# Veza

**Canonical:** https://apis.io/providers/veza/  
**Website:** https://www.veza.com/  
**APIs profiled:** 1

Veza is an identity security platform. Its Open Authorization API (OAA) publishes identity, resource, and authorization metadata from custom or unsupported applications into the Veza Entity Catalog, making access across systems searchable and governable for least-privilege enforcement, access reviews, and rules and alerts. The REST API manages custom providers and their data sources, pushes OAA JSON payloads (users, groups, roles, resources, permissions), and runs authorization assessment queries and reports. It authenticates with a per-tenant API key presented as a bearer token, with official Python and C# SDKs and a command-line client.

## Kin Score — 41.3 / 100 (developing)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 41.3).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 45.1 |
| Governance | 4.5 |
| Contract Governance | 4.5 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 68.5 |
| Commercial Clarity | 23.7 |
| Access Clarity | 23.7 |

## Agent readiness — 33.5 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **Veza Open Authorization API (OAA)** — Publish identity, resource and authorization metadata from custom or unsupported applications into the Veza Entity Catalog, and run authorization assessment queries and reports.

## MCP servers (1)

- **Veza MCP Server**

## Security (2)

- **Veza Authentication** — apiKey · 1 scheme
- **Veza Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC

## Tags

Company, Security, Identity Security, Authorization, Access Management, Identity Governance

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/veza/). Scores are computed from the provider's own public artifacts under a published rubric.
