Venafi

Venafi is the machine identity security platform for discovering, issuing, provisioning and retiring TLS/SSL certificates, SSH keys, code-signing keys and workload identities across data centers, clouds and Kubernetes. Its Control Plane ships two public REST contracts: the SaaS "Certificate Manager - SaaS" API on api.venafi.cloud (six data-residency regions) and the self-hosted Trust Protection Foundation WebSDK. Venafi was acquired by CyberArk in 2024 and the products now carry CyberArk Certificate Manager branding; venafi.com itself 301s to Palo Alto Networks following its acquisition of CyberArk, while developer.venafi.com, docs.venafi.com, docs.venafi.cloud, api.venafi.cloud and github.com/Venafi remain live and are where every artifact in this profile came from.

Venafi publishes 58 APIs on the APIs.io network, including Access Management APIs API, AlgorithmSelector APIs API, Application API, and 55 more. Tagged areas include Company, Security, Certificates, PKI, and Machine Identity.

The Venafi catalog on APIs.io includes 1 event-driven AsyncAPI specification.

Venafi’s developer surface includes authentication, documentation, API reference, getting-started guide, support, signup flow, changelog, and 24 more developer resources.

42.5/100 developing ▬ flat Agent 33/100 agent ready Front door AI 4/6 moderate Full breakdown ↓
scored 2026-09-21 · rubric v0.22.0
AccessSelf serve
4 APIs
CompanySecurityCertificatesPKIMachine IdentityIdentityCryptographyKey ManagementCertificate Lifecycle ManagementDevOpsKubernetesCode Signing

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-21 · rubric v0.22.0
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it carries 10 points of the composite. It is scored from the published contracts themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in front of it, and the first time that check is skipped a duplicate record is created. Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet, not penalised by it.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/venafi: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 58

Individual APIs this provider publishes, each with its own machine-readable definition.

Venafi Access Management APIs API

The endpoints in this section allow you to manage your OAuth environment. Using endpoints described in this section, you can configure your global OAuth properties, assign roles...

Venafi AlgorithmSelector APIs API

The AlgorithmSelector interface provides the ability to retrieve and configure allowed Key Algorithms for policy, key and certificate objects

Venafi Application API

The Application API from Venafi — 7 operation(s) for application.

Venafi Authentication Server APIs API

The Auth REST SDK manages authorization bearer tokens. The tokens you need are based on the set of API calls that your client uses. The Auth SDK uses the VEDauth service to gran...

Venafi Certificate Approvals API

The Certificate Approvals API from Venafi — 5 operation(s) for certificate approvals.

Venafi Certificate Auto-renewal Monitoring API

The Certificate Auto-renewal Monitoring API from Venafi — 4 operation(s) for certificate auto-renewal monitoring.

Venafi Certificate Discovery API

The Certificate Discovery API from Venafi — 2 operation(s) for certificate discovery.

Venafi Certificate Expiration Reports API

The Certificate Expiration Reports API from Venafi — 2 operation(s) for certificate expiration reports.

Venafi Certificate Import API

The Certificate Import API from Venafi — 1 operation(s) for certificate import.

Venafi Certificate Installations API

The Certificate Installations API from Venafi — 4 operation(s) for certificate installations.

Venafi Certificate Inventory Monitoring API

The Certificate Inventory Monitoring API from Venafi — 3 operation(s) for certificate inventory monitoring.

Venafi Certificate Management APIs API

The endpoints in this section manage TLS certificates. If you want certificates to secure SSH keys, see the _SshCertificates_ section ## PKIX Parameter Set ## As of TPP 25.1 alg...

Venafi Certificate Policy API

The Certificate Policy API from Venafi — 3 operation(s) for certificate policy.

Venafi Certificate Request API

The Certificate Request API from Venafi — 5 operation(s) for certificate request.

Venafi Certificate Revocation Approvals API

The Certificate Revocation Approvals API from Venafi — 2 operation(s) for certificate revocation approvals.

Venafi Certificates API

The Certificates API from Venafi — 8 operation(s) for certificates.

Venafi Client Management APIs API

## OSName Definitions ## * AIX * Android * BlackBerry * BSD * HPux * iOS * Linux * MacOS * Other * Solaris * Unknown * Windows * zOS ## ClientType Definitions ## |ClientType|Des...

Venafi CodeSigning APIs API

Code Sign Manager allows you to make REST API calls to manage global configurations, templates, projects, signing applications, and rights.

Venafi CodeSigning HSM API

This API allows you to request digital signing of software and manage signing, authentication, and encryption keys. This API requires the CyberArk Code Sign Manager product.

Venafi Configuration APIs API

## Introduction ## The Config interface manages objects, attributes, and policy values. API responses include a `Result` value that describes the result of the API call. If an o...

Venafi Credential APIs API

The Credentials interface stores information about credentials for use in requesting certificates and other activities. Trust Protection Foundation only stores the credentials y...

Venafi Credential Management API

The Credential Management API from Venafi — 7 operation(s) for credential management.

Venafi Discovery Management APIs API

The Discovery interface manages certificate, device, and application information from your network.

Venafi Encryption APIs API

The Crypto interface provides limited access to the cryptography configuration. Trust Protection Foundation installs with two encryption keys, the default Trust Protection Found...

Venafi Event Logs API

The Event Logs API from Venafi — 3 operation(s) for event logs.

Venafi Flow APIs API

The Flow API manages the sequence of tasks. If one of the tasks is has an 'approval required', Flow Tickets manages that approval.

Venafi HashiCorp PKI APIs API

The Public Key Infrastructure (PKI) interface allows Trust Protection Foundation to act as an Intermediate Certificate Authority for certificate vaults. This interface also send...

Venafi Identity APIs API

The Identity interface manages users and group access. The Web SDK supports the following identity providers for viewing individuals and groups of users: |Provider|Requirements|...

Venafi Legacy Workflow APIs API

The Workflow/Ticket interface manages certificates in an automated workflow. Trust Protection Foundation engines rely upon workflow object settings and their assignment to folde...

Venafi Log APIs API

The Log APIs allow to manage CyberArk application event logs. The Log interface allow for events to be recorded in the Trust Protection Foundation log table. Many API method cal...

Venafi Machine Identities API

The Machine Identities API from Venafi — 4 operation(s) for machine identities.

Venafi Machine Types API

The Machine Types API from Venafi — 1 operation(s) for machine types.

Venafi Machines API

The Machines API from Venafi — 8 operation(s) for machines.

Venafi Metadata APIs API

The Metadata interface manages Custom Fields for objects that appear in the following places of the UI: * Certificates * Devices * Code Signing Projects * Code Signing Environme...

Venafi Permission APIs API

The Permissions interface enables the management and querying of permissions within CyberArk Trust Protection Foundation™. Permissions grant principals (users and groups) privil...

Venafi Platform APIs API

The ServerStatus endpoints allow you to query if a Trust Protection Foundation is in the active or idle state. This can be useful in configurations where the standby feature is ...

Venafi Plugins API

The Plugins API from Venafi — 4 operation(s) for plugins.

Venafi Private Key Import API

The Private Key Import API from Venafi — 2 operation(s) for private key import.

Venafi Processing Engines APIs API

The ProcessingEngines interface assigns and controls how Platforms engines manage information in Policy folders. These features provide a means for load balancing certificate ma...

Venafi Recycle Bin APIs API

The RecycleBin interface allows you to manage old or recently deleted data.

Venafi SecretStore APIs API

SecretStore APIs

Venafi Service Accounts API

The Service Accounts API from Venafi — 5 operation(s) for service accounts.

Venafi SSH Certificate APIs API

The SSH Certificate APIs allow to manage the issuance of special certificates for SSH devices. These endpoints are valid only if you purchased SSH Manager for Machines.

Venafi SSH Management APIs API

The SSH Management APIs allow to manage device keys and keysets. This interface is valid only if you purchased SSH Manager for Machines. All product-supported operations are exp...

Venafi Statistics APIs API

The Statistics APIs provide metrics about Trust Protection Foundation operations. You can query, group, and filter data and then use it in your own reporting applications.

Venafi System Status APIs API

The SystemStatus interface provides status and upgrade information about Trust Protection Foundation engines. This information also appears in the UI. # Engine Upgrade Status En...

Venafi Tags API

The Tags API from Venafi — 9 operation(s) for tags.

Venafi Teams API

The Teams API from Venafi — 4 operation(s) for teams.

Venafi Teams APIs API

The Teams interface allows you to associate AD, LDAP, and local Identities to Policy assets and CyberArk products.

Venafi User Accounts API

The User Accounts API from Venafi — 1 operation(s) for user accounts.

Venafi User Preference APIs API

The Preference APIs allow to manages the caller's user preferences

Venafi Users API

The Users API from Venafi — 7 operation(s) for users.

Venafi V Satellite API

The VSatellite API from Venafi — 11 operation(s) for vsatellite.

Venafi Webhooks API

The Webhooks API from Venafi — 2 operation(s) for webhooks.

Venafi Workload Identity Manager Configurations API

The Workload Identity Manager Configurations API from Venafi — 2 operation(s) for workload identity manager configurations.

Venafi Workload Identity Manager Intermediate Certificates API

The Workload Identity Manager Intermediate Certificates API from Venafi — 1 operation(s) for workload identity manager intermediate certificates.

Venafi Workload Identity Manager Policies API

The Workload Identity Manager Policies API from Venafi — 2 operation(s) for workload identity manager policies.

Venafi Workload Identity Manager Sub CA Providers API

The Workload Identity Manager Sub CA Providers API from Venafi — 2 operation(s) for workload identity manager sub ca providers.

Scroll for all 58

Pricing Plans 1

Published pricing tiers and plan structures.

Venafi Plans Pricing

0 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Venafi Rate Limits

0 limits

RATE LIMITS

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Venafi Authentication

apiKey/http/oauth2 · 4 schemes

SECURITY

Venafi Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Venafi Scopes

OAuth 2.0 · no documented scopes

0 scopes

SCOPES

Resources

Get Started 3

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 6

Pagination, idempotency, versioning, errors, and events

Build 4

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Operate 5

Status, limits, changes, and where to get help

Commercial 1

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Other 3

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: venafi
name: Venafi
description: 'Venafi is the machine identity security platform for discovering, issuing, provisioning and retiring TLS/SSL
  certificates, SSH keys, code-signing keys and workload identities across data centers, clouds and Kubernetes. Its Control
  Plane ships two public REST contracts: the SaaS "Certificate Manager - SaaS" API on api.venafi.cloud (six data-residency
  regions) and the self-hosted Trust Protection Foundation WebSDK. Venafi was acquired by CyberArk in 2024 and the products
  now carry CyberArk Certificate Manager branding; venafi.com itself 301s to Palo Alto Networks following its acquisition
  of CyberArk, while developer.venafi.com, docs.venafi.com, docs.venafi.cloud, api.venafi.cloud and github.com/Venafi remain
  live and are where every artifact in this profile came from.'
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: medium
  source:
  - authentication
  - scopes
  - rate-limits
  - security
  - url: https://venafi.com/
    status: 301
    note: declared website redirects to https://www.paloaltonetworks.com/network-security/next-gen-trust-security/certificate-manager
      — a different registrable domain (venafi.com -> paloaltonetworks.com), possible rename or acquisition (probed 2026-09-03,
      roadmap#169)
  generated: '2026-09-03'
  method: derived
image: https://avatars.githubusercontent.com/u/7817722?v=4
url: https://raw.githubusercontent.com/api-evangelist/venafi/refs/heads/main/apis.yml
x-type: company
x-source: harvest:secondary-market
specificationVersion: '0.20'
created: '2026-09-02'
modified: '2026-09-02'
tags:
- Company
- Security
- Certificates
- PKI
- Machine Identity
- Identity
- Cryptography
- Key Management
- Certificate Lifecycle Management
- DevOps
- Kubernetes
- Code Signing
apis:
- aid: venafi:venafi-access-management-apis-api
  name: Venafi Access Management APIs API
  description: "The endpoints in this section allow you to manage your OAuth environment. \nUsing endpoints described in this\
    \ section, you can configure your global OAuth properties, assign roles \nto identities, create and manage applications,\
    \ and create grant rules. After these are in \nplace, users can request grants using the authentication server. This section\
    \ also includes \ndescriptions of endpoints that allow you to view and revoke issued grants."
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Access Management APIs
  properties:
  - type: OpenAPI
    url: openapi/venafi-access-management-apis-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-algorithmselector-apis-api
  name: Venafi AlgorithmSelector APIs API
  description: The AlgorithmSelector interface provides the ability to retrieve and configure allowed Key Algorithms for policy,
    key and certificate objects
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - AlgorithmSelector APIs
  properties:
  - type: OpenAPI
    url: openapi/venafi-algorithmselector-apis-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-application-api
  name: Venafi Application API
  description: The Application API from Venafi — 7 operation(s) for application.
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Application
  properties:
  - type: OpenAPI
    url: openapi/venafi-application-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-authentication-server-apis-api
  name: Venafi Authentication Server APIs API
  description: "The Auth REST SDK manages authorization bearer tokens. The tokens you need are based on the set of API calls\
    \ that your client uses.\n\n\nThe Auth SDK uses the VEDauth service to grant access and manage tokens. No installation\
    \ is necessary. \nHowever, configuration is required. For more information, see Setting up token authentication."
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Authentication Server APIs
  properties:
  - type: OpenAPI
    url: openapi/venafi-authentication-server-apis-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-approvals-api
  name: Venafi Certificate Approvals API
  description: The Certificate Approvals API from Venafi — 5 operation(s) for certificate approvals.
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Certificate Approvals
  properties:
  - type: OpenAPI
    url: openapi/venafi-certificate-approvals-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-auto-renewal-monitoring-api
  name: Venafi Certificate Auto-renewal Monitoring API
  description: The Certificate Auto-renewal Monitoring API from Venafi — 4 operation(s) for certificate auto-renewal monitoring.
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Certificate Auto-renewal Monitoring
  properties:
  - type: OpenAPI
    url: openapi/venafi-certificate-auto-renewal-monitoring-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-discovery-api
  name: Venafi Certificate Discovery API
  description: The Certificate Discovery API from Venafi — 2 operation(s) for certificate discovery.
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Certificate Discovery
  properties:
  - type: OpenAPI
    url: openapi/venafi-certificate-discovery-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-expiration-reports-api
  name: Venafi Certificate Expiration Reports API
  description: The Certificate Expiration Reports API from Venafi — 2 operation(s) for certificate expiration reports.
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Certificate Expiration Reports
  properties:
  - type: OpenAPI
    url: openapi/venafi-certificate-expiration-reports-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-import-api
  name: Venafi Certificate Import API
  description: The Certificate Import API from Venafi — 1 operation(s) for certificate import.
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Certificate Import
  properties:
  - type: OpenAPI
    url: openapi/venafi-certificate-import-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-installations-api
  name: Venafi Certificate Installations API
  description: The Certificate Installations API from Venafi — 4 operation(s) for certificate installations.
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Certificate Installations
  properties:
  - type: OpenAPI
    url: openapi/venafi-certificate-installations-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-inventory-monitoring-api
  name: Venafi Certificate Inventory Monitoring API
  description: The Certificate Inventory Monitoring API from Venafi — 3 operation(s) for certificate inventory monitoring.
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Certificate Inventory Monitoring
  properties:
  - type: OpenAPI
    url: openapi/venafi-certificate-inventory-monitoring-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-management-apis-api
  name: Venafi Certificate Management APIs API
  description: "The endpoints in this section manage TLS certificates. If you want certificates to secure SSH keys, see the\
    \ _SshCertificates_ section\n## PKIX Parameter Set ##\nAs of TPP 25.1 algorithms are identified by an OID called PKIX\
    \ Parameter Set. The following table lists the OID for each algorithm: \n\n\n\n**RSA Algorithms**\n\n| Algorithm | PKIX\
    \ Parameter Set | Description |\n|-----------|--------------------|--------------------------|\n| RSA 1024 | 1.3.6.1.4.1.28783.10.1.1.1024|\
    \ RSA 1024 bits offers moderate security but is now considered vulnerable and outdated for most modern applications. |\n\
    | RSA 2048 | 1.3.6.1.4.1.28783.10.1.1.2048| RSA 2048 bits offers strong security and is widely used for modern encryption\
    \ and digital signatures. |\n| RSA 3072 | 1.3.6.1.4.1.28783.10.1.1.3072| RSA 3072 bits provides a higher security level,\
    \ suitable for long-term protection of sensitive data. |\n| RSA 4096 | 1.3.6.1.4.1.28783.10.1.1.4096| RSA 4096 bits offers\
    \ very high security, commonly used for highly sensitive data and long-term encryption. |\n| RSA 8192 | 1.3.6.1.4.1.28783.10.1.1.8192|\
    \ RSA 8192 bits provides extremely high security, used for the most sensitive data and long-term protection. |\n| RSA\
    \ PSS/OAEP 1024 | 1.3.6.1.4.1.28783.10.1.2.1024| RSA 1024 bits PSS provides moderate security for digital signatures,\
    \ with PSS offering improved resistance against certain attacks, though it's now considered vulnerable for most applications.\
    \ |\n| RSA PSS/OAEP 2048 | 1.3.6.1.4.1.28783.10.1.2.2048| RSA 2048 bits PSS offers strong security with enhanced resistance\
    \ to forgery and adaptive chosen-message attacks, making it widely used in modern systems. |\n| RSA PSS/OAEP 3072 | 1.3.6.1.4.1.28783.10.1.2.3072|\
    \ RSA 3072 bits PSS provides enhanced security for long-term digital signature protection, with PSS improving resistance\
    \ to certain signature-related attacks. |\n| RSA PSS/OAEP 4096 | 1.3.6.1.4.1.28783.10.1.2.4096| RSA 4096 bits PSS provides\
    \ very high security for digital signatures, with PSS offering added protection against vulnerabilities in deterministic\
    \ signature schemes. |\n| RSA PSS/OAEP 8192 | 1.3.6.1.4.1.28783.10.1.2.8192| RSA 8192 bits PSS offers extremely high security\
    \ for critical digital signatures, with PSS further strengthening resistance to advanced cryptographic attacks and long-term\
    \ protection. |\n\n**Elliptic Curve Digital Signature Algorithms (ECDSA)**\n\n| Algorithm | PKIX Parameter Set | Description\
    \ |\n|-----------|--------------------|--------------------------|\n| ECDSA P-256 | 1.3.6.1.4.1.28783.10.2.1.256| Digital\
    \ signature algorithm based on the NIST P-256 curve, providing 128-bit security. |\n| ECDSA P-384 | 1.3.6.1.4.1.28783.10.2.1.384|\
    \ Digital signature algorithm based on the NIST P-384 curve, providing 192-bit security. |\n| ECDSA P-521 | 1.3.6.1.4.1.28783.10.2.1.521|\
    \ Digital signature algorithm based on the NIST P-521 curve, providing 256-bit security. |\n| Brainpool P-256r1 | 1.3.6.1.4.1.28783.10.2.2.1|\
    \ Brainpool P256 is a 256-bit elliptic curve offering strong security for digital signatures and key exchange. |\n| Brainpool\
    \ P-384r1 | 1.3.6.1.4.1.28783.10.2.2.2| Brainpool P384 is a 384-bit elliptic curve providing enhanced security for high-assurance\
    \ applications. |\n| Brainpool P-512r1 | 1.3.6.1.4.1.28783.10.2.2.3| Brainpool P512 is a 512-bit elliptic curve offering\
    \ very high security for sensitive data and long-term protection. |\n| Brainpool P-160r1 | 1.3.6.1.4.1.28783.10.2.2.4|\
    \ Brainpool P160 is a 160-bit curve, offering moderate security for lightweight cryptographic applications. |\n| Brainpool\
    \ P-160t1 | 1.3.6.1.4.1.28783.10.2.2.5| Brainpool P160T is a 160-bit twisted curve, offering efficient performance and\
    \ moderate security for lightweight applications. |\n| Brainpool P-192r1 | 1.3.6.1.4.1.28783.10.2.2.6| Brainpool P192\
    \ is a 192-bit curve providing a balanced security level for general-purpose cryptography. |\n| Brainpool P-192t1 | 1.3.6.1.4.1.28783.10.2.2.7|\
    \ Brainpool P192T is a 192-bit twisted curve, optimized for faster cryptographic operations with improved security. |\n\
    | Brainpool P-224r1 | 1.3.6.1.4.1.28783.10.2.2.8| Brainpool P224 is a 224-bit curve offering strong security for medium-strength\
    \ cryptographic applications. |\n| Brainpool P-224t1 | 1.3.6.1.4.1.28783.10.2.2.9| Brainpool P224T is a 224-bit twisted\
    \ Edwards curve, optimized for efficient cryptographic operations with strong security. |\n| Brainpool P-256t1 | 1.3.6.1.4.1.28783.10.2.2.10|\
    \ Brainpool P256T is a 256-bit twisted curve, optimized for faster operations and improved security in digital signatures\
    \ and key exchange. |\n| Brainpool P-320r1 | 1.3.6.1.4.1.28783.10.2.2.11| Brainpool P320 is a 320-bit curve providing\
    \ strong security for cryptographic operations, suitable for high-security applications. |\n| Brainpool P-320t1 | 1.3.6.1.4.1.28783.10.2.2.12|\
    \ Brainpool P320T is a 320-bit twisted curve, balancing strong security and efficient performance for cryptographic tasks.\
    \ |\n| Brainpool P-384t1 | 1.3.6.1.4.1.28783.10.2.2.13| Brainpool P384T is a 384-bit twisted curve providing strong security\
    \ for digital signatures and key exchange, optimized for performance and efficiency. |\n| Brainpool P-512t1 | 1.3.6.1.4.1.28783.10.2.2.14|\
    \ Brainpool P512T is a 512-bit twisted curve, providing very high security and optimized for efficient cryptographic processing.\
    \ |\n| SEC P-256k1 | 1.3.6.1.4.1.28783.10.2.3.1| Sec P256K is a 256-bit curve widely used in Bitcoin and blockchain technologies,\
    \ optimized for fast elliptic curve operations. |\n| SEC P-224r1 | 1.3.6.1.4.1.28783.10.2.3.2| Sec P224 is a 224-bit curve\
    \ offering strong security for general-purpose cryptography, commonly used in digital signatures. |\n| SEC P-224k1 | 1.3.6.1.4.1.28783.10.2.3.3|\
    \ Sec P224K is a 224-bit curve used in cryptographic applications with an emphasis on fast and efficient operations. |\n\
    | SEC P-192r1 | 1.3.6.1.4.1.28783.10.2.3.4| Sec P192 is a 192-bit curve providing moderate security for lightweight cryptographic\
    \ applications. |\n| SEC P-192k1 | 1.3.6.1.4.1.28783.10.2.3.5| Sec P192K is a 192-bit curve widely used in blockchain\
    \ and cryptographic systems, optimized for efficient operations. |\n\n**Edwards Curve Algorithms**\n\n| Algorithm | PKIX\
    \ Parameter Set | Description |\n|-----------|--------------------|--------------------------|\n| Ed25519 | 1.3.6.1.4.1.28783.10.3.25519|\
    \ Ed25519 is a high-security elliptic curve signature algorithm, designed for fast performance and resistance to side-channel\
    \ attacks. |\n| Ed448 | 1.3.6.1.4.1.28783.10.3.44448| Ed448 is a highly secure elliptic curve signature algorithm, offering\
    \ stronger security than ED25519, with a larger key size. |\n\n**ML-DSA Quantum-Safe Algorithms**\n\n| Algorithm | PKIX\
    \ Parameter Set | Description |\n|-----------|--------------------|--------------------------|\n| ML-DSA44 | 1.3.6.1.4.1.28783.10.4.44|\
    \ ML-DSA44 offers 128-bit quantum security, designed for lightweight applications that require post-quantum resilience\
    \ with moderate security. |\n| ML-DSA65 | 1.3.6.1.4.1.28783.10.4.65| ML-DSA65 provides 192-bit quantum security, offering\
    \ stronger protection against quantum adversaries while maintaining efficiency for broader use cases. |\n| ML-DSA87 |\
    \ 1.3.6.1.4.1.28783.10.4.87| ML-DSA87 delivers 256-bit quantum security, designed for high-assurance applications needing\
    \ robust resistance to future quantum computing threats. |\n\n**SLH-DSA Quantum-Safe Algorithms**\n\n| Algorithm | PKIX\
    \ Parameter Set | Description |\n|-----------|--------------------|--------------------------|\n| SLH-DSA-SHA2-128s |\
    \ 1.3.6.1.4.1.28783.10.5.1.1| SLH-DSA SHA2 128bit Small: Offers 128-bit security with SHA-2, optimized for small footprint\
    \ applications. |\n| SLH-DSA-SHA2-128f | 1.3.6.1.4.1.28783.10.5.1.2| SLH-DSA SHAKE 128bit Fast: Delivers 128-bit security\
    \ with SHAKE, optimized for fast performance. |\n| SLH-DSA-SHA2-192s | 1.3.6.1.4.1.28783.10.5.1.3| SLH-DSA SHA2 192bit\
    \ Small: Offers 192-bit security with SHA-2, suitable for small footprint applications. |\n| SLH-DSA-SHA2-192f | 1.3.6.1.4.1.28783.10.5.1.4|\
    \ SLH-DSA SHA2 192bit Fast: Ensures 192-bit security with SHA-2, optimized for fast performance. |\n| SLH-DSA-SHA2-256s\
    \ | 1.3.6.1.4.1.28783.10.5.1.5| SLH-DSA SHA2 256bit Small: Offers 256-bit security with SHA-2, suitable for small footprint\
    \ applications. |\n| SLH-DSA-SHA2-256f | 1.3.6.1.4.1.28783.10.5.1.6| SLH-DSA SHA2 256bit Small: Offers 256-bit security\
    \ with SHA-2, suitable for small footprint applications. |\n| SLH-DSA-Shake-128s | 1.3.6.1.4.1.28783.10.5.1.7| SLH-DSA\
    \ SHAKE 128bit Small: Provides 128-bit security with SHAKE, designed for small footprint applications. |\n| SLH-DSA-Shake-128f\
    \ | 1.3.6.1.4.1.28783.10.5.1.8| SLH-DSA SHAKE 128bit Fast: Ensures 128-bit security with SHAKE, optimized for fast performance.\
    \ |\n| SLH-DSA-Shake-192s | 1.3.6.1.4.1.28783.10.5.1.9| SLH-DSA SHAKE 192bit Small: Provides 192-bit security with SHAKE,\
    \ designed for small footprint applications. |\n| SLH-DSA-Shake-192f | 1.3.6.1.4.1.28783.10.5.1.10| SLH-DSA SHAKE 192bit\
    \ Fast: Delivers 192-bit security with SHAKE, optimized for fast performance. |\n| SLH-DSA-Shake-256s | 1.3.6.1.4.1.28783.10.5.1.11|\
    \ SLH-DSA SHAKE 256bit Small: Offers 256-bit security with SHAKE, suitable for small footprint applications. |\n| SLH-DSA-Shake-256f\
    \ | 1.3.6.1.4.1.28783.10.5.1.12| SLH-DSA SHA2 256bit Fast: Offers 256-bit security with SHAKE, optimized for fast performance.\
    \ |\n\n**Pre-Hash SLH-DSA Quantum-Safe Algorithms**\n\n| Algorithm | PKIX Parameter Set | Description |\n|-----------|--------------------|--------------------------|\n\
    | HASH-SLH-DSA-SHA2-128s-SHA256 | 1.3.6.1.4.1.28783.10.5.2.1| Pre-Hash SLH-DSA SHA2 128bit Small: Offers 128-bit security\
    \ with SHA-2, optimized for small footprint applications. |\n| HASH-SLH-DSA-SHA2-128f-SHA256 | 1.3.6.1.4.1.28783.10.5.2.2|\
    \ Pre-Hash SLH-DSA SHA2 128bit Fast: Delivers 128-bit security with SHA-2, optimized for fast performance. |\n| HASH-SLH-DSA-SHA2-192s-SHA512\
    \ | 1.3.6.1.4.1.28783.10.5.2.3| Pre-Hash SLH-DSA SHA2 192bit Small: Offers 192-bit security with SHA-2, suitable for small\
    \ footprint applications. |\n| HASH-SLH-DSA-SHA2-192f-SHA512 | 1.3.6.1.4.1.28783.10.5.2.4| Pre-Hash SLH-DSA SHA2 192bit\
    \ Fast: Ensures 192-bit security with SHA-2, optimized for fast performance. |\n| HASH-SLH-DSA-SHA2-256s-SHA512 | 1.3.6.1.4.1.28783.10.5.2.5|\
    \ Pre-Hash SLH-DSA SHA2 256bit Small: Offers 256-bit security with SHA-2, suitable for small footprint applications. |\n\
    | HASH-SLH-DSA-SHA2-256f-SHA512 | 1.3.6.1.4.1.28783.10.5.2.6| Pre-Hash SLH-DSA SHA2 256bit Small: Offers 256-bit security\
    \ with SHA-2, suitable for small footprint applications. |\n| HASH-SLH-DSA-Shake-128s-Shake128 | 1.3.6.1.4.1.28783.10.5.2.7|\
    \ Pre-Hash SLH-DSA SHAKE 128bit Small: Provides 128-bit security with SHAKE, designed for small footprint applications.\
    \ |\n| HASH-SLH-DSA-Shake-128f-Shake128 | 1.3.6.1.4.1.28783.10.5.2.8| Pre-Hash SLH-DSA SHA2 128bit Fast: Ensures 128-bit\
    \ security with SHA-2, optimized for fast performance. |\n| HASH-SLH-DSA-Shake-192s-SHAke256 | 1.3.6.1.4.1.28783.10.5.2.9|\
    \ Pre-Hash SLH-DSA SHAKE 192bit Small: Provides 192-bit security with SHAKE, designed for small footprint applications.\
    \ |\n| HASH-SLH-DSA-Shake-192f-SHAke256 | 1.3.6.1.4.1.28783.10.5.2.10| Pre-Hash SLH-DSA SHAKE 192bit Fast: Delivers 192-bit\
    \ security with SHAKE, optimized for fast performance. |\n| HASH-SLH-DSA-Shake-256s-SHAke256 | 1.3.6.1.4.1.28783.10.5.2.11|\
    \ Pre-Hash SLH-DSA SHA2 256bit Small: Offers 256-bit security with SHA-2, suitable for small footprint applications. |\n\
    | HASH-SLH-DSA-Shake-256f-SHAke256 | 1.3.6.1.4.1.28783.10.5.2.12| Pre-Hash SLH-DSA SHA2 256bit Fast: Offers 256-bit security\
    \ with SHAKE, optimized for fast performance. |\n\n**Composite Quantum-Safe Algorithms**\n\n| Algorithm | PKIX Parameter\
    \ Set | Description |\n|-----------|--------------------|--------------------------|\n| Composite ML-DSA44 / PSS2048 |\
    \ 1.3.6.1.4.1.28783.10.7.1| ML-DSA44 / RSA 2048 PSS combines 128-bit quantum security of ML-DSA44 with RSA2048PSS, suitable\
    \ for moderate security applications requiring post-quantum and classical resilience. |\n| Composite ML-DSA44 / RSA2048\
    \ | 1.3.6.1.4.1.28783.10.7.2| ML-DSA44 / RSA 2048 combines 128-bit quantum security of ML-DSA44 with RSA 2048, suitable\
    \ for moderate security applications requiring post-quantum and classical resilience. |\n| Composite ML-DSA44 / Ed25519\
    \ | 1.3.6.1.4.1.28783.10.7.3| ML-DSA44 / Ed25519 offers 128-bit quantum security of ML-DSA44 with Ed25519, optimized for\
    \ fast and secure digital signatures. |\n| Composite ML-DSA44 / ECP256 | 1.3.6.1.4.1.28783.10.7.4| ML-DSA44 / ECP256 provides\
    \ 128-bit quantum security of ML-DSA44 with ECDSA P-256, ideal for secure communications and data integrity. |\n| Composite\
    \ ML-DSA65 / PSS3072 | 1.3.6.1.4.1.28783.10.7.5| ML-DSA65 / RSA 3072 PSS combines 192-bit quantum security of ML-DSA65\
    \ with RSA 3072 PSS, suitable for long-term protection and moderate security applications. |\n| Composite ML-DSA65 / RSA3072\
    \ | 1.3.6.1.4.1.28783.10.7.6| ML-DSA65 / RSA 3072 offers 192-bit quantum security of ML-DSA65 with RSA 3072, ideal for\
    \ secure communications and data integrity. |\n| Composite ML-DSA65 / PSS4096 | 1.3.6.1.4.1.28783.10.7.7| ML-DSA65 / RSA\
    \ 4096 PSS provides 192-bit quantum security of ML-DSA65 with RSA 4096 PSS, suitable for highly sensitive data and long-term\
    \ protection. |\n| Composite ML-DSA65 / RSA4096 | 1.3.6.1.4.1.28783.10.7.8| ML-DSA65 / RSA 4096 combines 192-bit quantum\
    \ security of ML-DSA65 with RSA 4096, ideal for high-security applications needing long-term protection. |\n| Composite\
    \ ML-DSA65 / ECP256 | 1.3.6.1.4.1.28783.10.7.9| ML-DSA65 / ECP256 offers 192-bit quantum security of ML-DSA65 with ECDSA\
    \ P-256, designed for secure communications and data integrity. |\n| Composite ML-DSA65 / ECP384 | 1.3.6.1.4.1.28783.10.7.10|\
    \ ML-DSA65 / ECP384 offers 192-bit quantum security of ML-DSA65 with ECDSA P-384, ideal for high-security applications\
    \ needing long-term protection. |\n| Composite ML-DSA65 / Brainpool P-256 | 1.3.6.1.4.1.28783.10.7.11| ML-DSA65 / Brainpool\
    \ P-256 provides 192-bit quantum security of ML-DSA65 with Brainpool P-256, designed for secure communications and data\
    \ integrity. |\n| Composite ML-DSA65 / Ed25519 | 1.3.6.1.4.1.28783.10.7.12| ML-DSA65 / Ed25519 combines 192-bit quantum\
    \ security of ML-DSA65 with Ed25519, optimized for fast and secure digital signatures. |\n| Composite ML-DSA87 / ECP384\
    \ | 1.3.6.1.4.1.28783.10.7.13| ML-DSA87 / ECP384 ensures 256-bit quantum security of ML-DSA87 with ECDSA P-384, suitable\
    \ for highly sensitive data and long-term protection. |\n| Composite ML-DSA87 / Brainpool P-384 | 1.3.6.1.4.1.28783.10.7.14|\
    \ ML-DSA87 / Brainpool P-384 offers 256-bit quantum security of ML-DSA87 with Brainpool P-384, ideal for secure financial\
    \ transactions and data integrity. |\n| Composite ML-DSA87 / Ed448 | 1.3.6.1.4.1.28783.10.7.15| ML-DSA87 / Ed448 combines\
    \ 256-bit quantum security of ML-DSA87 with Ed448, designed for high-security digital signatures and fast performance.\
    \ |\n| Composite ML-DSA87 / PSS4096 | 1.3.6.1.4.1.28783.10.7.16| ML-DSA87 / RSA 4096 PSS provides 256-bit quantum security\
    \ of ML-DSA87 with RSA 4096 PSS, suitable for highly sensitive data and long-term protection. |\n| Composite ML-DSA87\
    \ / PSS3072 | 1.3.6.1.4.1.28783.10.7.17| ML-DSA87 / RSA 3072 PSS provides 256-bit quantum security of ML-DSA87 with RSA\
    \ 3072 PSS, suitable for highly sensitive data and long-term protection. |\n| Composite ML-DSA87 / ECP521 | 1.3.6.1.4.1.28783.10.7.18|\
    \ ML-DSA87 / ECP521 ensures 256-bit quantum security of ML-DSA87 with ECDSA P-521, suitable for highly sensitive data\
    \ and long-term protection. |"
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Certificate Management APIs
  properties:
  - type: OpenAPI
    url: openapi/venafi-certificate-management-apis-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-policy-api
  name: Venafi Certificate Policy API
  description: The Certificate Policy API from Venafi — 3 operation(s) for certificate policy.
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Certificate Policy
  properties:
  - type: OpenAPI
    url: openapi/venafi-certificate-policy-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-request-api
  name: Venafi Certificate Request API
  description: The Certificate Request API from Venafi — 5 operation(s) for certificate request.
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Certificate Request
  properties:
  - type: OpenAPI
    url: openapi/venafi-certificate-request-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-revocation-approvals-api
  name: Venafi Certificate Revocation Approvals API
  description: The Certificate Revocation Approvals API from Venafi — 2 operation(s) for certificate revocation approvals.
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Certificate Revocation Approvals
  properties:
  - type: OpenAPI
    url: openapi/venafi-certificate-revocation-approvals-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificates-api
  name: Venafi Certificates API
  description: The Certificates API from Venafi — 8 operation(s) for certificates.
  humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  baseURL: https://api.venafi.cloud
  tags:
  - Certificates
  properties:
  - type: OpenAPI
    url: openapi/venafi-certificates-api-openapi.yml
  - type: Documentation
    url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
  - type: Webhooks
    url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
  - type: Documentation
    url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php


# --- truncated at 32 KB (78 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/venafi/refs/heads/main/apis.yml

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/venafi"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/venafi/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/venafi/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.