spyderbat also ships a remote Model Context Protocol server, the open-source spyctl CLI, spydertop, and an event forwarder for SIEM integration.

## Kin Score — 43.1 / 100 (developing)

Scored 2026-09-01 under rubric 0.17.2. Trend: flat (+0.0 from 43.1).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 61.9 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 61.9 |
| Commercial Clarity | 10.5 |
| Access Clarity | 10.5 |

## Agent readiness — 35.1 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | yes |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## APIs (29)

- **Spyderbat Adhoc Search API** — Ad-hoc Search interface for complex queries
- **Spyderbat Agent Action API** — Agent Action defines actions that can be executed on remote agents in response to events.
- **Spyderbat Agent API** — Agents represent a sepecific agent which collects data for one or more sources.
- **Spyderbat Agent Registration API** — Agents registrations are used to authorize and group agents by the registration.
- **Spyderbat Agent Work API** — AgentWork API is intended for use by the UI to convey work & configuration to agents, this data can be specific to an agent or gloal to an organization. An example use case is c...
- **Spyderbat Analytics Policy API** — An API to allow management of the organizations analytics policies. These will be used throughout the system to take various actions.
- **Spyderbat Analytics Ruleset API** — An API to allow the management of analytics rulesets. Analytics rulesets are used within some types of analytics rulesets.
- **Spyderbat Archive API** — Access to raw agent archive data.
- **Spyderbat Cases API** — Cases management API
- **Spyderbat Cluster API** — Cluster represents known clusters, such as Kubernetes clusters running an appropriate agent.
- **Spyderbat Custom Flag API** — An API to allow the management of custom flags. Custom flags allow users to define custom detections within Spyderbat.
- **Spyderbat Fingerprint Data API** — Each source may send fingerprint data which is stored and processed by the system.
- **Spyderbat Forwarded Events API** — An API to allow retrieval of observations for a SIEM.
- **Spyderbat Investigation API** — Investigations can be created by users as a way to have an investigation into a potential attack, allowing users to associate data from one or more sources into a single investi...
- **Spyderbat Notifications API** — An API for retrieving, enabling, and disabling notification settings.
- **Spyderbat Notifications Agent Health API** — An API for creating, retrieving, updating, and deleting agent health notification settings.
- **Spyderbat Notification Target API** — An API to allow the management of notification targets. Notification targets allow users to define where notifications are sent.
- **Spyderbat Notification Template API** — An API to allow the management of notification templates. Notification templates allow users to define custom notifications within Spyderbat.
- **Spyderbat Org API** — Organizations hold resources & data associated with an organization, users must be associated via roles with an organization to have permissions to interact with the organizatio...
- **Spyderbat Org Type API** — Organizational types specify both limits and defaults for organizations, they are used by the system to determine the resource utilization for an organization and associated set...
- **Spyderbat RBAC API** — # Introduction This RBAC model is based off of Amazon's model with some simplifications and generic assumptions A user has some number of roles on some number of organizations, ...
- **Spyderbat Saved Query API** — An API to allow the management of saved queries. Saved queries are used to quickly run Athena searches.
- **Spyderbat Search Set API** — An API to allow the management of search sets. Search sets can be used to augment queries in search.
- **Spyderbat Source API** — Sources are used to represent a container for source of security data, such as a machine, or other potential source. The source itself has data associated with the source, see t...
- **Spyderbat Source Data API** — Each source may send data which is stored and processed by the system. So for example a machine will send data in a raw form which is then analyzed, both the raw machine data an...
- **Spyderbat Spyctl API** — A way to execute specific Spyctl logic via the API.
- **Spyderbat STS API** — Security Token Service endpoints. Trusted services assume a role on a single org and receive a short-lived, org-locked JWT for downstream consumers. The caller's authority to as...
- **Spyderbat Suppress API** — An API that provides direct access to Spyderbat's tuning features.
- **Spyderbat Watchlist API** — An API to manage the watchlist for files within an organization.

## MCP servers (1)

- **Spyderbat MCP Server** — A first-party, provider-hosted Model Context Protocol server that exposes Spyderbat's search, investigation and management surface to MCP-compatible AI clients. Documented and s...

## Security (2)

- **Spyderbat Authentication** — http · 1 scheme
- **Spyderbat Domain Security** — TLSv1.3 · HSTS · DMARC

## Plans (1)

- **Spyderbat Plans Pricing**

## Tags

Company, Security, Cloud Security, Runtime Security, Cloud Detection and Response, Kubernetes, Containers, eBPF, Linux, Observability, Threat Detection, Incident Response, DevSecOps, SIEM, Monitoring

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/spyderbat/). Scores are computed from the provider's own public artifacts under a published rubric.
