SecurityGroup

The SecurityGroup resource defines a set of rules for controlling network access to and from compute instances. It allows you to specify which traffic is allowed or denied based on various criteria. The SecurityGroup resource is hierarchical, meaning it can be defined at different levels (tenant, workspace). This allows for flexible management of network access rules across different scopes.

CompanyCloudCloud InfrastructureSovereigntyEuropeOpen StandardsMulti-CloudInteroperabilityOpenAPI
View JSON Schema on GitHub

JSON Schema

eu-sovereign-cloud-api-security-group-schema.json Raw ↑
{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://raw.githubusercontent.com/api-evangelist/eu-sovereign-cloud-api/main/json-schema/eu-sovereign-cloud-api-security-group-schema.json",
  "title": "SecurityGroup",
  "description": "The SecurityGroup resource defines a set of rules for controlling network access to and from compute instances.\nIt allows you to specify which traffic is allowed or denied based on various criteria.\n\nThe SecurityGroup resource is hierarchical, meaning it can be defined at different levels (tenant, workspace).\nThis allows for flexible management of network access rules across different scopes.\n",
  "x-generated": "2026-10-09",
  "x-method": "derived",
  "x-generator": "derive-json-schema.py",
  "x-source": "openapi/eu-sovereign-cloud-api-foundation-network-v1-openapi.yml#/components/schemas/SecurityGroup",
  "allOf": [
    {
      "$ref": "#/$defs/UserResourceMetadata"
    },
    {
      "type": "object",
      "description": "A Security Group defines network access rules for a group of compute instances.\n\nKey Concepts:\n- Rules define bi-directional or uni-directional network communication\n- Supports routing between security groups\n- Enables granular control over public internet access\n- Implements stateful connection tracking\n\nConnection Tracking:\nWhen a connection is initiated from an allowed source, return traffic^ is automatically permitted,\neven if not explicitly defined in the rules. This ensures seamless, bi-directional communication\nfor established connections.\n\nRouting and Communication Patterns:\n- Group-to-Group Rules: Define explicit communication paths between security groups\n- PublicInternet Target: Allows precise control over internet-facing traffic\n- Ingress/Egress Control: Fine-grained rules for incoming and outgoing traffic\n",
      "required": [
        "spec"
      ],
      "properties": {
        "metadata": {
          "$ref": "#/$defs/RegionalWorkspaceResourceMetadata"
        },
        "spec": {
          "$ref": "#/$defs/SecurityGroupSpec"
        },
        "status": {
          "$ref": "#/$defs/SecurityGroupStatus"
        }
      }
    }
  ],
  "$defs": {
    "Annotations": {
      "x-go-type-skip-optional-pointer": true,
      "type": "object",
      "description": "User-defined key/value pairs that are mutable and can be used to add annotations.\nThe number of annotations is eventually limited by the CSP.\n",
      "additionalProperties": {
        "type": "string",
        "maxLength": 1024
      }
    },
    "Extensions": {
      "x-go-type-skip-optional-pointer": true,
      "type": "object",
      "description": "User-defined key/value pairs that are mutable and can be used to add extensions.\nExtensions are subject to validation by the CSP, and any value that is not accepted will be rejected during admission.\n",
      "additionalProperties": {
        "type": "string"
      }
    },
    "IPVersion": {
      "type": "string",
      "description": "IP version of the address",
      "enum": [
        "IPv4",
        "IPv6"
      ],
      "x-enumNames": [
        "IPVersionIPv4",
        "IPVersionIPv6"
      ],
      "x-oapi-codegen-extra-tags": {
        "x-kubebuilder-validation-enum": "IPv4;IPv6"
      }
    },
    "IcmpConfig": {
      "type": "object",
      "description": "ICMP specific rule configuration",
      "required": [
        "type",
        "code"
      ],
      "properties": {
        "type": {
          "type": "integer",
          "description": "ICMP type",
          "minimum": 0,
          "maximum": 8,
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-minimum": "0",
            "x-kubebuilder-validation-maximum": "8"
          }
        },
        "code": {
          "type": "integer",
          "description": "ICMP code",
          "minimum": 0,
          "maximum": 5,
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-minimum": "0",
            "x-kubebuilder-validation-maximum": "5"
          }
        }
      }
    },
    "Labels": {
      "x-go-type-skip-optional-pointer": true,
      "type": "object",
      "description": "User-defined key/value pairs that are mutable and can be used to\norganize and categorize resources. They can be used to filter resources.\nThe number of labels is eventually limited by the CSP.\n",
      "additionalProperties": {
        "type": "string",
        "maxLength": 63
      }
    },
    "ModificationMetadata": {
      "type": "object",
      "readOnly": true,
      "description": "Base metadata for all resources with optional region references",
      "required": [
        "createdAt",
        "lastModifiedAt",
        "resourceVersion"
      ],
      "properties": {
        "createdAt": {
          "type": "string",
          "format": "date-time",
          "description": "Indicates the time when the resource was created. The field is set by the provider and should not be modified by the user."
        },
        "deletedAt": {
          "type": "string",
          "format": "date-time",
          "description": "If set, indicates the time when the resource was marked for deletion. Resources with this field set are considered pending deletion."
        },
        "lastModifiedAt": {
          "type": "string",
          "format": "date-time",
          "description": "Indicates the time when the resource was created or last modified. Field is used for \"If-Unmodified-Since\" logic for concurrency control. The provider guarantees that a modification on a single resource can happen only once every millisecond."
        },
        "resourceVersion": {
          "type": "integer",
          "description": "Incremented on every modification of the resource. Used for optimistic concurrency control.",
          "minimum": 1,
          "format": "int64"
        }
      }
    },
    "NameMetadata": {
      "type": "object",
      "readOnly": true,
      "required": [
        "name"
      ],
      "description": "Metadata for resource names",
      "properties": {
        "name": {
          "type": "string",
          "description": "Resource identifier in dash-case (kebab-case) format. Must start and end with an alphanumeric character.\nCan contain lowercase letters, numbers, and hyphens. Multiple segments can be joined with dots.\nEach segment follows the same rules.\n",
          "minLength": 1,
          "maxLength": 128,
          "pattern": "^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$"
        }
      }
    },
    "PermissionMetadata": {
      "type": "object",
      "readOnly": true,
      "description": "Metadata for permission management",
      "required": [
        "provider",
        "resource",
        "verb"
      ],
      "properties": {
        "provider": {
          "type": "string",
          "minLength": 1,
          "maxLength": 64
        },
        "resource": {
          "type": "string",
          "minLength": 1,
          "maxLength": 256
        },
        "verb": {
          "type": "string",
          "minLength": 1,
          "maxLength": 7
        }
      }
    },
    "Port": {
      "description": "A valid network port number.\nThe port number is a 16-bit unsigned integer ranging from 1 to 65535.\n",
      "type": "integer",
      "minimum": 1,
      "maximum": 65535,
      "x-oapi-codegen-extra-tags": {
        "x-kubebuilder-validation-minimum": "1",
        "x-kubebuilder-validation-maximum": "65535"
      }
    },
    "Ports": {
      "type": "object",
      "description": "Defines a specific port list or port range for the rule.\nThe configuration allows specifying individual ports, ranges, or a combination of both.\n\nBehavior:\n- If only `from` is specified, the range is interpreted as a single port: `from` to `from`.\n- If only `to` is specified, the range is interpreted as a single port: `to` to `to`.\n- If both `from` and `to` are specified, the range spans from `from` to `to`.\n- The `list` property can be used to explicitly define additional individual ports.\n\nThe final result is a comprehensive list of ports and/or port ranges.\n",
      "properties": {
        "from": {
          "x-go-type-skip-optional-pointer": true,
          "allOf": [
            {
              "$ref": "#/$defs/Port"
            }
          ]
        },
        "to": {
          "x-go-type-skip-optional-pointer": true,
          "allOf": [
            {
              "$ref": "#/$defs/Port"
            }
          ]
        },
        "list": {
          "type": "array",
          "x-go-type-skip-optional-pointer": true,
          "maxItems": 100,
          "items": {
            "$ref": "#/$defs/Port"
          },
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-items-minimum": "1",
            "x-kubebuilder-validation-items-maximum": "65535",
            "x-kubebuilder-validation-max-items": "100"
          }
        }
      }
    },
    "Reference": {
      "type": "object",
      "description": "A reference to a resource using an object. The object contains the\nsame information as the ReferenceURN, but is represented as a structured object.\nThe advantage of this representation is that it can be used to reference\nresources in different workspaces or regions without the need to specify\nthe full URN.\n",
      "required": [
        "resource"
      ],
      "properties": {
        "region": {
          "type": "string",
          "x-go-type-skip-optional-pointer": true,
          "description": "Region of the resource. If not set, the region is inferred from the context.\n",
          "maxLength": 64,
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-max-length": "64"
          }
        },
        "provider": {
          "type": "string",
          "x-go-type-skip-optional-pointer": true,
          "description": "Provider of the resource. If not set, the provider is inferred from the context.\n",
          "maxLength": 64,
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-max-length": "64"
          }
        },
        "tenant": {
          "type": "string",
          "x-go-type-skip-optional-pointer": true,
          "description": "Tenant of the resource. If not set, the tenant is inferred from the context.\n",
          "maxLength": 64,
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-max-length": "64"
          }
        },
        "workspace": {
          "type": "string",
          "x-go-type-skip-optional-pointer": true,
          "description": "Workspace of the resource. If not set, the workspace is inferred from the context.\n",
          "maxLength": 64,
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-max-length": "64"
          }
        },
        "resource": {
          "type": "string",
          "description": "Resource-specific path identifying the resource within its workspace context.\nThis is the segment of the full URN after the provider, version, tenant, and\nworkspace parts. For a flat resource it is `<type>/<name>`, and for hierarchical\n(nested) resources it includes the parent path segments:\n  `networks/<network-name>/route-tables/<rt-name>`\nThe provider, tenant, and workspace can be specified as separate fields in this\nobject; they do not need to be repeated here.\n",
          "minLength": 1,
          "maxLength": 256,
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-min-length": "1",
            "x-kubebuilder-validation-max-length": "256"
          }
        }
      }
    },
    "ReferenceURN": {
      "type": "string",
      "minLength": 1,
      "description": "A unique resource name (URN) used to identify and reference this resource.\n\nThe URN is NOT a URL — it does not contain a protocol scheme (http/https), a host,\nor any endpoint-specific prefix. It is a portable, transport-agnostic identifier.\nA configured SDK client — which knows the provider's base URL and endpoint mapping —\ncan derive a URL from a URN, but the URN alone cannot be turned into a URL without\nthat SDK configuration context. This separation keeps the URN portable across\nenvironments and CSP deployments.\n\nThe full URN format is:\n  `{provider}/{version}/tenants/{tenant}/workspaces/{workspace}/{type}/{name}`\n\nFor hierarchical (nested) resources, additional parent path segments are included:\n  `seca.network/v1/tenants/tn-1/workspaces/ws-1/networks/my-net/route-tables/my-rt`\n\n### Automatic Prefix Inference\n\nIn most cases, the prefix of the URN can be automatically derived in the given context.\nTo simplify usage, only the resource type and name might be specified as a reference\nusing the `<type>/<name>` notation. The suffix can be made more specific by adding\nadditional segments separated by slashes.\n\nThe prefix is automatically inferred from the context. For example, if the resource is a\nblock storage in the same workspace the reference can be specified as\n`block-storages/my-block-storage`. If the resource is a block storage in a different workspace, the\nreference can be specified as `workspaces/ws-1/block-storages/my-block-storage`.\n\nFor automatic prefix inference, the following rules apply:\n- the version is inferred from the current resource version\n- the workspace is inferred from the current workspace\n- the region is inferred from the current region\n- the provider is inferred from the type and context of the usage\n\nThe prefix inference is resolved on admission into the full URN format, which makes it\nmostly suitable for human use.\n",
      "maxLength": 255
    },
    "RegionalMetadata": {
      "type": "object",
      "description": "Metadata for regional resources",
      "readOnly": true,
      "required": [
        "region"
      ],
      "properties": {
        "region": {
          "type": "string",
          "description": "Reference to the region where the resource is located",
          "minLength": 1,
          "maxLength": 64
        }
      }
    },
    "RegionalWorkspaceResourceMetadata": {
      "description": "Metadata for regional resources with name, permission, modification, type, tenant and workspace and region information.\n",
      "allOf": [
        {
          "$ref": "#/$defs/NameMetadata"
        },
        {
          "$ref": "#/$defs/PermissionMetadata"
        },
        {
          "$ref": "#/$defs/ModificationMetadata"
        },
        {
          "$ref": "#/$defs/TypeMetadata"
        },
        {
          "$ref": "#/$defs/TenantMetadata"
        },
        {
          "$ref": "#/$defs/WorkspaceMetadata"
        },
        {
          "$ref": "#/$defs/RegionalMetadata"
        }
      ]
    },
    "ResourceState": {
      "type": "string",
      "description": "Current phase of the resource:\n- pending: not available, waiting for other resources\n- creating: not available, creation started\n- active: available for data layer usage\n- updating: available for data layer usage\n- deleting: maybe still available for data layer user, can fail any moment\n- error: failed to fulfill the request; would be related to provider issue or customer related input.\n",
      "enum": [
        "pending",
        "creating",
        "active",
        "updating",
        "deleting",
        "error"
      ],
      "x-enumNames": [
        "ResourceStatePending",
        "ResourceStateCreating",
        "ResourceStateActive",
        "ResourceStateUpdating",
        "ResourceStateDeleting",
        "ResourceStateError"
      ]
    },
    "SecurityGroupRuleSpec": {
      "type": "object",
      "description": "Specification of a security group rule defining network access permissions.\nIf no version is specified, any IP version will be allowed.\nIf no protocol is specified, any network protocol will be allowed.\n",
      "required": [
        "direction"
      ],
      "properties": {
        "annotations": {
          "$ref": "#/$defs/Annotations"
        },
        "direction": {
          "type": "string",
          "enum": [
            "ingress",
            "egress"
          ],
          "x-enumNames": [
            "SecurityGroupRuleDirectionIngress",
            "SecurityGroupRuleDirectionEgress"
          ],
          "description": "Direction of the traffic flow:\n* ingress: Only incoming traffic is allowed\n* egress: Only outgoing traffic is allowed\n",
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-enum": "ingress;egress",
            "x-kubebuilder-validation-max-length": "7"
          }
        },
        "version": {
          "x-go-type-skip-optional-pointer": true,
          "allOf": [
            {
              "$ref": "#/$defs/IPVersion"
            }
          ]
        },
        "protocol": {
          "type": "string",
          "x-go-type-skip-optional-pointer": true,
          "description": "Network protocol for the rule",
          "enum": [
            "tcp",
            "udp",
            "tcp+udp",
            "icmp"
          ],
          "x-enumNames": [
            "SecurityGroupRuleProtocolTCP",
            "SecurityGroupRuleProtocolUDP",
            "SecurityGroupRuleProtocolTCPUDP",
            "SecurityGroupRuleProtocolICMP"
          ],
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-enum": "tcp;udp;tcp+udp;icmp",
            "x-kubebuilder-validation-max-length": "7"
          }
        },
        "ports": {
          "allOf": [
            {
              "$ref": "#/$defs/Ports"
            }
          ],
          "x-oapi-codegen-extra-tags": {
            "x-cel-rule-0": "!has(self.from) || !has(self.to) || self.to >= self.from",
            "x-cel-message-0": "ports.to must be greater than or equal to ports.from"
          }
        },
        "icmp": {
          "$ref": "#/$defs/IcmpConfig"
        },
        "sourceRef": {
          "type": "array",
          "x-go-type-skip-optional-pointer": true,
          "maxItems": 32,
          "description": "Reference to a CIDR block, IP address, gateway, instance or security group that is allowed to communicate\nwith the security group. If a security group is specified, all instances in that group are allowed.\nIf no sourceRef is specified, all traffic is allowed.\n",
          "items": {
            "$ref": "#/$defs/Reference"
          },
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-max-items": "32"
          }
        }
      }
    },
    "SecurityGroupSpec": {
      "type": "object",
      "description": "Specification of the security group",
      "properties": {
        "rules": {
          "type": "array",
          "x-go-type-skip-optional-pointer": true,
          "maxItems": 500,
          "description": "Network access rules defining communication between security groups and external networks.\n\nRule Evaluation:\n- Default behavior is to deny all traffic not explicitly allowed\n- Rules provide granular control over allowed traffic types, sources, and destinations\n",
          "items": {
            "$ref": "#/$defs/SecurityGroupRuleSpec"
          },
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-max-items": "500",
            "x-cel-rule-0": "self.all(x, !has(x.icmp) || !has(x.protocol) || x.protocol == 'icmp')",
            "x-cel-message-0": "icmp is only allowed when protocol is icmp",
            "x-cel-rule-1": "self.all(x, !has(x.ports) || !has(x.protocol) || x.protocol != 'icmp')",
            "x-cel-message-1": "ports is not allowed when protocol is icmp"
          }
        },
        "ruleRefs": {
          "type": "array",
          "x-go-type-skip-optional-pointer": true,
          "maxItems": 500,
          "description": "References to shared SecurityGroupRule resources.\nThese rules are applied in addition to the inline rules.\n",
          "items": {
            "allOf": [
              {
                "$ref": "#/$defs/Reference"
              }
            ],
            "description": "Reference to a SecurityGroupRule resource."
          },
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-max-items": "500"
          }
        }
      }
    },
    "SecurityGroupStatus": {
      "description": "Status of the security group, including the status of its rules.\nThe status is read-only and reflects the current state of the security group.\n",
      "allOf": [
        {
          "$ref": "#/$defs/Status"
        },
        {
          "type": "object",
          "readOnly": true,
          "description": "Current status of the security group\nCondition type `rules` indicates the status of the security group rules.\nThe status can be `applied` or `pending`.\n",
          "properties": {
            "rules": {
              "type": "array",
              "x-go-type-skip-optional-pointer": true,
              "maxItems": 500,
              "items": {
                "$ref": "#/$defs/Status"
              },
              "x-oapi-codegen-extra-tags": {
                "x-kubebuilder-validation-max-items": "500"
              }
            }
          }
        }
      ]
    },
    "Status": {
      "type": "object",
      "readOnly": true,
      "description": "Current status of the resource",
      "required": [
        "conditions"
      ],
      "properties": {
        "state": {
          "x-go-type-skip-optional-pointer": true,
          "allOf": [
            {
              "$ref": "#/$defs/ResourceState"
            }
          ]
        },
        "conditions": {
          "type": "array",
          "description": "History of state transitions, ordered newest-first, complementing the\ncurrent snapshot in `state`.\n",
          "maxItems": 32,
          "items": {
            "$ref": "#/$defs/StatusCondition"
          },
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-max-items": "32"
          }
        }
      }
    },
    "StatusCondition": {
      "type": "object",
      "description": "StatusCondition describes the state of a resource at a certain point.\nConditions are provider-specific and can represent different states depending on the\nresource type and provider implementation.\n",
      "required": [
        "state",
        "lastTransitionAt"
      ],
      "properties": {
        "state": {
          "$ref": "#/$defs/ResourceState"
        },
        "lastTransitionAt": {
          "type": "string",
          "format": "date-time",
          "description": "LastTransitionAt is the last time the condition transitioned from one\nstatus to another. This should be when the underlying condition changed.\nIf that is not known, then using the time when the API field changed is\nacceptable.\n"
        },
        "type": {
          "type": "string",
          "x-go-type-skip-optional-pointer": true,
          "description": "Type of condition. The condition type is provider-specific and should\nreflect the specific states relevant to your resource.\n"
        },
        "reason": {
          "type": "string",
          "x-go-type-skip-optional-pointer": true,
          "description": "The reason for the condition's last transition in CamelCase.\nThe specific set of reason values is provider-specific and should be\ndocumented by the provider.\n",
          "maxLength": 1024,
          "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-max-length": "1024",
            "x-kubebuilder-validation-pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$"
          }
        },
        "message": {
          "type": "string",
          "x-go-type-skip-optional-pointer": true,
          "description": "A human-readable message indicating details about the transition.\n",
          "maxLength": 32768,
          "x-oapi-codegen-extra-tags": {
            "x-kubebuilder-validation-max-length": "32768"
          }
        }
      }
    },
    "TenantMetadata": {
      "type": "object",
      "description": "Metadata for resources with tenant constraints",
      "readOnly": true,
      "required": [
        "tenant"
      ],
      "properties": {
        "tenant": {
          "type": "string",
          "description": "Tenant identifier",
          "minLength": 1,
          "maxLength": 64
        }
      }
    },
    "TypeMetadata": {
      "type": "object",
      "readOnly": true,
      "required": [
        "apiVersion",
        "kind",
        "ref"
      ],
      "description": "Metadata for all resources with type information.\n",
      "properties": {
        "apiVersion": {
          "type": "string",
          "description": "API version of the resource",
          "minLength": 1,
          "maxLength": 16,
          "default": "v1"
        },
        "kind": {
          "type": "string",
          "description": "Type of the resource",
          "enum": [
            "activity-log",
            "block-storage",
            "image",
            "instance",
            "instance-sku",
            "internet-gateway",
            "network",
            "network-load-balancer",
            "network-sku",
            "nic",
            "object-storage-account",
            "public-ip",
            "region",
            "role",
            "role-assignment",
            "routing-table",
            "security-group",
            "security-group-rule",
            "storage-sku",
            "subnet",
            "workspace"
          ],
          "x-enumNames": [
            "ResourceKindActivityLog",
            "ResourceKindBlockStorage",
            "ResourceKindImage",
            "ResourceKindInstance",
            "ResourceKindInstanceSku",
            "ResourceKindInternetGateway",
            "ResourceKindNetwork",
            "ResourceKindNetworkLoadBalancer",
            "ResourceKindNetworkSku",
            "ResourceKindNic",
            "ResourceKindObjectStorageAccount",
            "ResourceKindPublicIP",
            "ResourceKindRegion",
            "ResourceKindRole",
            "ResourceKindRoleAssignment",
            "ResourceKindRoutingTable",
            "ResourceKindSecurityGroup",
            "ResourceKindSecurityGroupRule",
            "ResourceKindStorageSku",
            "ResourceKindSubnet",
            "ResourceKindWorkspace"
          ]
        },
        "ref": {
          "$ref": "#/$defs/ReferenceURN"
        }
      }
    },
    "UserResourceMetadata": {
      "type": "object",
      "description": "Metadata for user-defined resource properties",
      "properties": {
        "labels": {
          "$ref": "#/$defs/Labels"
        },
        "annotations": {
          "$ref": "#/$defs/Annotations"
        },
        "extensions": {
          "$ref": "#/$defs/Extensions"
        }
      }
    },
    "WorkspaceMetadata": {
      "type": "object",
      "description": "Metadata for resources with workspace constraints",
      "readOnly": true,
      "required": [
        "workspace"
      ],
      "properties": {
        "workspace": {
          "type": "string",
          "description": "Workspace identifier",
          "minLength": 1,
          "maxLength": 64
        }
      }
    }
  }
}

Work with this as data

Every JSON Schema here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for schemas

4 MCP tools reach this
  • find_json_schemasBrowse and filter every JSON Schema in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This JSON Schema
curl "https://apis.io/api/v1/json-schemas/eu-sovereign-cloud-api-security-group"
All schemas
curl "https://apis.io/api/v1/json-schemas?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.