# ThreatLocker

**Canonical:** https://apis.io/providers/threatlocker/  
**Website:** https://www.threatlocker.com/  
**APIs profiled:** 18

ThreatLocker is a Zero Trust endpoint and cloud security platform used by enterprises and managed service providers to enforce least privilege across endpoints, networks, and cloud workloads. Its capabilities include Application Control (allowlisting), Ringfencing, Elevation Control, Storage Control, Network Control / ZTNA, Web Content Control, Patch Management, and ThreatLocker Detect (managed detection and response). The multi-tenant ThreatLocker Portal is exposed programmatically through the PortalAPI — a public OpenAPI 3.0 REST contract covering action logs, applications, approval requests, computers and computer groups, maintenance mode, organizations, policies, reports, saved searches, scheduled agent actions, system audit, tags, upload requests, and agent versions. The platform is deployed as regionally isolated instances (A–H plus AE1, AU1, CA1, EU1, SA1 and a FedRAMP instance), so both the portal and the API are addressed per instance.

## Kin Score — 52.6 / 100 (developing)

Scored 2026-08-25 under rubric 0.14.0. Trend: flat (+0.0 from 52.6).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 47.2 |
| Governance | 30.3 |
| Contract Governance | 30.3 |
| Operational Transparency | 39.5 |
| Developer Ergonomics | 58.9 |
| Commercial Clarity | 60.5 |
| Access Clarity | 60.5 |

## Agent readiness — 25.4 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## APIs (18)

- **ThreatLocker Action Log API** — The ActionLog API from ThreatLocker — 9 operation(s) for actionlog.
- **ThreatLocker Application API** — The Application API from ThreatLocker — 6 operation(s) for application.
- **ThreatLocker Approval Request API** — The ApprovalRequest API from ThreatLocker — 12 operation(s) for approvalrequest.
- **ThreatLocker Computer API** — The Computer API from ThreatLocker — 21 operation(s) for computer.
- **ThreatLocker Computer Checkin API** — The ComputerCheckin API from ThreatLocker — 1 operation(s) for computercheckin.
- **ThreatLocker Computer Group API** — The ComputerGroup API from ThreatLocker — 4 operation(s) for computergroup.
- **ThreatLocker Maintenance Mode API** — The MaintenanceMode API from ThreatLocker — 4 operation(s) for maintenancemode.
- **ThreatLocker Online Devices API** — The OnlineDevices API from ThreatLocker — 1 operation(s) for onlinedevices.
- **ThreatLocker Organization API** — The Organization API from ThreatLocker — 3 operation(s) for organization.
- **ThreatLocker Policy API** — The Policy API from ThreatLocker — 1 operation(s) for policy.
- **ThreatLocker Report API** — The Report API from ThreatLocker — 2 operation(s) for report.
- **ThreatLocker Save Search API** — The SaveSearch API from ThreatLocker — 3 operation(s) for savesearch.
- **ThreatLocker Scheduled Agent Action API** — The ScheduledAgentAction API from ThreatLocker — 6 operation(s) for scheduledagentaction.
- **ThreatLocker System Audit API** — The SystemAudit API from ThreatLocker — 3 operation(s) for systemaudit.
- **ThreatLocker Tag API** — The Tag API from ThreatLocker — 3 operation(s) for tag.
- **ThreatLocker Threat Locker Version API** — The ThreatLockerVersion API from ThreatLocker — 1 operation(s) for threatlockerversion.
- **ThreatLocker Upload Request API** — The UploadRequest API from ThreatLocker — 2 operation(s) for uploadrequest.
- **ThreatLocker VDI Hyper V API** — The VDIHyperV API from ThreatLocker — 1 operation(s) for vdihyperv.

## MCP servers (1)

- **ThreatLocker MCP Server** — ThreatLocker publishes NO official or hosted MCP server. This is a DERIVED candidate tool surface — one tool per PortalAPI operation group — offered as a design starting point, ...

## Agentic access (1)

- **Threatlocker Agentic Access** — 83 operations · 46 acting · 1 human-in-the-loop

## Security (3)

- **Threatlocker Authentication** — apiKey · 3 schemes
- **Threatlocker Domain Security** — TLSv1.3 · HSTS · DMARC
- **Threatlocker Trust Center** — SOC 2 Type II, ISO 27001, FedRAMP

## Tags

Cybersecurity, Zero Trust, Endpoint Security, Application-Control, allowlisting, Ransomware Prevention, Privileged Access Management, Network Access Control, Managed Detection and Response, Device Management, MSP, Compliance

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/threatlocker/). Scores are computed from the provider's own public artifacts under a published rubric.
