Threat Stack

Threat Stack was a Boston-based cloud security company providing full-stack cloud security observability, intrusion detection, and compliance monitoring for infrastructure and applications across cloud-native workloads including virtual machines, containers, and Kubernetes. Its platform combined rules and supervised machine learning to detect threats, vulnerabilities, and attacks in real time. Threat Stack exposed a RESTful V2 API (HAWK/HMAC authenticated) and trigger-based webhook alerts, along with first-party SDKs, a Go CLI, and configuration-management modules (Chef, Ansible, Puppet, Terraform, CloudFormation, Helm). The company was acquired by F5 in 2021 and the product is now F5 Distributed Cloud App Infrastructure Protection (AIP); the original threatstack.com and api.threatstack.com domains have been decommissioned.

Threat Stack is profiled on the APIs.io network. Tagged areas include Company, Security, Cloud Security, Cloud Monitoring, and Intrusion Detection.

Threat Stack’s developer surface includes documentation, API reference, authentication, CLI, and 5 more developer resources.

15.3/100 emerging ▬ flat Agent 10/100 human only Full breakdown ↓
scored 2026-07-27 · rubric v0.5
AccessSelf serve
0 APIs
CompanySecurityCloud SecurityCloud MonitoringIntrusion DetectionComplianceObservabilityDevSecOpsContainersKubernetes

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 15.3/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 7.8 / 20
Commercial Clarity 0.0 / 20
Operational Transparency 0.7 / 13
Governance 0.0 / 12
Discoverability 6.8 / 10
Agent readiness — 10/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/threat-stack: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Threat Stack Authentication

hawk · 1 scheme

SECURITY

Resources

Documentation 2

Reference material describing how the API behaves

Build 4

SDKs, sample code, and the tooling you integrate with

Access & Security 1

Authentication, authorization, and security posture

Company 1

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: threat-stack
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: medium
  source:
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/threat-stack.png
name: Threat Stack
description: Threat Stack was a Boston-based cloud security company providing full-stack cloud security observability, intrusion
  detection, and compliance monitoring for infrastructure and applications across cloud-native workloads including virtual
  machines, containers, and Kubernetes. Its platform combined rules and supervised machine learning to detect threats, vulnerabilities,
  and attacks in real time. Threat Stack exposed a RESTful V2 API (HAWK/HMAC authenticated) and trigger-based webhook alerts,
  along with first-party SDKs, a Go CLI, and configuration-management modules (Chef, Ansible, Puppet, Terraform, CloudFormation,
  Helm). The company was acquired by F5 in 2021 and the product is now F5 Distributed Cloud App Infrastructure Protection
  (AIP); the original threatstack.com and api.threatstack.com domains have been decommissioned.
url: https://raw.githubusercontent.com/api-evangelist/threat-stack/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- techstars
x-tier: stub
x-tier-reason: portfolio-lead
x-status: acquired
x-acquired-by: f5
x-successor: F5 Distributed Cloud App Infrastructure Protection (AIP)
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-21'
tags:
- Company
- Security
- Cloud Security
- Cloud Monitoring
- Intrusion Detection
- Compliance
- Observability
- DevSecOps
- Containers
- Kubernetes
apis: []
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://www.f5.com/glossary/threat-stack
- type: ProductPage
  url: https://www.f5.com/products/distributed-cloud-services
- type: Documentation
  url: https://clouddocs.f5.com/training/community/threat-stack/html/class2/Threat_Stack_API.html
- type: APIReference
  url: https://clouddocs.f5.com/training/community/threat-stack/html/class2/Threat_Stack_API.html
- type: GitHubOrganization
  url: https://github.com/threatstack
- type: Authentication
  url: authentication/threat-stack-authentication.yml
- type: Packages
  url: packages/threat-stack-packages.yml
- type: SDKs
  url: packages/threat-stack-packages.yml
- type: CLI
  url: cli/threat-stack-cli.yml
x-enrichment:
  date: '2026-07-21'
  status: enriched
  artifacts_added: 3
  pass: local-v1