Venafi
Venafi is the machine identity security platform for discovering, issuing, provisioning and retiring TLS/SSL certificates, SSH keys, code-signing keys and workload identities across data centers, clouds and Kubernetes. Its Control Plane ships two public REST contracts: the SaaS "Certificate Manager - SaaS" API on api.venafi.cloud (six data-residency regions) and the self-hosted Trust Protection Foundation WebSDK. Venafi was acquired by CyberArk in 2024 and the products now carry CyberArk Certificate Manager branding; venafi.com itself 301s to Palo Alto Networks following its acquisition of CyberArk, while developer.venafi.com, docs.venafi.com, docs.venafi.cloud, api.venafi.cloud and github.com/Venafi remain live and are where every artifact in this profile came from.
Venafi publishes 58 APIs on the APIs.io network, including Access Management APIs API, AlgorithmSelector APIs API, Application API, and 55 more. Tagged areas include Company, Security, Certificates, PKI, and Machine Identity.
The Venafi catalog on APIs.io includes 1 event-driven AsyncAPI specification.
Venafi’s developer surface includes authentication, documentation, API reference, getting-started guide, support, signup flow, changelog, and 24 more developer resources.
4 APIs
Individual APIs this provider publishes, each with its own machine-readable definition.
The endpoints in this section allow you to manage your OAuth environment. Using endpoints described in this section, you can configure your global OAuth properties, assign roles...
The AlgorithmSelector interface provides the ability to retrieve and configure allowed Key Algorithms for policy, key and certificate objects
The Application API from Venafi — 7 operation(s) for application.
The Auth REST SDK manages authorization bearer tokens. The tokens you need are based on the set of API calls that your client uses. The Auth SDK uses the VEDauth service to gran...
The Certificate Approvals API from Venafi — 5 operation(s) for certificate approvals.
The Certificate Auto-renewal Monitoring API from Venafi — 4 operation(s) for certificate auto-renewal monitoring.
The Certificate Discovery API from Venafi — 2 operation(s) for certificate discovery.
The Certificate Expiration Reports API from Venafi — 2 operation(s) for certificate expiration reports.
The Certificate Import API from Venafi — 1 operation(s) for certificate import.
The Certificate Installations API from Venafi — 4 operation(s) for certificate installations.
The Certificate Inventory Monitoring API from Venafi — 3 operation(s) for certificate inventory monitoring.
The endpoints in this section manage TLS certificates. If you want certificates to secure SSH keys, see the _SshCertificates_ section ## PKIX Parameter Set ## As of TPP 25.1 alg...
The Certificate Policy API from Venafi — 3 operation(s) for certificate policy.
The Certificate Request API from Venafi — 5 operation(s) for certificate request.
The Certificate Revocation Approvals API from Venafi — 2 operation(s) for certificate revocation approvals.
The Certificates API from Venafi — 8 operation(s) for certificates.
## OSName Definitions ## * AIX * Android * BlackBerry * BSD * HPux * iOS * Linux * MacOS * Other * Solaris * Unknown * Windows * zOS ## ClientType Definitions ## |ClientType|Des...
Code Sign Manager allows you to make REST API calls to manage global configurations, templates, projects, signing applications, and rights.
This API allows you to request digital signing of software and manage signing, authentication, and encryption keys. This API requires the CyberArk Code Sign Manager product.
## Introduction ## The Config interface manages objects, attributes, and policy values. API responses include a `Result` value that describes the result of the API call. If an o...
The Credentials interface stores information about credentials for use in requesting certificates and other activities. Trust Protection Foundation only stores the credentials y...
The Credential Management API from Venafi — 7 operation(s) for credential management.
The Discovery interface manages certificate, device, and application information from your network.
The Crypto interface provides limited access to the cryptography configuration. Trust Protection Foundation installs with two encryption keys, the default Trust Protection Found...
The Event Logs API from Venafi — 3 operation(s) for event logs.
The Flow API manages the sequence of tasks. If one of the tasks is has an 'approval required', Flow Tickets manages that approval.
The Public Key Infrastructure (PKI) interface allows Trust Protection Foundation to act as an Intermediate Certificate Authority for certificate vaults. This interface also send...
The Identity interface manages users and group access. The Web SDK supports the following identity providers for viewing individuals and groups of users: |Provider|Requirements|...
The Workflow/Ticket interface manages certificates in an automated workflow. Trust Protection Foundation engines rely upon workflow object settings and their assignment to folde...
The Log APIs allow to manage CyberArk application event logs. The Log interface allow for events to be recorded in the Trust Protection Foundation log table. Many API method cal...
The Machine Identities API from Venafi — 4 operation(s) for machine identities.
The Machine Types API from Venafi — 1 operation(s) for machine types.
The Machines API from Venafi — 8 operation(s) for machines.
The Metadata interface manages Custom Fields for objects that appear in the following places of the UI: * Certificates * Devices * Code Signing Projects * Code Signing Environme...
The Permissions interface enables the management and querying of permissions within CyberArk Trust Protection Foundation™. Permissions grant principals (users and groups) privil...
The ServerStatus endpoints allow you to query if a Trust Protection Foundation is in the active or idle state. This can be useful in configurations where the standby feature is ...
The Plugins API from Venafi — 4 operation(s) for plugins.
The Private Key Import API from Venafi — 2 operation(s) for private key import.
The ProcessingEngines interface assigns and controls how Platforms engines manage information in Policy folders. These features provide a means for load balancing certificate ma...
The RecycleBin interface allows you to manage old or recently deleted data.
The Service Accounts API from Venafi — 5 operation(s) for service accounts.
The SSH Certificate APIs allow to manage the issuance of special certificates for SSH devices. These endpoints are valid only if you purchased SSH Manager for Machines.
The SSH Management APIs allow to manage device keys and keysets. This interface is valid only if you purchased SSH Manager for Machines. All product-supported operations are exp...
The Statistics APIs provide metrics about Trust Protection Foundation operations. You can query, group, and filter data and then use it in your own reporting applications.
The SystemStatus interface provides status and upgrade information about Trust Protection Foundation engines. This information also appears in the UI. # Engine Upgrade Status En...
The Tags API from Venafi — 9 operation(s) for tags.
The Teams API from Venafi — 4 operation(s) for teams.
The Teams interface allows you to associate AD, LDAP, and local Identities to Policy assets and CyberArk products.
The User Accounts API from Venafi — 1 operation(s) for user accounts.
The Preference APIs allow to manages the caller's user preferences
The Users API from Venafi — 7 operation(s) for users.
The VSatellite API from Venafi — 11 operation(s) for vsatellite.
The Webhooks API from Venafi — 2 operation(s) for webhooks.
The Workload Identity Manager Configurations API from Venafi — 2 operation(s) for workload identity manager configurations.
The Workload Identity Manager Intermediate Certificates API from Venafi — 1 operation(s) for workload identity manager intermediate certificates.
The Workload Identity Manager Policies API from Venafi — 2 operation(s) for workload identity manager policies.
The Workload Identity Manager Sub CA Providers API from Venafi — 2 operation(s) for workload identity manager sub ca providers.
Published pricing tiers and plan structures.
Documented rate limits and quota policies.
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
OAuth scopes governing access to this provider's APIs.
aid: venafi
name: Venafi
description: 'Venafi is the machine identity security platform for discovering, issuing, provisioning and retiring TLS/SSL
certificates, SSH keys, code-signing keys and workload identities across data centers, clouds and Kubernetes. Its Control
Plane ships two public REST contracts: the SaaS "Certificate Manager - SaaS" API on api.venafi.cloud (six data-residency
regions) and the self-hosted Trust Protection Foundation WebSDK. Venafi was acquired by CyberArk in 2024 and the products
now carry CyberArk Certificate Manager branding; venafi.com itself 301s to Palo Alto Networks following its acquisition
of CyberArk, while developer.venafi.com, docs.venafi.com, docs.venafi.cloud, api.venafi.cloud and github.com/Venafi remain
live and are where every artifact in this profile came from.'
accessModel:
pricing: unknown
onboarding: self-serve
trial: false
try_now: false
public: false
label: Self-serve signup
confidence: medium
source:
- authentication
- scopes
- rate-limits
- security
- url: https://venafi.com/
status: 301
note: declared website redirects to https://www.paloaltonetworks.com/network-security/next-gen-trust-security/certificate-manager
— a different registrable domain (venafi.com -> paloaltonetworks.com), possible rename or acquisition (probed 2026-09-03,
roadmap#169)
generated: '2026-09-03'
method: derived
image: https://avatars.githubusercontent.com/u/7817722?v=4
url: https://raw.githubusercontent.com/api-evangelist/venafi/refs/heads/main/apis.yml
x-type: company
x-source: harvest:secondary-market
specificationVersion: '0.20'
created: '2026-09-02'
modified: '2026-09-02'
tags:
- Company
- Security
- Certificates
- PKI
- Machine Identity
- Identity
- Cryptography
- Key Management
- Certificate Lifecycle Management
- DevOps
- Kubernetes
- Code Signing
apis:
- aid: venafi:venafi-access-management-apis-api
name: Venafi Access Management APIs API
description: "The endpoints in this section allow you to manage your OAuth environment. \nUsing endpoints described in this\
\ section, you can configure your global OAuth properties, assign roles \nto identities, create and manage applications,\
\ and create grant rules. After these are in \nplace, users can request grants using the authentication server. This section\
\ also includes \ndescriptions of endpoints that allow you to view and revoke issued grants."
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Access Management APIs
properties:
- type: OpenAPI
url: openapi/venafi-access-management-apis-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-algorithmselector-apis-api
name: Venafi AlgorithmSelector APIs API
description: The AlgorithmSelector interface provides the ability to retrieve and configure allowed Key Algorithms for policy,
key and certificate objects
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- AlgorithmSelector APIs
properties:
- type: OpenAPI
url: openapi/venafi-algorithmselector-apis-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-application-api
name: Venafi Application API
description: The Application API from Venafi — 7 operation(s) for application.
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Application
properties:
- type: OpenAPI
url: openapi/venafi-application-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-authentication-server-apis-api
name: Venafi Authentication Server APIs API
description: "The Auth REST SDK manages authorization bearer tokens. The tokens you need are based on the set of API calls\
\ that your client uses.\n\n\nThe Auth SDK uses the VEDauth service to grant access and manage tokens. No installation\
\ is necessary. \nHowever, configuration is required. For more information, see Setting up token authentication."
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Authentication Server APIs
properties:
- type: OpenAPI
url: openapi/venafi-authentication-server-apis-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-approvals-api
name: Venafi Certificate Approvals API
description: The Certificate Approvals API from Venafi — 5 operation(s) for certificate approvals.
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Certificate Approvals
properties:
- type: OpenAPI
url: openapi/venafi-certificate-approvals-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-auto-renewal-monitoring-api
name: Venafi Certificate Auto-renewal Monitoring API
description: The Certificate Auto-renewal Monitoring API from Venafi — 4 operation(s) for certificate auto-renewal monitoring.
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Certificate Auto-renewal Monitoring
properties:
- type: OpenAPI
url: openapi/venafi-certificate-auto-renewal-monitoring-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-discovery-api
name: Venafi Certificate Discovery API
description: The Certificate Discovery API from Venafi — 2 operation(s) for certificate discovery.
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Certificate Discovery
properties:
- type: OpenAPI
url: openapi/venafi-certificate-discovery-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-expiration-reports-api
name: Venafi Certificate Expiration Reports API
description: The Certificate Expiration Reports API from Venafi — 2 operation(s) for certificate expiration reports.
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Certificate Expiration Reports
properties:
- type: OpenAPI
url: openapi/venafi-certificate-expiration-reports-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-import-api
name: Venafi Certificate Import API
description: The Certificate Import API from Venafi — 1 operation(s) for certificate import.
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Certificate Import
properties:
- type: OpenAPI
url: openapi/venafi-certificate-import-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-installations-api
name: Venafi Certificate Installations API
description: The Certificate Installations API from Venafi — 4 operation(s) for certificate installations.
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Certificate Installations
properties:
- type: OpenAPI
url: openapi/venafi-certificate-installations-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-inventory-monitoring-api
name: Venafi Certificate Inventory Monitoring API
description: The Certificate Inventory Monitoring API from Venafi — 3 operation(s) for certificate inventory monitoring.
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Certificate Inventory Monitoring
properties:
- type: OpenAPI
url: openapi/venafi-certificate-inventory-monitoring-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-management-apis-api
name: Venafi Certificate Management APIs API
description: "The endpoints in this section manage TLS certificates. If you want certificates to secure SSH keys, see the\
\ _SshCertificates_ section\n## PKIX Parameter Set ##\nAs of TPP 25.1 algorithms are identified by an OID called PKIX\
\ Parameter Set. The following table lists the OID for each algorithm: \n\n\n\n**RSA Algorithms**\n\n| Algorithm | PKIX\
\ Parameter Set | Description |\n|-----------|--------------------|--------------------------|\n| RSA 1024 | 1.3.6.1.4.1.28783.10.1.1.1024|\
\ RSA 1024 bits offers moderate security but is now considered vulnerable and outdated for most modern applications. |\n\
| RSA 2048 | 1.3.6.1.4.1.28783.10.1.1.2048| RSA 2048 bits offers strong security and is widely used for modern encryption\
\ and digital signatures. |\n| RSA 3072 | 1.3.6.1.4.1.28783.10.1.1.3072| RSA 3072 bits provides a higher security level,\
\ suitable for long-term protection of sensitive data. |\n| RSA 4096 | 1.3.6.1.4.1.28783.10.1.1.4096| RSA 4096 bits offers\
\ very high security, commonly used for highly sensitive data and long-term encryption. |\n| RSA 8192 | 1.3.6.1.4.1.28783.10.1.1.8192|\
\ RSA 8192 bits provides extremely high security, used for the most sensitive data and long-term protection. |\n| RSA\
\ PSS/OAEP 1024 | 1.3.6.1.4.1.28783.10.1.2.1024| RSA 1024 bits PSS provides moderate security for digital signatures,\
\ with PSS offering improved resistance against certain attacks, though it's now considered vulnerable for most applications.\
\ |\n| RSA PSS/OAEP 2048 | 1.3.6.1.4.1.28783.10.1.2.2048| RSA 2048 bits PSS offers strong security with enhanced resistance\
\ to forgery and adaptive chosen-message attacks, making it widely used in modern systems. |\n| RSA PSS/OAEP 3072 | 1.3.6.1.4.1.28783.10.1.2.3072|\
\ RSA 3072 bits PSS provides enhanced security for long-term digital signature protection, with PSS improving resistance\
\ to certain signature-related attacks. |\n| RSA PSS/OAEP 4096 | 1.3.6.1.4.1.28783.10.1.2.4096| RSA 4096 bits PSS provides\
\ very high security for digital signatures, with PSS offering added protection against vulnerabilities in deterministic\
\ signature schemes. |\n| RSA PSS/OAEP 8192 | 1.3.6.1.4.1.28783.10.1.2.8192| RSA 8192 bits PSS offers extremely high security\
\ for critical digital signatures, with PSS further strengthening resistance to advanced cryptographic attacks and long-term\
\ protection. |\n\n**Elliptic Curve Digital Signature Algorithms (ECDSA)**\n\n| Algorithm | PKIX Parameter Set | Description\
\ |\n|-----------|--------------------|--------------------------|\n| ECDSA P-256 | 1.3.6.1.4.1.28783.10.2.1.256| Digital\
\ signature algorithm based on the NIST P-256 curve, providing 128-bit security. |\n| ECDSA P-384 | 1.3.6.1.4.1.28783.10.2.1.384|\
\ Digital signature algorithm based on the NIST P-384 curve, providing 192-bit security. |\n| ECDSA P-521 | 1.3.6.1.4.1.28783.10.2.1.521|\
\ Digital signature algorithm based on the NIST P-521 curve, providing 256-bit security. |\n| Brainpool P-256r1 | 1.3.6.1.4.1.28783.10.2.2.1|\
\ Brainpool P256 is a 256-bit elliptic curve offering strong security for digital signatures and key exchange. |\n| Brainpool\
\ P-384r1 | 1.3.6.1.4.1.28783.10.2.2.2| Brainpool P384 is a 384-bit elliptic curve providing enhanced security for high-assurance\
\ applications. |\n| Brainpool P-512r1 | 1.3.6.1.4.1.28783.10.2.2.3| Brainpool P512 is a 512-bit elliptic curve offering\
\ very high security for sensitive data and long-term protection. |\n| Brainpool P-160r1 | 1.3.6.1.4.1.28783.10.2.2.4|\
\ Brainpool P160 is a 160-bit curve, offering moderate security for lightweight cryptographic applications. |\n| Brainpool\
\ P-160t1 | 1.3.6.1.4.1.28783.10.2.2.5| Brainpool P160T is a 160-bit twisted curve, offering efficient performance and\
\ moderate security for lightweight applications. |\n| Brainpool P-192r1 | 1.3.6.1.4.1.28783.10.2.2.6| Brainpool P192\
\ is a 192-bit curve providing a balanced security level for general-purpose cryptography. |\n| Brainpool P-192t1 | 1.3.6.1.4.1.28783.10.2.2.7|\
\ Brainpool P192T is a 192-bit twisted curve, optimized for faster cryptographic operations with improved security. |\n\
| Brainpool P-224r1 | 1.3.6.1.4.1.28783.10.2.2.8| Brainpool P224 is a 224-bit curve offering strong security for medium-strength\
\ cryptographic applications. |\n| Brainpool P-224t1 | 1.3.6.1.4.1.28783.10.2.2.9| Brainpool P224T is a 224-bit twisted\
\ Edwards curve, optimized for efficient cryptographic operations with strong security. |\n| Brainpool P-256t1 | 1.3.6.1.4.1.28783.10.2.2.10|\
\ Brainpool P256T is a 256-bit twisted curve, optimized for faster operations and improved security in digital signatures\
\ and key exchange. |\n| Brainpool P-320r1 | 1.3.6.1.4.1.28783.10.2.2.11| Brainpool P320 is a 320-bit curve providing\
\ strong security for cryptographic operations, suitable for high-security applications. |\n| Brainpool P-320t1 | 1.3.6.1.4.1.28783.10.2.2.12|\
\ Brainpool P320T is a 320-bit twisted curve, balancing strong security and efficient performance for cryptographic tasks.\
\ |\n| Brainpool P-384t1 | 1.3.6.1.4.1.28783.10.2.2.13| Brainpool P384T is a 384-bit twisted curve providing strong security\
\ for digital signatures and key exchange, optimized for performance and efficiency. |\n| Brainpool P-512t1 | 1.3.6.1.4.1.28783.10.2.2.14|\
\ Brainpool P512T is a 512-bit twisted curve, providing very high security and optimized for efficient cryptographic processing.\
\ |\n| SEC P-256k1 | 1.3.6.1.4.1.28783.10.2.3.1| Sec P256K is a 256-bit curve widely used in Bitcoin and blockchain technologies,\
\ optimized for fast elliptic curve operations. |\n| SEC P-224r1 | 1.3.6.1.4.1.28783.10.2.3.2| Sec P224 is a 224-bit curve\
\ offering strong security for general-purpose cryptography, commonly used in digital signatures. |\n| SEC P-224k1 | 1.3.6.1.4.1.28783.10.2.3.3|\
\ Sec P224K is a 224-bit curve used in cryptographic applications with an emphasis on fast and efficient operations. |\n\
| SEC P-192r1 | 1.3.6.1.4.1.28783.10.2.3.4| Sec P192 is a 192-bit curve providing moderate security for lightweight cryptographic\
\ applications. |\n| SEC P-192k1 | 1.3.6.1.4.1.28783.10.2.3.5| Sec P192K is a 192-bit curve widely used in blockchain\
\ and cryptographic systems, optimized for efficient operations. |\n\n**Edwards Curve Algorithms**\n\n| Algorithm | PKIX\
\ Parameter Set | Description |\n|-----------|--------------------|--------------------------|\n| Ed25519 | 1.3.6.1.4.1.28783.10.3.25519|\
\ Ed25519 is a high-security elliptic curve signature algorithm, designed for fast performance and resistance to side-channel\
\ attacks. |\n| Ed448 | 1.3.6.1.4.1.28783.10.3.44448| Ed448 is a highly secure elliptic curve signature algorithm, offering\
\ stronger security than ED25519, with a larger key size. |\n\n**ML-DSA Quantum-Safe Algorithms**\n\n| Algorithm | PKIX\
\ Parameter Set | Description |\n|-----------|--------------------|--------------------------|\n| ML-DSA44 | 1.3.6.1.4.1.28783.10.4.44|\
\ ML-DSA44 offers 128-bit quantum security, designed for lightweight applications that require post-quantum resilience\
\ with moderate security. |\n| ML-DSA65 | 1.3.6.1.4.1.28783.10.4.65| ML-DSA65 provides 192-bit quantum security, offering\
\ stronger protection against quantum adversaries while maintaining efficiency for broader use cases. |\n| ML-DSA87 |\
\ 1.3.6.1.4.1.28783.10.4.87| ML-DSA87 delivers 256-bit quantum security, designed for high-assurance applications needing\
\ robust resistance to future quantum computing threats. |\n\n**SLH-DSA Quantum-Safe Algorithms**\n\n| Algorithm | PKIX\
\ Parameter Set | Description |\n|-----------|--------------------|--------------------------|\n| SLH-DSA-SHA2-128s |\
\ 1.3.6.1.4.1.28783.10.5.1.1| SLH-DSA SHA2 128bit Small: Offers 128-bit security with SHA-2, optimized for small footprint\
\ applications. |\n| SLH-DSA-SHA2-128f | 1.3.6.1.4.1.28783.10.5.1.2| SLH-DSA SHAKE 128bit Fast: Delivers 128-bit security\
\ with SHAKE, optimized for fast performance. |\n| SLH-DSA-SHA2-192s | 1.3.6.1.4.1.28783.10.5.1.3| SLH-DSA SHA2 192bit\
\ Small: Offers 192-bit security with SHA-2, suitable for small footprint applications. |\n| SLH-DSA-SHA2-192f | 1.3.6.1.4.1.28783.10.5.1.4|\
\ SLH-DSA SHA2 192bit Fast: Ensures 192-bit security with SHA-2, optimized for fast performance. |\n| SLH-DSA-SHA2-256s\
\ | 1.3.6.1.4.1.28783.10.5.1.5| SLH-DSA SHA2 256bit Small: Offers 256-bit security with SHA-2, suitable for small footprint\
\ applications. |\n| SLH-DSA-SHA2-256f | 1.3.6.1.4.1.28783.10.5.1.6| SLH-DSA SHA2 256bit Small: Offers 256-bit security\
\ with SHA-2, suitable for small footprint applications. |\n| SLH-DSA-Shake-128s | 1.3.6.1.4.1.28783.10.5.1.7| SLH-DSA\
\ SHAKE 128bit Small: Provides 128-bit security with SHAKE, designed for small footprint applications. |\n| SLH-DSA-Shake-128f\
\ | 1.3.6.1.4.1.28783.10.5.1.8| SLH-DSA SHAKE 128bit Fast: Ensures 128-bit security with SHAKE, optimized for fast performance.\
\ |\n| SLH-DSA-Shake-192s | 1.3.6.1.4.1.28783.10.5.1.9| SLH-DSA SHAKE 192bit Small: Provides 192-bit security with SHAKE,\
\ designed for small footprint applications. |\n| SLH-DSA-Shake-192f | 1.3.6.1.4.1.28783.10.5.1.10| SLH-DSA SHAKE 192bit\
\ Fast: Delivers 192-bit security with SHAKE, optimized for fast performance. |\n| SLH-DSA-Shake-256s | 1.3.6.1.4.1.28783.10.5.1.11|\
\ SLH-DSA SHAKE 256bit Small: Offers 256-bit security with SHAKE, suitable for small footprint applications. |\n| SLH-DSA-Shake-256f\
\ | 1.3.6.1.4.1.28783.10.5.1.12| SLH-DSA SHA2 256bit Fast: Offers 256-bit security with SHAKE, optimized for fast performance.\
\ |\n\n**Pre-Hash SLH-DSA Quantum-Safe Algorithms**\n\n| Algorithm | PKIX Parameter Set | Description |\n|-----------|--------------------|--------------------------|\n\
| HASH-SLH-DSA-SHA2-128s-SHA256 | 1.3.6.1.4.1.28783.10.5.2.1| Pre-Hash SLH-DSA SHA2 128bit Small: Offers 128-bit security\
\ with SHA-2, optimized for small footprint applications. |\n| HASH-SLH-DSA-SHA2-128f-SHA256 | 1.3.6.1.4.1.28783.10.5.2.2|\
\ Pre-Hash SLH-DSA SHA2 128bit Fast: Delivers 128-bit security with SHA-2, optimized for fast performance. |\n| HASH-SLH-DSA-SHA2-192s-SHA512\
\ | 1.3.6.1.4.1.28783.10.5.2.3| Pre-Hash SLH-DSA SHA2 192bit Small: Offers 192-bit security with SHA-2, suitable for small\
\ footprint applications. |\n| HASH-SLH-DSA-SHA2-192f-SHA512 | 1.3.6.1.4.1.28783.10.5.2.4| Pre-Hash SLH-DSA SHA2 192bit\
\ Fast: Ensures 192-bit security with SHA-2, optimized for fast performance. |\n| HASH-SLH-DSA-SHA2-256s-SHA512 | 1.3.6.1.4.1.28783.10.5.2.5|\
\ Pre-Hash SLH-DSA SHA2 256bit Small: Offers 256-bit security with SHA-2, suitable for small footprint applications. |\n\
| HASH-SLH-DSA-SHA2-256f-SHA512 | 1.3.6.1.4.1.28783.10.5.2.6| Pre-Hash SLH-DSA SHA2 256bit Small: Offers 256-bit security\
\ with SHA-2, suitable for small footprint applications. |\n| HASH-SLH-DSA-Shake-128s-Shake128 | 1.3.6.1.4.1.28783.10.5.2.7|\
\ Pre-Hash SLH-DSA SHAKE 128bit Small: Provides 128-bit security with SHAKE, designed for small footprint applications.\
\ |\n| HASH-SLH-DSA-Shake-128f-Shake128 | 1.3.6.1.4.1.28783.10.5.2.8| Pre-Hash SLH-DSA SHA2 128bit Fast: Ensures 128-bit\
\ security with SHA-2, optimized for fast performance. |\n| HASH-SLH-DSA-Shake-192s-SHAke256 | 1.3.6.1.4.1.28783.10.5.2.9|\
\ Pre-Hash SLH-DSA SHAKE 192bit Small: Provides 192-bit security with SHAKE, designed for small footprint applications.\
\ |\n| HASH-SLH-DSA-Shake-192f-SHAke256 | 1.3.6.1.4.1.28783.10.5.2.10| Pre-Hash SLH-DSA SHAKE 192bit Fast: Delivers 192-bit\
\ security with SHAKE, optimized for fast performance. |\n| HASH-SLH-DSA-Shake-256s-SHAke256 | 1.3.6.1.4.1.28783.10.5.2.11|\
\ Pre-Hash SLH-DSA SHA2 256bit Small: Offers 256-bit security with SHA-2, suitable for small footprint applications. |\n\
| HASH-SLH-DSA-Shake-256f-SHAke256 | 1.3.6.1.4.1.28783.10.5.2.12| Pre-Hash SLH-DSA SHA2 256bit Fast: Offers 256-bit security\
\ with SHAKE, optimized for fast performance. |\n\n**Composite Quantum-Safe Algorithms**\n\n| Algorithm | PKIX Parameter\
\ Set | Description |\n|-----------|--------------------|--------------------------|\n| Composite ML-DSA44 / PSS2048 |\
\ 1.3.6.1.4.1.28783.10.7.1| ML-DSA44 / RSA 2048 PSS combines 128-bit quantum security of ML-DSA44 with RSA2048PSS, suitable\
\ for moderate security applications requiring post-quantum and classical resilience. |\n| Composite ML-DSA44 / RSA2048\
\ | 1.3.6.1.4.1.28783.10.7.2| ML-DSA44 / RSA 2048 combines 128-bit quantum security of ML-DSA44 with RSA 2048, suitable\
\ for moderate security applications requiring post-quantum and classical resilience. |\n| Composite ML-DSA44 / Ed25519\
\ | 1.3.6.1.4.1.28783.10.7.3| ML-DSA44 / Ed25519 offers 128-bit quantum security of ML-DSA44 with Ed25519, optimized for\
\ fast and secure digital signatures. |\n| Composite ML-DSA44 / ECP256 | 1.3.6.1.4.1.28783.10.7.4| ML-DSA44 / ECP256 provides\
\ 128-bit quantum security of ML-DSA44 with ECDSA P-256, ideal for secure communications and data integrity. |\n| Composite\
\ ML-DSA65 / PSS3072 | 1.3.6.1.4.1.28783.10.7.5| ML-DSA65 / RSA 3072 PSS combines 192-bit quantum security of ML-DSA65\
\ with RSA 3072 PSS, suitable for long-term protection and moderate security applications. |\n| Composite ML-DSA65 / RSA3072\
\ | 1.3.6.1.4.1.28783.10.7.6| ML-DSA65 / RSA 3072 offers 192-bit quantum security of ML-DSA65 with RSA 3072, ideal for\
\ secure communications and data integrity. |\n| Composite ML-DSA65 / PSS4096 | 1.3.6.1.4.1.28783.10.7.7| ML-DSA65 / RSA\
\ 4096 PSS provides 192-bit quantum security of ML-DSA65 with RSA 4096 PSS, suitable for highly sensitive data and long-term\
\ protection. |\n| Composite ML-DSA65 / RSA4096 | 1.3.6.1.4.1.28783.10.7.8| ML-DSA65 / RSA 4096 combines 192-bit quantum\
\ security of ML-DSA65 with RSA 4096, ideal for high-security applications needing long-term protection. |\n| Composite\
\ ML-DSA65 / ECP256 | 1.3.6.1.4.1.28783.10.7.9| ML-DSA65 / ECP256 offers 192-bit quantum security of ML-DSA65 with ECDSA\
\ P-256, designed for secure communications and data integrity. |\n| Composite ML-DSA65 / ECP384 | 1.3.6.1.4.1.28783.10.7.10|\
\ ML-DSA65 / ECP384 offers 192-bit quantum security of ML-DSA65 with ECDSA P-384, ideal for high-security applications\
\ needing long-term protection. |\n| Composite ML-DSA65 / Brainpool P-256 | 1.3.6.1.4.1.28783.10.7.11| ML-DSA65 / Brainpool\
\ P-256 provides 192-bit quantum security of ML-DSA65 with Brainpool P-256, designed for secure communications and data\
\ integrity. |\n| Composite ML-DSA65 / Ed25519 | 1.3.6.1.4.1.28783.10.7.12| ML-DSA65 / Ed25519 combines 192-bit quantum\
\ security of ML-DSA65 with Ed25519, optimized for fast and secure digital signatures. |\n| Composite ML-DSA87 / ECP384\
\ | 1.3.6.1.4.1.28783.10.7.13| ML-DSA87 / ECP384 ensures 256-bit quantum security of ML-DSA87 with ECDSA P-384, suitable\
\ for highly sensitive data and long-term protection. |\n| Composite ML-DSA87 / Brainpool P-384 | 1.3.6.1.4.1.28783.10.7.14|\
\ ML-DSA87 / Brainpool P-384 offers 256-bit quantum security of ML-DSA87 with Brainpool P-384, ideal for secure financial\
\ transactions and data integrity. |\n| Composite ML-DSA87 / Ed448 | 1.3.6.1.4.1.28783.10.7.15| ML-DSA87 / Ed448 combines\
\ 256-bit quantum security of ML-DSA87 with Ed448, designed for high-security digital signatures and fast performance.\
\ |\n| Composite ML-DSA87 / PSS4096 | 1.3.6.1.4.1.28783.10.7.16| ML-DSA87 / RSA 4096 PSS provides 256-bit quantum security\
\ of ML-DSA87 with RSA 4096 PSS, suitable for highly sensitive data and long-term protection. |\n| Composite ML-DSA87\
\ / PSS3072 | 1.3.6.1.4.1.28783.10.7.17| ML-DSA87 / RSA 3072 PSS provides 256-bit quantum security of ML-DSA87 with RSA\
\ 3072 PSS, suitable for highly sensitive data and long-term protection. |\n| Composite ML-DSA87 / ECP521 | 1.3.6.1.4.1.28783.10.7.18|\
\ ML-DSA87 / ECP521 ensures 256-bit quantum security of ML-DSA87 with ECDSA P-521, suitable for highly sensitive data\
\ and long-term protection. |"
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Certificate Management APIs
properties:
- type: OpenAPI
url: openapi/venafi-certificate-management-apis-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-policy-api
name: Venafi Certificate Policy API
description: The Certificate Policy API from Venafi — 3 operation(s) for certificate policy.
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Certificate Policy
properties:
- type: OpenAPI
url: openapi/venafi-certificate-policy-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-request-api
name: Venafi Certificate Request API
description: The Certificate Request API from Venafi — 5 operation(s) for certificate request.
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Certificate Request
properties:
- type: OpenAPI
url: openapi/venafi-certificate-request-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificate-revocation-approvals-api
name: Venafi Certificate Revocation Approvals API
description: The Certificate Revocation Approvals API from Venafi — 2 operation(s) for certificate revocation approvals.
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Certificate Revocation Approvals
properties:
- type: OpenAPI
url: openapi/venafi-certificate-revocation-approvals-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
- aid: venafi:venafi-certificates-api
name: Venafi Certificates API
description: The Certificates API from Venafi — 8 operation(s) for certificates.
humanURL: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
baseURL: https://api.venafi.cloud
tags:
- Certificates
properties:
- type: OpenAPI
url: openapi/venafi-certificates-api-openapi.yml
- type: Documentation
url: https://developer.venafi.com/tlsprotectcloud/reference/tls-protect-overview
- type: Webhooks
url: asyncapi/venafi-certificate-manager-saas-webhooks.yml
- type: Documentation
url: https://docs.venafi.com/Docs/currentSDK/TopNav/Content/SDK/WebSDK/cco-sdk-GettingStarted.php
# --- truncated at 32 KB (78 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/venafi/refs/heads/main/apis.yml
Every provider here is available over the APIs.io API and to AI agents over MCP.