Zuplo
Zuplo is the API management platform for developers. Build, deploy, and scale APIs faster with Zuplo.
Zuplo publishes 13 APIs on the APIs.io network, including API Keys - Buckets API, API Keys - Consumers API, API Keys - Keys API, and 10 more. Tagged areas include AI Gateway, API Management, Gateways, and Platform.
The Zuplo catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
Zuplo’s developer surface includes authentication, documentation, pricing, engineering blog, signup flow, support, changelog, and 60 more developer resources.
Kin Score
What adopting Zuplo moves on the Kin Score 15
Zuplo is an area vendor: providers adopt it to run part of their developer surface. This is the Kin Score checks its features can move for a provider that adopts it, what each one really earns, and what it earns nothing for.
Zuplo’s lift lands on access clarity and agent readiness: a public pricing page with multiple plans, self-serve sign-up and keys, a try-it console, an MCP server generated from the provider’s own routes on the provider’s own gateway host (graded templated, 0.6), and a served OAuth protected-resource document that also earns the composite .well-known check. The portal only counts once the provider declares it in apis.yml, the rate-limit policy emits Retry-After — a header the verified grade accepts, but only once the provider declares it on its 429 responses in its own OpenAPI — and the RFC 7807 error envelope scores only when the provider writes that schema into its own contract.
| Check | Earns | Through |
|---|---|---|
| MCP Servertemplated Agent ReadinessTools are generated from the provider’s own gateway routes and served on the provider’s own gateway host (custom domain possible), which is templated (0.6), not platform. It reaches verified only if the catalog’s probe of the provider’s mcp/ manifest … |
7.2 of 12 | MCP Server handler |
| Protected Resource Metadata Agent ReadinessRegister the plugin with the authorization server’s issuer and serve it on the host the catalog probes; the served document carries both resource and authorization_servers. |
5.0 of 5 | OAuthProtectedResourcePlugin |
| Rate-Limit Signalingpartial Agent Readiness verified reads response headers declared in the provider’s OpenAPI; score.rb’s RATELIMIT_HEADER_RE (/\A(x-)?ratelimit|\Aretry-after\z/i) accepts Retry-After, which the policy emits by default. But nothing fetched shows Zuplo writing that header into the s… |
3.5 of 7 | Rate limiting inbound policy (429 + Retry-After) |
| Plans published Access ClarityPublish at least one plan on the public Pricing page; the catalog’s plans artifact is harvested from it. |
8.0 of 8 | Monetization plugin — public pricing page, subscriptions, usage dashboard |
| Rate limits documented Operational TransparencyShow per-plan quotas/limits on the public Pricing page (or a docs page) so the rate_limits artifact can be harvested. |
8.0 of 8 | Monetization plugin — public pricing page, subscriptions, usage dashboard |
| Serves a .well-known surface DiscoverabilityServe the protected-resource document on the provider’s own API host so the well-known probe finds it; the check accepts a protected-resource doc as one of its four qualifying files. |
6.0 of 6 | OAuthProtectedResourcePlugin |
| Self-service sign-up Access ClarityDeclare the portal sign-up/login URL as a SignUp or Login entry in apis.yml common[]. |
5.0 of 5 | Self-serve sign-up and API key management |
| Developer portal Developer ErgonomicsDeclare the portal URL as a DeveloperPortal entry in apis.yml common[]. |
4.0 of 4 | Developer portal (Zudoku) generated from OpenAPI |
| Pricing published Access ClarityEnable the monetization plugin and declare the portal Pricing page as a Pricing entry in apis.yml common[]. |
4.0 of 4 | Monetization plugin — public pricing page, subscriptions, usage dashboard |
| Publishes llms.txt DiscoverabilityBuilt from the provider’s own portal pages and served on the provider’s portal domain, so it is authored from first-party content (rule 2). It is opt-in ( llmsTxt), so it only counts once turned on. |
4.0 of 4 | LLM-friendly docs export (llms.txt, llms-full.txt, per-page .md) |
| API referencesaturated Developer Ergonomics94% of providers with a contract, docs and a reference already earn this; the vendor cannot move it for most of its buyers. |
3.0 of 3 | Developer portal (Zudoku) generated from OpenAPI |
| Console or sandbox Developer ErgonomicsDeclare the try-it reference as a Console (or Playground) entry in apis.yml common[]. |
3.0 of 3 | Try-it panel on every operation |
| Stable Error Semanticsconditional Agent ReadinessOnly if the provider’s own OpenAPI $refs a shared problem+json schema across 4xx/5xx responses — the gateway returns the envelope at runtime, and Zuplo’s docs leave documenting it in the OpenAPI to the provider. |
8.0 of 8 | RFC 7807 Problem Details on every gateway error |
| Multiple plansconditional Access ClarityOnly if the provider publishes three or more plans — Zuplo renders whatever plans exist, it does not create tiers. |
4.0 of 4 | Monetization plugin — public pricing page, subscriptions, usage dashboard |
| Error responses documentedconditional Contract QualityOnly if the provider’s OpenAPI declares 4xx response schemas on at least half its operations. |
4.0 of 4 | RFC 7807 Problem Details on every gateway error |
What Zuplo ships that earns nothing (4)
- Consumer usage dashboard — Consumer usage analytics are real value to a customer and no check reads them.
- OAuthProtectedResourcePlugin — The plugin advertises the resource; DCR needs a registration_endpoint in the authorization server’s discovery document, which lives at the external IdP, not at Zuplo.
- OAuthProtectedResourcePlugin — The
servedgrade reads an openid-configuration/oauth-authorization-server document with an issuer on the provider’s host; Zuplo serves the resource metadata only, and the discovery document is the IdP’s. - Rate limiting inbound policy (429 + Retry-After) — Enforcing three limits is not documenting them; the check counts limits the provider publishes.
A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. The rating is not for sale → · Full vendor facets artifact
APIs 13
Individual APIs this provider publishes, each with its own machine-readable definition.
Zuplo API Keys - Buckets API
A Bucket is an object representing a group of API key consumers for a given account. This section includes a group of endpoints available to perform CRUD operations on a bucket....
Zuplo API Keys - Consumers API
A Consumer is an object representing a group of API keys in a given bucket. This section includes a group of endpoints available to perform CRUD operations on a consumer. You ca...
Zuplo API Keys - Keys API
This is an object representing an API key. This section includes a list of endpoints to perform CRUD operations on an API key. You can learn more about API keys [here](https://z...
Zuplo API Keys - Managers API
A Manager is an object representing a group of managers in a given consumer. This section includes a group of endpoints available to perform operations on a manager. You can lea...
Zuplo Audit Logs API
The Audit Logs API from Zuplo — 1 operation(s) for audit logs.
Zuplo Custom Domains API
Manage account custom domains and their deployment mappings
Zuplo Deployments API
Set of operations available to handle deployments. You can learn more about deployments [here](https://zuplo.com/docs/articles/environments).
Zuplo MCP Servers API
MCP server endpoints for AI-powered tools
Zuplo Tunnel Services API
List of endpoints available to manage services for a given tunnel.
Zuplo Tunnels API
List of endpoints available to perform operations on Tunnels.
Zuplo Variables API
Set of operations available to create and update environment variables. You can learn more about environment variables [here](https://zuplo.com/docs/articles/environment-variabl...
Zuplo Open API
The Open API API from Zuplo — 1 operation(s) for open api.
Zuplo Whoami API
The Whoami API from Zuplo — 1 operation(s) for whoami.
Scroll for all 13
Postman Collections 1
Ready-to-run Postman collections for exercising this provider's APIs.
Zuplo Developer API
POSTMANOpen Collections 15
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
API Collection
OPEN COLLECTIONZuplo Developer API Keys - Buckets API
OPEN COLLECTIONZuplo Developer API Keys - Buckets API Keys - Consumers API
OPEN COLLECTIONZuplo Developer API Keys - Buckets API Keys - Keys API
OPEN COLLECTIONZuplo Developer API Keys - Buckets API Keys - Managers API
OPEN COLLECTIONZuplo Developer API Keys - Buckets Audit Logs API
OPEN COLLECTIONZuplo Developer API Keys - Buckets Custom Domains API
OPEN COLLECTIONZuplo Developer API Keys - Buckets Deployments API
OPEN COLLECTIONZuplo Developer API Keys - Buckets MCP Servers API
OPEN COLLECTIONZuplo Developer API Keys - Buckets Openapi API
OPEN COLLECTIONZuplo Developer API Keys - Buckets Tunnel Services API
OPEN COLLECTIONZuplo Developer API Keys - Buckets Tunnels API
OPEN COLLECTIONZuplo Developer API Keys - Buckets Variables API
OPEN COLLECTIONZuplo Developer API Keys - Buckets Who Am I API
OPEN COLLECTIONZuplo Developer API
OPEN COLLECTIONScroll for all 15
Arazzo Workflows 18
Multi-step API workflows described with the Arazzo specification.
Zuplo Add a Manager to a Consumer
Create a consumer, add a manager to it, then list the consumer's managers.
ARAZZOZuplo Bulk-Issue API Keys to a Consumer
Create a consumer, bulk-create multiple API keys for it, then list the keys.
ARAZZOZuplo Create a Consumer and Issue an API Key
Create a consumer in an existing bucket, issue an API key, then read the key back.
ARAZZOZuplo Deactivate a Consumer's API Key
List a consumer's keys, find one, and delete it to revoke access.
ARAZZOZuplo Discover Account and List Its Buckets
Resolve the account name from the API key, then list that account's API key buckets.
ARAZZOZuplo Find and Update an API Key Bucket
List the account's buckets, confirm a match exists, update one, and read it back.
ARAZZOZuplo Find a Consumer and Update Its Metadata
List consumers in a bucket, find a match by name, update its metadata, and read it back.
ARAZZOZuplo Find and Delete a Consumer
List consumers in a bucket, confirm a match exists, and delete the consumer.
ARAZZOZuplo Map a Custom Domain to a Deployment
Create a custom domain for a deployment and list the account's domains to confirm it.
ARAZZOZuplo Onboard a Consumer With an API Key
Create a bucket, create a consumer with an API key, and list the consumer's keys.
ARAZZOZuplo Provision an API Key Bucket
Create a new API key bucket and read it back to confirm it exists.
ARAZZOZuplo Provision a Secure Tunnel
Create a tunnel and read it back to retrieve the connection token.
ARAZZOZuplo Inspect and Redeploy a Project Deployment
List a project's deployments, read the live deployment detail, then trigger a redeploy.
ARAZZOZuplo Repoint a Custom Domain to a New Deployment
List custom domains, confirm one exists, and update it to a new deployment.
ARAZZOZuplo Rotate a Consumer's API Keys
Read a consumer, roll its keys to set an expiration and issue a fresh key, then list the keys.
ARAZZOZuplo Rotate a Tunnel Token
Read a tunnel to confirm it exists, then rotate its connection token.
ARAZZOZuplo Set an Environment Variable and Redeploy
Create a branch variable, list the project's deployments, and redeploy so the variable takes effect.
ARAZZOZuplo Update an Environment Variable and Redeploy
Update an existing branch variable value, find the deployment, and redeploy it.
ARAZZOScroll for all 18
Agent Skills 4
Packaged agent skills for driving this provider's APIs from an AI assistant.
Pricing Plans 1
Published pricing tiers and plan structures.
Zuplo Plans Pricing
PLANSRate Limits 1
Documented rate limits and quota policies.
Zuplo Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Zuplo Finops
FINOPSSemantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Zuplo Context
JSON-LDSpectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
Zuplo API Rules
SPECTRALZuplo API Rules
SPECTRALJSON Schema 4
Standalone JSON Schema definitions for this provider's data models.
Zuplo API Key
JSON SCHEMAZuplo Consumer
JSON SCHEMAZuplo Deployment
JSON SCHEMAZuplo Tunnel
JSON SCHEMAJSON Structure 3
JSON Structure definitions describing this provider's data shapes.
Zuplo Api Key Structure
JSON STRUCTUREZuplo Consumer Structure
JSON STRUCTUREZuplo Deployment Structure
JSON STRUCTUREExamples 3
Example request and response payloads for these APIs.
Zuplo Create Api Key Example
EXAMPLEZuplo Create Tunnel Example
EXAMPLEZuplo List Consumers Example
EXAMPLESecurity Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 4
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 4
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 18
Pagination, idempotency, versioning, errors, and events
Scroll for all 18
Build 5
SDKs, sample code, and the tooling you integrate with
Access & Security 6
Authentication, authorization, and security posture
Learn 1
Tutorials, courses, talks, and written guidance
Operate 7
Status, limits, changes, and where to get help
Scroll for all 7
Commercial 3
Pricing, plans, and the legal terms of use
Company 5
The organization behind the API
Other 12
Properties that don't map to a standard resource type
Scroll for all 12
Source (apis.yml)
Work with this as data
Every provider here is available over the APIs.io API and to AI agents over MCP.