emerging · 1.1

DevSecOps

Score 20.8 / 100 85 providers 5 APIs Search apis.io →

Providers using this tag (85)

Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.

Strong 3 Solid coverage with minor gaps
Developing 19 Usable, with meaningful gaps to close
Thin 25 Limited public surface area
Fortify SoftwareCompanySecurityApplication SecurityAppSec28 APIs38.2KubescapeKubernetes SecurityCloud Native SecurityContainer Security7 APIs37.8CorridorCompanySecurityApplication SecurityAI Coding6 APIs37.6CopadoCompanyDevOpsSalesforceCI/CD37.4SonatypeSoftware Supply ChainSecurityVulnerability ManagementSBOM58 APIs37.1ARMOKubernetes SecurityCloud Native SecurityCNAPP8 APIs36.9BytebaseDatabaseDevOpsSchema MigrationCI/CD12 APIs36.6Black Duck SoftwareCompanySecurityApplication SecuritySoftware Composition Analysis36.4Truffle SecurityCompanySecuritySecrets DetectionSecrets Scanning35.8GitLab CI/CDDevOpsCI/CDPipelinesGitLab98 APIs35.5Chaitin TechSecurityWeb Application FirewallWAFCybersecurity556 APIs35.3SnykSecurityVulnerability ManagementApplication Security48 APIs33.8Black DuckCompanyEnterpriseApplication SecuritySoftware Composition Analysis1 API33.7TrivyContainersKubernetesSBOMSecurity4 APIs32.5ConjurCompanyCybersecuritySecrets ManagementIdentity and Access Management1 API31.9MinimusCompanyContainer ImagesContainer SecuritySupply Chain Security31.4OpseraCompanyDevOpsCI/CD1 API30.6Legit SecurityCompanyCybersecurityApplication SecurityASPM30.5CycodeCompanyCybersecurityApplication SecuritySoftware Supply Chain Security1 API29.2Contrast SecurityApplication SecurityAppSecIASTRASP5 APIs28.242CrunchAPI SecurityPlatformScanningSecurity6 APIs27.3AppdomeCompanyMobile App SecurityMobile App Defense1 API26.9ArmorCodeCompanySecurityApplication SecurityVulnerability Management1 API26.9HeelerCompanySecurityApplication Security26.7AktoCompanyAPI SecuritySecurityAPI Security Testing26.5
Emerging 25 Early or largely undocumented
TolmoCompanySecurityCybersecurityCloud Security1 API25.8Jit (fka Cbrix)CompanyCybersecurityApplication Security1 API25.2Software Development LifecycleDevelopment ProcessProject ManagementQuality AssuranceSoftware Engineering7 APIs25.0ChainguardCloud-NativeContainer ImagesContainers6 APIs21.8APIsecCompanyAPI SecurityApplication SecurityAppSec21.0PrivadoCompanyDevOpsPrivacyData Privacy20.9SemgrepStatic AnalysisSASTApplication SecuritySupply Chain6 APIs20.8Defense UnicornsCompanyInfrastructureKubernetes20.5SeezoCompanyArtificial IntelligenceSecurityApplication Security20.3KodemCompanyCybersecurityApplication SecurityRuntime Security1 API19.4BridgecrewCompanySecurityCloud SecurityInfrastructure as Code19.0OtterizeCompanyBusiness ApplicationsKubernetesAccess Control18.6Crash OverrideCompanyCybersecuritySoftware Supply ChainApplication Security18.0Second Front SystemsCompanyDefenseGovernment17.9EchoCompanySecuritySupply Chain SecurityContainer Security17.6ApiiroCompanyCybersecurityApplication SecurityASPM15.4RunsybilCompanySecurityOffensive SecurityPenetration Testing15.1depthfirstCompanySecurityApplication SecurityCybersecurity14.6WizCloud SecurityCNAPPCSPMVulnerability Management1 API14.6Clover SecurityCompanySecurityProduct SecurityApplication Security14.1Threat StackCompanySecurityCloud SecurityCloud Monitoring13.9RapidFortCompanySecurityContainer SecuritySoftware Supply Chain12.7EnclaveCompanySecurityApplication SecurityCloud Security12.4TAAI Labs, IncCompanySecurityApplication SecurityArtificial Intelligence11.8CodeSecureCompanyApplication SecurityStatic AnalysisSAST11.3
Minimal 13 Almost no public developer surface

APIs with this tag (5)

Ranked by the provider's API Evangelist rating — the Kin Score is scored per provider, not per API, so every API of a provider shares its band. How the rating works →

Strong 1 Solid coverage with minor gaps
Developing 1 Usable, with meaningful gaps to close
Thin 2 Limited public surface area
Emerging 1 Early or largely undocumented

Score breakdown

Frequency
53.6
log-scaled weighted occurrences
Breadth
2.3
spread across providers
Quality lift
34.2
mean composite of providers using it
Cohesion
0.0
strength of nearest seed neighbor

Related tags

Application Security 41 co-occurrences Vulnerability Management 33 co-occurrences SAST 18 co-occurrences Container Security 13 co-occurrences SBOM 13 co-occurrences Software Composition Analysis 11 co-occurrences SCA 11 co-occurrences Vulnerabilities 11 co-occurrences

Where this tag comes from

Provider tag82
Api tag5

Cohort brief

Auto-generated

The 85 providers in the APIs.io catalog tagged DevSecOps, scored on the Kin Score. Every figure below is computed from the catalog — nothing here is written.

Providers
85
all scored
Mean Kin Score
28.4
+7.7 vs catalog 20.7
Mean Agent Readiness
12.6
+2.9 vs catalog 9.7
Spread
4.3–65.3
median 27.3 · σ 15.7
How the 85 split by band
Exemplar 0Strong 3Developing 19Thin 25Emerging 25Minimal 13
Facet averages, against the whole catalog
FacetThis cohortCatalogDifferenceScored
Developer Ergonomics 31.9 17.9 +14 85
Operational Transparency 19.1 11.3 +7.8 85
Access Clarity 29.1 22.3 +6.8 85
Discoverability 66.7 60.4 +6.3 85
Contract Quality 22.9 17.5 +5.4 85
Contract Governance 9.7 6.4 +3.3 85

A facet is averaged over the members that carry it, not over the whole cohort — the “Scored” column is that count. Averaging an absent facet as zero would score our own coverage gaps as the providers’ posture.

What this cohort publishes
ArtifactThis cohortCatalogDifference
MCP server (any) 32% 16% +16
MCP server (first-party) 14% 7% +7
Agent Skills 0% 0% 0
OAuth scopes 7% 9% -2
Security 89% 88% +1
Arazzo workflows 4% 2% +2
Governance rules 19% 13% +6

mcp_pct counts any mcp/ artifact including ones API Evangelist derived from the provider OpenAPI; mcp_first_party_pct counts only servers the provider publishes. Prefer the latter.

Top by Kin Score
  1. 1 GitLab 65.3
  2. 2 Kondukto 62.5
  3. 3 Google Cloud Binary Authorization 54.7
  4. 4 Qwiet Ai 53.8
  5. 5 Snyk Container 53.8
  6. 6 Fortify 51.9
  7. 7 Mend 49.9
  8. 8 ProjectDiscovery 49.9
  9. 9 Plerion 49.1
  10. 10 Chef 48.1
Top by Agent Readiness
  1. 1 GitLab 47.8
  2. 2 Socket 41.2
  3. 3 Amazon CodeGuru Security 34.5
  4. 4 Qwiet Ai 33.7
  5. 5 Trivy 32.7
  6. 6 Kondukto 32.6
  7. 7 Snyk 30.6
  8. 8 Contrast Security 29.8
  9. 9 GitLab CI/CD 29.5
  10. 10 Harness 29.4
All 85 members of this roster resolve to a scored provider in the catalog.Generated from the catalog build of 25 August 2026, across 26891 providers, using the same computation served by the APIs.io cohort API. Briefs are published for rosters of 5 or more scored providers; below that a distribution is not meaningful.

Work with this as data

Every tag here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for tags

7 MCP tools reach this
  • find_tagsBrowse and filter every tag in the catalog.
  • get_cohortThis tag as a scored cohort — every provider carrying it, with scores.
  • cohort_statsPRO — the distribution across this tag: mean, median, band split, adoption rates.
  • cohort_rankingsPRO — the leaderboard, on composite AND agent-readiness axes.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This tag
curl "https://apis.io/api/v1/tags/devsecops"
All tags
curl "https://apis.io/api/v1/tags?limit=25"
As a scored cohort
curl "https://apis.io/api/v1/cohorts/tag/devsecops"
The distribution (Pro)
curl "https://apis.io/api/v1/cohorts/tag/devsecops/stats" \
  -H "X-API-Key: $APIS_IO_KEY"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.