Home
Providers
Zero Trust Network Access
Zero Trust Network Access
Zero Trust Network Access (ZTNA) is a security framework and product category that grants access to private applications and resources based on identity, device posture, and context, rather than network location. ZTNA replaces the implicit trust of legacy VPNs with explicit per-request verification, creating one-to-one encrypted tunnels between authenticated users and the specific applications they are authorized to use. This topic collects the leading ZTNA vendors, the standards bodies that govern the underlying primitives, and the data schemas used to describe access policies, identities, devices, and resources.
Zero Trust Network Access publishes 6 APIs on the APIs.io network, including Deployment Groups API, Devices API, DEX Tests API, and 3 more. Tagged areas include Access Control, Cloud Security, Cybersecurity, Identity Management, and Network Access.
The Zero Trust Network Access catalog on APIs.io includes 1 JSON-LD context and 1 Spectral governance ruleset.
Zero Trust Network Access’ developer surface includes documentation, developer portal, code examples, and 19 more developer resources.
12 APIs
8 Features
6 Use Cases
On this page
Kin Score
APIs 12
Open Collections 7
GraphQL 1
Pricing Plans 1
Rate Limits 1
FinOps 1
Features 8
Vocabularies 1
Spectral Rules 1
JSON Schema 3
JSON Structure 1
Examples 2
Security Posture 2
Use Cases 6
Resources 22
apis.yml
11 Operational Transparency
Composite quality — 33.1/100 · thin
Contract Quality
14.8 / 25
Developer Ergonomics
3.8 / 20
Operational Transparency
1.4 / 13
Contract Governance
1.2 / 12
Agent readiness — 19/100 · agent aware
Machine-Readable Contract
18 / 18
Agentic Access Contract
0 / 10
Documented Reversibility
0 / 6
MCP Server
0 / 12
Machine-Readable Auth
10 / 10
Idempotency
0 / 9
Stable Error Semantics
0 / 8
Request/Response Examples
7 / 7
Rate-Limit Signaling
7 / 7
Typed Event Surface
0 / 6
Agent Skills
0 / 5
Well-Known Catalog
0 / 4
Consent & Bot Identity
0 / 3
A2A Agent Card
0 / 8
Dry-Run / Simulate Mode
0 / 4
Delegated User Identity
0 / 6
Protected Resource Metadata
0 / 5
Registration Without a Human
0 / 6
Agentic Commerce Surface
0 / 5
Individual APIs this provider publishes, each with its own machine-readable definition.
Scroll for all 12
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Scroll for all 7
GraphQL schemas published by this provider.
Published pricing tiers and plan structures.
Documented rate limits and quota policies.
Cost, billing, and metering signals for API financial operations.
Notable capabilities this provider offers.
Scroll for all 8
JSON-LD contexts and semantic vocabularies used across these APIs.
Spectral governance rulesets for linting and validating these APIs.
Standalone JSON Schema definitions for this provider's data models.
JSON Structure definitions describing this provider's data shapes.
Example request and response payloads for these APIs.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
What developers build with this provider.
Get Started 6
Portal, sign-up, and the first successful call
Documentation 6
Reference material describing how the API behaves
Design & Contract 2
Pagination, idempotency, versioning, errors, and events
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 3
Authentication, authorization, and security posture
Other 1
Properties that don't map to a standard resource type
Source (apis.yml)
aid: zero-trust-network-access
accessModel:
pricing: freemium
onboarding: unknown
trial: false
try_now: false
public: false
label: Freemium
confidence: medium
source:
- plans
generated: '2026-07-22'
method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/zero-trust-network-access.png
name: Zero Trust Network Access
description: Zero Trust Network Access (ZTNA) is a security framework and product category that grants access to private applications
and resources based on identity, device posture, and context, rather than network location. ZTNA replaces the implicit trust
of legacy VPNs with explicit per-request verification, creating one-to-one encrypted tunnels between authenticated users
and the specific applications they are authorized to use. This topic collects the leading ZTNA vendors, the standards bodies
that govern the underlying primitives, and the data schemas used to describe access policies, identities, devices, and resources.
type: Index
url: https://www.cloudflare.com/learning/security/glossary/what-is-zero-trust/
tags:
- Access Control
- Cloud Security
- Cybersecurity
- Identity Management
- Network Access
- Network Security
- Security
- VPN Replacement
- Zero Trust
- ZTNA
created: '2025'
modified: '2026-05-03'
specificationVersion: '0.23'
apis:
- aid: zero-trust-network-access:cloudflare-zero-trust
name: Cloudflare Zero Trust API
description: Cloudflare Zero Trust (formerly Cloudflare for Teams / Cloudflare Access) provides ZTNA, secure web gateway,
browser isolation, CASB, and DLP through a single global edge platform. The Cloudflare API exposes endpoints for managing
Access applications, policies, identity providers, device posture, tunnels, and gateway rules.
humanURL: https://developers.cloudflare.com/cloudflare-one/
tags:
- Cloudflare
- SASE
- ZTNA
properties:
- type: Documentation
url: https://developers.cloudflare.com/cloudflare-one/
- type: APIReference
url: https://developers.cloudflare.com/api/
- type: Authentication
url: https://developers.cloudflare.com/fundamentals/api/get-started/keys/
- url: graphql/zero-trust-network-access-graphql.md
type: GraphQL
- aid: zero-trust-network-access:zscaler-zpa
name: Zscaler Private Access (ZPA) API
description: Zscaler Private Access is a cloud-native ZTNA service that connects authenticated users to private applications
without exposing them to the internet or placing them on the corporate network. The ZPA Public API supports application
segments, server groups, policies, posture profiles, and connector groups.
humanURL: https://help.zscaler.com/zpa/api-reference
tags:
- SASE
- Zscaler
- ZTNA
properties:
- type: Documentation
url: https://help.zscaler.com/zpa
- type: APIReference
url: https://help.zscaler.com/zpa/api-reference
- aid: zero-trust-network-access:netskope-private-access
name: Netskope Private Access API
description: Netskope Private Access provides ZTNA as part of the Netskope SASE platform, brokering authenticated access
to private applications across cloud and on-premises. The Netskope REST API surfaces operations on private apps, publishers,
policies, and risk events.
humanURL: https://docs.netskope.com/en/netskope-help/admin-console/rest-api/
tags:
- Netskope
- SASE
- ZTNA
properties:
- type: Documentation
url: https://docs.netskope.com/en/netskope-help/admin-console/rest-api/
- aid: zero-trust-network-access:palo-alto-prisma-access
name: Palo Alto Prisma Access (Prisma SASE) API
description: Palo Alto Networks Prisma Access offers cloud-delivered ZTNA, SWG, and FWaaS as part of the Prisma SASE platform.
The Prisma Access REST API exposes operations on remote networks, mobile users, security policies, and decryption rules.
humanURL: https://docs.paloaltonetworks.com/prisma/prisma-access
tags:
- Palo Alto
- SASE
- ZTNA
properties:
- type: Documentation
url: https://docs.paloaltonetworks.com/prisma/prisma-access
- aid: zero-trust-network-access:tailscale-api
name: Tailscale API
description: Tailscale is a WireGuard-based mesh-VPN ZTNA platform that exposes a REST API for managing devices, ACL policies,
tailnet keys, DNS, and audit logs. It implements identity-based device-to-device tunnels brokered by an identity-aware
control plane.
humanURL: https://tailscale.com/api
tags:
- Mesh VPN
- Tailscale
- WireGuard
- ZTNA
properties:
- type: Documentation
url: https://tailscale.com/api
- type: APIReference
url: https://tailscale.com/api
- type: GitHubOrganization
url: https://github.com/tailscale
- aid: zero-trust-network-access:twingate-api
name: Twingate API
description: Twingate is a software-defined ZTNA platform that exposes a GraphQL Admin API for managing remote networks,
resources, groups, users, service accounts, and connectors.
humanURL: https://www.twingate.com/docs/api
tags:
- Twingate
- ZTNA
properties:
- type: Documentation
url: https://www.twingate.com/docs/api
- type: APIReference
url: https://www.twingate.com/docs/api
- aid: zero-trust-network-access:zero-trust-network-access-deployment-groups-api
name: Zero Trust Network Access Deployment Groups API
description: Account-level WARP deployment groups.
humanURL: https://developers.cloudflare.com/cloudflare-one/
tags:
- Deployment Groups
properties:
- type: OpenAPI
url: openapi/zero-trust-network-access-deployment-groups-api-openapi.yml
- aid: zero-trust-network-access:zero-trust-network-access-devices-api
name: Zero Trust Network Access Devices API
description: WARP devices enrolled in Zero Trust.
humanURL: https://developers.cloudflare.com/cloudflare-one/
tags:
- Devices
properties:
- type: OpenAPI
url: openapi/zero-trust-network-access-devices-api-openapi.yml
- aid: zero-trust-network-access:zero-trust-network-access-dex-tests-api
name: Zero Trust Network Access DEX Tests API
description: Digital Experience Monitoring tests.
humanURL: https://developers.cloudflare.com/cloudflare-one/
tags:
- DEX Tests
properties:
- type: OpenAPI
url: openapi/zero-trust-network-access-dex-tests-api-openapi.yml
- aid: zero-trust-network-access:zero-trust-network-access-ip-profiles-api
name: Zero Trust Network Access IP Profiles API
description: WARP device IP profiles.
humanURL: https://developers.cloudflare.com/cloudflare-one/
tags:
- IP Profiles
properties:
- type: OpenAPI
url: openapi/zero-trust-network-access-ip-profiles-api-openapi.yml
- aid: zero-trust-network-access:zero-trust-network-access-registrations-api
name: Zero Trust Network Access Registrations API
description: Per-user WARP registrations on a device.
humanURL: https://developers.cloudflare.com/cloudflare-one/
tags:
- Registrations
properties:
- type: OpenAPI
url: openapi/zero-trust-network-access-registrations-api-openapi.yml
- aid: zero-trust-network-access:zero-trust-network-access-warp-override-api
name: Zero Trust Network Access WARP Override API
description: Global Cloudflare WARP override state.
humanURL: https://developers.cloudflare.com/cloudflare-one/
tags:
- WARP Override
properties:
- type: OpenAPI
url: openapi/zero-trust-network-access-warp-override-api-openapi.yml
common:
- type: VulnerabilityDisclosure
url: security/zero-trust-network-access-vulnerability-disclosure.yml
- type: DomainSecurity
url: security/zero-trust-network-access-domain-security.yml
- type: Documentation
title: Cloudflare - What Is Zero Trust
url: https://www.cloudflare.com/learning/security/glossary/what-is-zero-trust/
description: Cloudflare's reference explainer on Zero Trust security and ZTNA.
- type: Documentation
title: Gartner Definition of ZTNA
url: https://www.gartner.com/en/information-technology/glossary/zero-trust-network-access-ztna-
description: Gartner glossary entry defining ZTNA as a market category.
- type: Documentation
title: NIST SP 800-207 (ZTA underpinnings of ZTNA)
url: https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-207.pdf
description: NIST Special Publication 800-207 - the architectural foundation behind ZTNA.
- type: Compliance
title: CISA Zero Trust Maturity Model
url: https://www.cisa.gov/zero-trust-maturity-model
description: CISA Zero Trust Maturity Model that ZTNA deployments are commonly aligned to.
- type: Portal
title: Cloudflare Zero Trust
url: https://www.cloudflare.com/zero-trust/
- type: Portal
title: Zscaler Zero Trust Exchange
url: https://www.zscaler.com/products-and-solutions/zero-trust-exchange
- type: Portal
title: Netskope SASE
url: https://www.netskope.com/platform/sase
- type: Portal
title: Palo Alto Networks Prisma Access
url: https://www.paloaltonetworks.com/sase/access
- type: Portal
title: Tailscale
url: https://tailscale.com/
- type: Portal
title: Twingate
url: https://www.twingate.com/
- type: GitHubOrganization
title: Tailscale on GitHub
url: https://github.com/tailscale
- type: GitHubOrganization
title: WireGuard
url: https://github.com/WireGuard
- type: JSONSchema
title: ZTNA Access Policy Schema
url: json-schema/zero-trust-network-access-policy-schema.json
- type: JSONSchema
title: ZTNA Application Schema
url: json-schema/zero-trust-network-access-application-schema.json
- type: JSONSchema
title: ZTNA Device Posture Schema
url: json-schema/zero-trust-network-access-device-posture-schema.json
- type: JSONStructure
title: ZTNA Access Policy Structure
url: json-structure/zero-trust-network-access-policy-structure.json
- type: JSONLD
title: ZTNA JSON-LD Context
url: json-ld/zero-trust-network-access-context.jsonld
- type: CodeExamples
title: ZTNA Access Policy Example
url: examples/zero-trust-network-access-policy-example.json
- type: CodeExamples
title: ZTNA Device Posture Example
url: examples/zero-trust-network-access-device-posture-example.json
- type: Resources
title: ZTNA Vocabulary
url: vocabulary/zero-trust-network-access-vocabulary.yaml
- type: Features
data:
- name: Identity-Centric Access
description: Access decisions are based on user and workload identity rather than network location.
- name: Application-Level Tunnels
description: One-to-one encrypted connections between authenticated users and specific applications.
- name: Device Posture Checks
description: Continuous evaluation of device health, OS patch level, EDR status, and certificate state.
- name: Context-Aware Policy
description: Policies factor in time, location, risk score, and behavior in addition to identity.
- name: Application Cloaking
description: Private applications are dark to the public internet and not advertised by IP or DNS.
- name: SSO and MFA Integration
description: Native integration with SAML, OIDC, and modern MFA providers.
- name: Microsegmentation
description: Lateral movement is prevented by issuing scoped, per-application access.
- name: Continuous Authorization
description: Sessions are reauthenticated and reauthorized as conditions change.
- type: UseCases
data:
- name: VPN Replacement
description: Replacing legacy site-to-site and remote-access VPNs with identity-aware brokered access.
- name: Third-Party Contractor Access
description: Granting time-bounded, application-scoped access to vendors and contractors.
- name: M&A Network Integration
description: Enabling acquired companies to reach internal applications without merging networks.
- name: BYOD Access
description: Allowing personal and unmanaged devices to access selected applications under posture rules.
- name: Privileged Access
description: Brokering jump-host and bastion access to sensitive infrastructure.
- name: Multi-Cloud Application Access
description: Providing consistent ZTNA across applications hosted in AWS, Azure, GCP, and on-premises.
- type: Integrations
data:
- name: Okta
description: Enterprise identity provider used by virtually all ZTNA platforms.
- name: Microsoft Entra ID
description: Cloud identity platform integrated as IdP for ZTNA brokers.
- name: CrowdStrike Falcon
description: EDR signals fed into ZTNA device-posture rules.
- name: SentinelOne
description: EDR signals fed into ZTNA device-posture rules.
- name: Jamf
description: macOS / iOS MDM signals integrated into device posture for ZTNA.
- name: Intune
description: Microsoft Endpoint Manager signals integrated into device posture for ZTNA.
- name: Splunk
description: SIEM destination for ZTNA access and audit logs.
- name: ServiceNow
description: ITSM workflow integration for granting and revoking ZTNA access.
- type: Integrations
url: https://www.cloudflare.com/partners/technology-partners/
integrations:
- name: Google cloud
- name: Cyber Risk-icon
- name: Identity Providers-icon
- name: Mobile Device Management-icon
- name: Threat Intelligence-icon
- name: Network Observability-icon
- name: Edge Database-icon
- name: Workers Observability-icon
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Every provider here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for providers
9 MCP tools reach this
find_providersBrowse and filter every provider in the catalog.
get_provider_artifactsEvery artifact this provider publishes, grouped by type.
get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
get_provider_ratingPRO — composite, band, trend and facet scores.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools
Call it yourself
curl for this page
This provider
curl "https://apis.io/api/v1/providers/zero-trust-network-access"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/zero-trust-network-access/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/zero-trust-network-access/evidence"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no email required.
A second provider on the same verified email joins the account you already have.