# Xbow

**Canonical:** https://apis.io/providers/xbow/  
**Website:** https://xbow.com  
**APIs profiled:** 9

XBOW is an autonomous offensive security platform that uses AI to perform penetration testing with real exploit validation — it identifies vulnerabilities, chains them into attack paths, and proves exploitability before findings reach security teams. The XBOW API (public preview) exposes the full platform workflow: register assets, launch and manage assessments, fetch validated findings and reports, upload source-code resources for gray-box testing, and subscribe webhooks with Ed25519-signed deliveries. XBOW has ranked #1 on the HackerOne and Microsoft MSRC leaderboards and is used by 150+ security teams.

## Kin Score — 58.0 / 100 (strong)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 58.0).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 67.9 |
| Governance | 11.5 |
| Operational Transparency | 63.2 |
| Developer Ergonomics | 56.0 |
| Commercial Clarity | 60.5 |

## Agent readiness — 46.6 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | derived |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | verified |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (9)

- **Xbow Assessments API** — Endpoints related to assessments for assets. All endpoints require an _organization_ API key.
- **Xbow Assets API** — Endpoints related to assets within an organization. All endpoints require an _organization_ API key.
- **Xbow Findings API** — Endpoints for viewing and managing findings. All endpoints require an _organization_ API key.
- **Xbow Lightspeed API** — Endpoints related to Lightspeed assessment requests.
- **Xbow Meta API** — Instance metadata endpoints.
- **Xbow Organizations API** — Endpoints related to organizations and their management.
- **Xbow Reports API** — Endpoints for downloading and viewing reports. All endpoints require an _organization_ API key.
- **Xbow Resources API** — Upload and manage files used in assessments, such as source code archives. All endpoints require an _organization_ API key. ## Upload flow Resources use a multipart S3 upload. T...
- **Xbow Webhooks API** — Manage webhook subscriptions and receive event notifications. When creating an organization, you may provide an HTTPS webhook URL to receive events related to the organization's...

## MCP servers (1)

- **xbow-mcp.yml**

## Agentic access (1)

- **Xbow Agentic Access** — 40 operations · 21 acting · 1 human-in-the-loop

## Security (4)

- **Xbow Authentication** — http · 1 scheme
- **Xbow Domain Security** — TLSv1.3 · HSTS · DMARC
- **Xbow Vulnerability Disclosure** — contact published
- **Xbow Trust Center** — SOC 2 Type 1, SOC 2 Type 2, GDPR, HIPAA

## Tags

Security, Penetration Testing, Offensive Security, Artificial Intelligence, Vulnerability Management, Cybersecurity, Application Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/xbow/). Scores are computed from the provider's own public artifacts under a published rubric.
