StackHawk website screenshot

StackHawk

StackHawk is an application and API security testing platform that helps engineering teams find, triage, and fix security vulnerabilities in their APIs and web applications. It provides Dynamic Application Security Testing (DAST) with deep OpenAPI spec integration, CI/CD pipeline automation, AI-powered spec generation, and an AppSec Intelligence platform for program-level visibility across the software development lifecycle.

StackHawk publishes 14 APIs on the APIs.io network, including Api Authentication API, Applications API, Global Configuration API, and 11 more. Tagged areas include API Security, Application Security, DAST, Security Testing, and Vulnerability Management.

The StackHawk catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

StackHawk’s developer surface includes authentication, documentation, API reference, getting-started guide, engineering blog, changelog, pricing, and 10 more developer resources.

60.8/100 strong ▬ flat Agent 31/100 agent aware Full breakdown ↓
scored 2026-08-05 · rubric v0.9.1
AccessFreemiumSelf serve⚡ Free to try
14 APIs
API SecurityApplication SecurityDASTSecurity TestingVulnerability Management

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-05 · rubric v0.9.1
Composite quality — 60.8/100 · strong
Contract Quality 16.7 / 25
Developer Ergonomics 8.7 / 20
Commercial Clarity 14.2 / 20
Operational Transparency 6.8 / 13
Governance 7.0 / 12
Discoverability 7.4 / 10
Agent readiness — 31/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/stackhawk: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 14

Individual APIs this provider publishes, each with its own machine-readable definition.

StackHawk Api Authentication API

Token management and login

StackHawk Applications API

Manage applications and environments

StackHawk Global Configuration API

Organization-level configurations

StackHawk Hosted OAS API

OpenAPI spec uploads and mapping

StackHawk Organization Teams API

Team creation and member assignment

StackHawk Organizations API

Member management and audit logs

StackHawk Perch API

Scan command control

StackHawk Profile Scans API

Profile scan analysis

StackHawk Reports API

Scan report generation

StackHawk Repositories API

Repository management

StackHawk Scan Configuration API

Scan configuration file management

StackHawk Scan Policies API

Security policy management

StackHawk Scan Results API

Scan result reporting and findings

StackHawk User API

Authenticated user information

Scroll for all 14

Postman Collections 14

Ready-to-run Postman collections for exercising this provider's APIs.

Scroll for all 14

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

StackHawk API

OPEN COLLECTION

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Stackhawk Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Stackhawk Context

9 classes · 4 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

StackHawk API Rules

5 rules · 3 warnings 2 info

SPECTRAL

StackHawk API Rules

7 rules · 3 errors 4 warnings

SPECTRAL

JSON Schema 2

Standalone JSON Schema definitions for this provider's data models.

StackHawk Security Finding

7 properties

JSON SCHEMA

StackHawk Scan

7 properties

JSON SCHEMA

JSON Structure 1

JSON Structure definitions describing this provider's data shapes.

Stackhawk Scan Structure

0 properties

JSON STRUCTURE

Examples 1

Example request and response payloads for these APIs.

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Stackhawk Authentication

http · 1 scheme

SECURITY

Stackhawk Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Stackhawk Vulnerability Disclosure

security.txt · contact published

SECURITY

Stackhawk Trust Center

SOC 2

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Stackhawk Agentic Access

54 operations · 25 acting

54 operations · 25 acting

AGENTIC

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 1

Status, limits, changes, and where to get help

Commercial 1

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: stackhawk
name: StackHawk
description: StackHawk is an application and API security testing platform that helps engineering teams find, triage, and
  fix security vulnerabilities in their APIs and web applications. It provides Dynamic Application Security Testing (DAST)
  with deep OpenAPI spec integration, CI/CD pipeline automation, AI-powered spec generation, and an AppSec Intelligence platform
  for program-level visibility across the software development lifecycle.
url: https://raw.githubusercontent.com/api-evangelist/stackhawk/refs/heads/main/apis.yml
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/stackhawk.png
tags:
- API Security
- Application Security
- DAST
- Security Testing
- Vulnerability Management
type: Index
access: 3rd-Party
created: '2025-01-08'
modified: '2026-05-19'
specificationVersion: '0.19'
apis:
- aid: stackhawk:stackhawk-api-authentication-api
  name: StackHawk Api Authentication API
  description: Token management and login
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - Api Authentication
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-api-authentication-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
- aid: stackhawk:stackhawk-applications-api
  name: StackHawk Applications API
  description: Manage applications and environments
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - Applications
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-applications-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
- aid: stackhawk:stackhawk-global-configuration-api
  name: StackHawk Global Configuration API
  description: Organization-level configurations
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - Global Configuration
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-global-configuration-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
- aid: stackhawk:stackhawk-hosted-oas-api
  name: StackHawk Hosted OAS API
  description: OpenAPI spec uploads and mapping
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - Hosted OAS
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-hosted-oas-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
- aid: stackhawk:stackhawk-organization-teams-api
  name: StackHawk Organization Teams API
  description: Team creation and member assignment
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - Organization Teams
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-organization-teams-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
- aid: stackhawk:stackhawk-organizations-api
  name: StackHawk Organizations API
  description: Member management and audit logs
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - Organizations
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-organizations-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
- aid: stackhawk:stackhawk-perch-api
  name: StackHawk Perch API
  description: Scan command control
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - Perch
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-perch-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
- aid: stackhawk:stackhawk-profile-scans-api
  name: StackHawk Profile Scans API
  description: Profile scan analysis
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - Profile Scans
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-profile-scans-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
- aid: stackhawk:stackhawk-reports-api
  name: StackHawk Reports API
  description: Scan report generation
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - Reports
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-reports-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
- aid: stackhawk:stackhawk-repositories-api
  name: StackHawk Repositories API
  description: Repository management
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - Repositories
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-repositories-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
- aid: stackhawk:stackhawk-scan-configuration-api
  name: StackHawk Scan Configuration API
  description: Scan configuration file management
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - Scan Configuration
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-scan-configuration-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
- aid: stackhawk:stackhawk-scan-policies-api
  name: StackHawk Scan Policies API
  description: Security policy management
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - Scan Policies
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-scan-policies-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
- aid: stackhawk:stackhawk-scan-results-api
  name: StackHawk Scan Results API
  description: Scan result reporting and findings
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - Scan Results
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-scan-results-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
- aid: stackhawk:stackhawk-user-api
  name: StackHawk User API
  description: Authenticated user information
  humanURL: https://apidocs.stackhawk.com/docs
  baseURL: https://api.stackhawk.com
  tags:
  - User
  properties:
  - type: OpenAPI
    url: openapi/stackhawk-user-api-openapi.yml
  - type: Documentation
    url: https://apidocs.stackhawk.com/docs
common:
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/stackhawk/overview
- type: AgenticAccess
  url: agentic-access/stackhawk-agentic-access.yml
- type: TrustCenter
  url: security/stackhawk-trust-center.yml
- type: VulnerabilityDisclosure
  url: security/stackhawk-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/stackhawk-domain-security.yml
- type: Authentication
  url: authentication/stackhawk-authentication.yml
- type: GitHubOrganization
  url: https://github.com/stackhawk
- type: LinkedIn
  url: https://www.linkedin.com/company/stackhawk
- type: Website
  url: https://www.stackhawk.com/
  name: StackHawk Website
- type: Documentation
  url: https://docs.stackhawk.com/
  name: StackHawk Documentation
- type: APIReference
  url: https://apidocs.stackhawk.com/docs
  name: API Reference
- type: GettingStarted
  url: https://docs.stackhawk.com/
  name: Getting Started
- type: Blog
  url: https://www.stackhawk.com/blog/
  name: StackHawk Blog
- type: ChangeLog
  url: https://docs.stackhawk.com/changelog.html
  name: Changelog
- type: Pricing
  url: https://www.stackhawk.com/pricing/
  name: Pricing
- type: Login
  url: https://app.stackhawk.com/
  name: StackHawk App
- type: LlmsText
  url: https://docs.stackhawk.com/llms.txt
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com