Varonis website screenshot

Varonis

Varonis is a pioneer in data security and analytics, specializing in software for data security, governance, threat detection and response. The company provides solutions for protecting enterprise data across cloud and on-premises environments including data classification, access governance, behavioral threat detection, and automated remediation.

Varonis publishes 3 APIs on the APIs.io network: Alerts API, Events API, and Threat Models API. Tagged areas include Cloud Security, Compliance, Data Analytics, Data Governance, and Data Security.

The Varonis catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Varonis’ developer surface includes authentication, developer portal, support, engineering blog, changelog, signup flow, training material, and 28 more developer resources.

65.7/100 strong ▬ flat Agent 44/100 agent ready Full breakdown ↓
scored 2026-08-05 · rubric v0.9.1
AccessEnterpriseSelf serve
6 APIs 8 Features 7 Use Cases
Cloud SecurityComplianceData AnalyticsData GovernanceData SecurityThreat Detection

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-05 · rubric v0.9.1
Composite quality — 65.7/100 · strong
Contract Quality 20.2 / 25
Developer Ergonomics 6.1 / 20
Commercial Clarity 14.2 / 20
Operational Transparency 8.9 / 13
Governance 8.3 / 12
Discoverability 8.2 / 10
Agent readiness — 44/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/varonis: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 6

Individual APIs this provider publishes, each with its own machine-readable definition.

Varonis Data Security Platform API

API for integrating with Varonis Data Security Platform to manage data security policies, access permissions, and threat detection.

Varonis DataPrivilege API

REST and SOAP API for integrating Varonis DataPrivilege with IAM and ITSM solutions. Enables synchronization of managed data, execution and reporting on access requests and acce...

Varonis MCP Server

Model Context Protocol server that interfaces with Varonis APIs, allowing AI clients such as ChatGPT, Claude, and GitHub Copilot to access and orchestrate the Varonis Data Secur...

Varonis Alerts API

Retrieve, filter, and manage security alerts generated by Varonis DatAlert threat detection engine.

Varonis Events API

Access forensic event data associated with specific alerts for investigation and threat hunting.

Varonis Threat Models API

Retrieve threat model definitions used to generate alerts, including categories and severity levels.

Postman Collections 1

Ready-to-run Postman collections for exercising this provider's APIs.

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Varonis DatAlert API

OPEN COLLECTION

Arazzo Workflows 8

Multi-step API workflows described with the Arazzo specification.

Varonis Close Low-Severity Noise

Find the newest low-severity open alert, note it, and close it as legitimate activity.

ARAZZO

Varonis Device Malicious IP Response

Pull a device's newest alert, and if it involves a malicious IP, fetch events and investigate.

ARAZZO

Varonis High-Severity Model Coverage

List threat models, pull alerts for one model, and annotate its newest alert.

ARAZZO

Varonis Investigate and Close Alert

Pull events for a known alert, document findings as a note, then close it.

ARAZZO

Varonis Sensitive Data Alert Escalation

Pull the newest open alert and branch on whether it touches classified sensitive data.

ARAZZO

Varonis Threat Model Hunt

Resolve a threat model by name, pull its recent alerts, and load the newest alert's events.

ARAZZO

Varonis Triage Newest Alert

Pull the newest open alert, load its forensic events, and move it into investigation.

ARAZZO

Varonis User High-Severity Investigation

Find a user's high-severity alerts, pull the top alert's events, and annotate it.

ARAZZO

Scroll for all 8

Pricing Plans 1

Published pricing tiers and plan structures.

Varonis Plans Pricing

1 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Varonis Rate Limits

1 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 8

Notable capabilities this provider offers.

Behavioral Threat Detection

AI-powered detection of abnormal user and data access behavior using DatAlert threat models aligned to MITRE ATT&CK.

Data Classification

Automated sensitive data discovery and classification across cloud and on-premises data stores.

Access Governance

DataPrivilege workflow automation for entitlement reviews, access requests, and permission remediation.

Forensic Investigation

Detailed event-level forensics including file access, permission changes, and login activity for incident investigation.

SIEM and SOAR Integration

REST API integration with SIEM platforms (Splunk, QRadar, Sentinel) and SOAR platforms (XSOAR, Phantom) for automated response.

AI-Assisted Security (MCP)

Model Context Protocol server enabling natural language security operations with Claude, ChatGPT, and GitHub Copilot.

Compliance Reporting

Built-in reporting for GDPR, HIPAA, PCI-DSS, SOX, and other compliance frameworks.

Cloud Security Posture

Data security posture management for Microsoft 365, AWS, Azure, and Google Cloud environments.

Scroll for all 8

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Varonis Datalert Context

13 classes · 43 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Varonis API Rules

5 rules · 3 warnings 2 info

SPECTRAL

Varonis API Rules

37 rules · 13 errors 22 warnings 2 info

SPECTRAL

JSON Schema 12

Standalone JSON Schema definitions for this provider's data models.

AddNoteRequest

2 properties

JSON SCHEMA

Alert

19 properties

JSON SCHEMA

AlertedEvent

11 properties

JSON SCHEMA

AlertedEventsResponse

2 properties

JSON SCHEMA

AlertsResponse

2 properties

JSON SCHEMA

CloseAlertRequest

3 properties

JSON SCHEMA

GetAlertedEventsRequest

6 properties

JSON SCHEMA

GetAlertsRequest

12 properties

JSON SCHEMA

SuccessResponse

2 properties

JSON SCHEMA

ThreatModel

5 properties

JSON SCHEMA

ThreatModelsResponse

1 properties

JSON SCHEMA

UpdateAlertStatusRequest

3 properties

JSON SCHEMA

Scroll for all 12

JSON Structure 12

JSON Structure definitions describing this provider's data shapes.

Varonis Datalert Alert Structure

19 properties

JSON STRUCTURE

Varonis Datalert Alerted Event Structure

11 properties

JSON STRUCTURE

Varonis Datalert Alerts Response Structure

2 properties

JSON STRUCTURE

Varonis Datalert Threat Model Structure

5 properties

JSON STRUCTURE

Scroll for all 12

Examples 12

Example request and response payloads for these APIs.

Scroll for all 12

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Varonis Authentication

apiKey · 1 scheme

SECURITY

Varonis Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Varonis Vulnerability Disclosure

disclosure policy published

SECURITY

Varonis Trust Center

SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS, HIPAA, FedRAMP, GDPR, CSA STAR

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Varonis Agentic Access

6 operations · 5 acting

6 operations · 5 acting

AGENTIC

Use Cases 7

What developers build with this provider.

Insider Threat Detection

Detect and respond to abnormal access patterns that indicate potential insider threats or compromised accounts.

Ransomware Detection

Identify ransomware activity through mass file access, renaming, and encryption patterns.

Data Breach Investigation

Investigate potential data breaches using forensic event trails to determine scope and blast radius.

Privileged Access Review

Automate periodic entitlement reviews to ensure least-privilege access to sensitive data.

Compliance Audit

Generate audit-ready reports demonstrating data access controls for regulatory frameworks.

SOAR Automation

Integrate alert triage and remediation into automated playbooks via the DatAlert REST API.

AI-Driven Security Operations

Use the Varonis MCP Server to enable AI assistants to query alerts, investigate events, and execute remediation.

Scroll for all 7

Integrations 8

Pre-built integrations with other platforms and tools.

Microsoft Sentinel

Ingest Varonis alerts and events into Microsoft Sentinel for correlation and automated response.

Splunk

Stream DatAlert events to Splunk via the official Varonis App for Splunk SIEM integration.

IBM QRadar

Forward Varonis DatAlert events to QRadar using the official integration guide.

CrowdStrike Falcon

Enrich endpoint threat data with Varonis user and data access context.

ServiceNow

Create and manage security incident tickets in ServiceNow from Varonis alerts.

Palo Alto XSOAR

Automate alert triage and remediation workflows using the Varonis XSOAR integration.

Microsoft 365

Monitor and protect SharePoint, OneDrive, Exchange, and Teams data natively.

AWS

Data security posture management for S3, RDS, and other AWS data services.

Scroll for all 8

Resources

Get Started 4

Portal, sign-up, and the first successful call

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 11

Pagination, idempotency, versioning, errors, and events

Scroll for all 11

Build 3

SDKs, sample code, and the tooling you integrate with

Access & Security 6

Authentication, authorization, and security posture

Learn 1

Tutorials, courses, talks, and written guidance

Operate 4

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
name: Varonis
description: Varonis is a pioneer in data security and analytics, specializing in software for data security, governance,
  threat detection and response. The company provides solutions for protecting enterprise data across cloud and on-premises
  environments including data classification, access governance, behavioral threat detection, and automated remediation.
accessModel:
  pricing: enterprise
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Enterprise · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://www.varonis.com/favicon.ico
url: https://www.varonis.com
created: '2025'
modified: '2026-05-19'
tags:
- Cloud Security
- Compliance
- Data Analytics
- Data Governance
- Data Security
- Threat Detection
apis:
- name: Varonis Data Security Platform API
  description: API for integrating with Varonis Data Security Platform to manage data security policies, access permissions,
    and threat detection.
  image: https://www.varonis.com/favicon.ico
  humanURL: https://www.varonis.com/products/data-security-platform
  baseURL: https://api.varonis.com
  tags:
  - Access Control
  - Data Security
  - Permissions
  properties:
  - type: Documentation
    url: https://docs.varonis.com/api
  - type: Authentication
    url: https://docs.varonis.com/api/authentication
- name: Varonis DataPrivilege API
  description: REST and SOAP API for integrating Varonis DataPrivilege with IAM and ITSM solutions. Enables synchronization
    of managed data, execution and reporting on access requests and access control changes, and automation of entitlement
    reviews and self-service access workflows.
  image: https://www.varonis.com/favicon.ico
  humanURL: https://www.varonis.com/products/dataprivilege
  baseURL: https://api.varonis.com
  tags:
  - Access Governance
  - Entitlement Reviews
  - Identity Management
  - Self-Service Access
  properties:
  - type: Documentation
    url: https://www.varonis.com/blog/introducing-gdpr-patterns-and-dataprivilege-api
- name: Varonis MCP Server
  description: Model Context Protocol server that interfaces with Varonis APIs, allowing AI clients such as ChatGPT, Claude,
    and GitHub Copilot to access and orchestrate the Varonis Data Security Platform using natural language. Enables complex
    workflows including alert retrieval, access remediation, and compliance reporting.
  image: https://www.varonis.com/favicon.ico
  humanURL: https://www.varonis.com/blog/mcp-server
  baseURL: https://api.varonis.com
  tags:
  - AI Integration
  - Automation
  - MCP
  - Natural Language
  properties:
  - type: Documentation
    url: https://www.varonis.com/blog/mcp-server
  - type: SDKs
    url: https://www.npmjs.com/package/@varonis/mcp
    title: MCP Server npm Package
- aid: varonis:varonis-alerts-api
  name: Varonis Alerts API
  description: Retrieve, filter, and manage security alerts generated by Varonis DatAlert threat detection engine.
  humanURL: https://www.varonis.com/products/datalert
  baseURL: https://api.varonis.com/datalert
  tags:
  - Alerts
  properties:
  - type: OpenAPI
    url: openapi/varonis-alerts-api-openapi.yml
  - type: Documentation
    url: https://docs.varonis.com/api/datalert
  - type: Authentication
    url: https://docs.varonis.com/api/authentication
  - type: JSONSchema
    url: json-schema/varonis-datalert-alert-schema.json
  - type: JSONSchema
    url: json-schema/varonis-datalert-alerted-event-schema.json
  - type: JSONSchema
    url: json-schema/varonis-datalert-threat-model-schema.json
  - type: JSONStructure
    url: json-structure/varonis-datalert-alert-structure.json
  - type: JSONStructure
    url: json-structure/varonis-datalert-alerted-event-structure.json
  - type: Examples
    url: examples/varonis-datalert-alert-example.json
  - type: Examples
    url: examples/varonis-datalert-alerted-event-example.json
- aid: varonis:varonis-events-api
  name: Varonis Events API
  description: Access forensic event data associated with specific alerts for investigation and threat hunting.
  humanURL: https://www.varonis.com/products/datalert
  baseURL: https://api.varonis.com/datalert
  tags:
  - Events
  properties:
  - type: OpenAPI
    url: openapi/varonis-events-api-openapi.yml
  - type: Documentation
    url: https://docs.varonis.com/api/datalert
  - type: Authentication
    url: https://docs.varonis.com/api/authentication
  - type: JSONSchema
    url: json-schema/varonis-datalert-alert-schema.json
  - type: JSONSchema
    url: json-schema/varonis-datalert-alerted-event-schema.json
  - type: JSONSchema
    url: json-schema/varonis-datalert-threat-model-schema.json
  - type: JSONStructure
    url: json-structure/varonis-datalert-alert-structure.json
  - type: JSONStructure
    url: json-structure/varonis-datalert-alerted-event-structure.json
  - type: Examples
    url: examples/varonis-datalert-alert-example.json
  - type: Examples
    url: examples/varonis-datalert-alerted-event-example.json
- aid: varonis:varonis-threat-models-api
  name: Varonis Threat Models API
  description: Retrieve threat model definitions used to generate alerts, including categories and severity levels.
  humanURL: https://www.varonis.com/products/datalert
  baseURL: https://api.varonis.com/datalert
  tags:
  - Threat Models
  properties:
  - type: OpenAPI
    url: openapi/varonis-threat-models-api-openapi.yml
  - type: Documentation
    url: https://docs.varonis.com/api/datalert
  - type: Authentication
    url: https://docs.varonis.com/api/authentication
  - type: JSONSchema
    url: json-schema/varonis-datalert-alert-schema.json
  - type: JSONSchema
    url: json-schema/varonis-datalert-alerted-event-schema.json
  - type: JSONSchema
    url: json-schema/varonis-datalert-threat-model-schema.json
  - type: JSONStructure
    url: json-structure/varonis-datalert-alert-structure.json
  - type: JSONStructure
    url: json-structure/varonis-datalert-alerted-event-structure.json
  - type: Examples
    url: examples/varonis-datalert-alert-example.json
  - type: Examples
    url: examples/varonis-datalert-alerted-event-example.json
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
  url: https://apievangelist.com
include:
- name: Varonis Support Portal
  url: https://support.varonis.com
common:
- type: AgenticAccess
  url: agentic-access/varonis-agentic-access.yml
- type: TrustCenter
  url: security/varonis-trust-center.yml
- type: VulnerabilityDisclosure
  url: security/varonis-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/varonis-domain-security.yml
- type: Authentication
  url: authentication/varonis-authentication.yml
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/varonis/overview
- type: Arazzo
  url: arazzo/varonis-close-low-severity-noise-workflow.yml
  name: Varonis Close Low-Severity Noise
- type: Arazzo
  url: arazzo/varonis-device-malicious-ip-response-workflow.yml
  name: Varonis Device Malicious IP Response
- type: Arazzo
  url: arazzo/varonis-high-severity-model-coverage-workflow.yml
  name: Varonis High-Severity Model Coverage
- type: Arazzo
  url: arazzo/varonis-investigate-and-close-alert-workflow.yml
  name: Varonis Investigate and Close Alert
- type: Arazzo
  url: arazzo/varonis-sensitive-data-alert-escalation-workflow.yml
  name: Varonis Sensitive Data Alert Escalation
- type: Arazzo
  url: arazzo/varonis-threat-model-hunt-workflow.yml
  name: Varonis Threat Model Hunt
- type: Arazzo
  url: arazzo/varonis-triage-alert-workflow.yml
  name: Varonis Triage Newest Alert
- type: Arazzo
  url: arazzo/varonis-user-high-severity-investigation-workflow.yml
  name: Varonis User High-Severity Investigation
- type: LinkedIn
  url: https://www.linkedin.com/company/varonis
- type: Portal
  url: https://www.varonis.com/developers
- type: Website
  url: https://www.varonis.com
- type: Support
  url: https://www.varonis.com/resources/support
- type: Blog
  url: https://www.varonis.com/blog
- type: PrivacyPolicy
  url: https://www.varonis.com/trust/privacy
- type: TermsOfService
  url: https://www.varonis.com/terms
- type: StatusPage
  url: https://status.varonis.com
- type: ChangeLog
  url: https://www.varonis.com/platform/changelog
- type: Security
  url: https://www.varonis.com/trust/security
- type: Login
  url: https://my.varonis.io/
- type: Signup
  url: https://help.varonis.com/s/article/WDOC-2305
- type: HelpCenter
  url: https://help.varonis.com/s/
- type: TrustCenter
  url: https://www.varonis.com/trust
- type: Integrations
  url: https://www.varonis.com/security-ecosystem-integrations
- type: Training
  url: https://www.varonis.com/product-training
- type: ContentLibrary
  url: https://www.varonis.com/resources
- type: GitHubOrganization
  url: https://github.com/varonis
- type: PartnerPortal
  url: https://partners.varonis.com/
- type: SpectralRules
  url: rules/varonis-spectral-rules.yml
- type: Vocabulary
  url: vocabulary/varonis-vocabulary.yaml
- type: JSONLD
  url: json-ld/varonis-datalert-context.jsonld
- type: Features
  data:
  - name: Behavioral Threat Detection
    description: AI-powered detection of abnormal user and data access behavior using DatAlert threat models aligned to MITRE
      ATT&CK.
  - name: Data Classification
    description: Automated sensitive data discovery and classification across cloud and on-premises data stores.
  - name: Access Governance
    description: DataPrivilege workflow automation for entitlement reviews, access requests, and permission remediation.
  - name: Forensic Investigation
    description: Detailed event-level forensics including file access, permission changes, and login activity for incident
      investigation.
  - name: SIEM and SOAR Integration
    description: REST API integration with SIEM platforms (Splunk, QRadar, Sentinel) and SOAR platforms (XSOAR, Phantom) for
      automated response.
  - name: AI-Assisted Security (MCP)
    description: Model Context Protocol server enabling natural language security operations with Claude, ChatGPT, and GitHub
      Copilot.
  - name: Compliance Reporting
    description: Built-in reporting for GDPR, HIPAA, PCI-DSS, SOX, and other compliance frameworks.
  - name: Cloud Security Posture
    description: Data security posture management for Microsoft 365, AWS, Azure, and Google Cloud environments.
- type: UseCases
  data:
  - name: Insider Threat Detection
    description: Detect and respond to abnormal access patterns that indicate potential insider threats or compromised accounts.
  - name: Ransomware Detection
    description: Identify ransomware activity through mass file access, renaming, and encryption patterns.
  - name: Data Breach Investigation
    description: Investigate potential data breaches using forensic event trails to determine scope and blast radius.
  - name: Privileged Access Review
    description: Automate periodic entitlement reviews to ensure least-privilege access to sensitive data.
  - name: Compliance Audit
    description: Generate audit-ready reports demonstrating data access controls for regulatory frameworks.
  - name: SOAR Automation
    description: Integrate alert triage and remediation into automated playbooks via the DatAlert REST API.
  - name: AI-Driven Security Operations
    description: Use the Varonis MCP Server to enable AI assistants to query alerts, investigate events, and execute remediation.
- type: Integrations
  data:
  - name: Microsoft Sentinel
    description: Ingest Varonis alerts and events into Microsoft Sentinel for correlation and automated response.
  - name: Splunk
    description: Stream DatAlert events to Splunk via the official Varonis App for Splunk SIEM integration.
  - name: IBM QRadar
    description: Forward Varonis DatAlert events to QRadar using the official integration guide.
  - name: CrowdStrike Falcon
    description: Enrich endpoint threat data with Varonis user and data access context.
  - name: ServiceNow
    description: Create and manage security incident tickets in ServiceNow from Varonis alerts.
  - name: Palo Alto XSOAR
    description: Automate alert triage and remediation workflows using the Varonis XSOAR integration.
  - name: Microsoft 365
    description: Monitor and protect SharePoint, OneDrive, Exchange, and Teams data natively.
  - name: AWS
    description: Data security posture management for S3, RDS, and other AWS data services.