niche · 0.1 market domain

Incident Response

Score 20.0 / 100 62 providers +4 via APIs 16 APIs Search apis.io →

Providers using this tag (62)

Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.

Strong 3 Solid coverage with minor gaps
Developing 14 Usable, with meaningful gaps to close
Thin 19 Limited public surface area
Emerging 18 Early or largely undocumented
Minimal 7 Almost no public developer surface
Unrated 1 Not yet scored

APIs with this tag (16)

Ranked by the provider's API Evangelist rating — the Kin Score is scored per provider, not per API, so every API of a provider shares its band. How the rating works →

Exemplar 1 Complete, well-documented, and agent-ready
Strong 1 Solid coverage with minor gaps
Developing 6 Usable, with meaningful gaps to close
Thin 6 Limited public surface area
Emerging 1 Early or largely undocumented
Unrated 1 Not yet scored

Companies reaching this through an API (4)

These companies publish an API, specification or operation carrying “Incident Response” but do not classify their business under it. Listed unranked and kept out of the count above, because one tagged operation is not a statement about what a company does.

Grafana Harness SIGNL4 Trellix

Score breakdown

Frequency
51.4
log-scaled weighted occurrences
Breadth
1.7
spread across providers
Quality lift
33.3
mean composite of providers using it
Cohesion
0.0
strength of nearest seed neighbor

Related tags

Security Operations 19 co-occurrences Threat Detection 29 co-occurrences SOC 13 co-occurrences SOAR 8 co-occurrences Threat Intelligence 17 co-occurrences Managed Detection and Response 8 co-occurrences SIEM 11 co-occurrences On-Call 7 co-occurrences

Where this tag comes from

Provider tag62
Api tag16
Openapi tag1
Openapi op tag1

Cohort brief

Auto-generated

The 59 providers in the APIs.io catalog tagged Incident Response, scored on the Kin Score. Every figure below is computed from the catalog — nothing here is written.

Providers
59
all scored
Mean Kin Score
30.2
+6.2 vs catalog 24
Mean Agent Readiness
14.3
+1.9 vs catalog 12.4
Spread
5.5–61.4
median 30.2 · σ 13.9
How the 59 split by band
Exemplar 0Strong 3Developing 14Thin 19Emerging 18Minimal 5
Facet averages, against the whole catalog
FacetThis cohortCatalogDifferenceScored
Access Clarity 37 26.5 +10.5 59
Developer Ergonomics 33.5 23.4 +10.1 59
Operational Transparency 21 14 +7 59
Discoverability 66.8 61 +5.8 59
Contract Governance 9.9 6.5 +3.4 59
Contract Quality 22 20.1 +1.9 59

A facet is averaged over the members that carry it, not over the whole cohort — the “Scored” column is that count. Averaging an absent facet as zero would score our own coverage gaps as the providers’ posture.

What this cohort publishes
ArtifactThis cohortCatalogDifference
MCP server (any) 27% 10% +17
MCP server (first-party) 27% 13% +14
Agent Skills 0% 0% 0
OAuth scopes 17% 11% +6
Security 100% 96% +4
Arazzo workflows 0% 2% -2
Governance rules 13% 13% 0

mcp_pct counts any mcp/ artifact including ones API Evangelist derived from the provider OpenAPI; mcp_first_party_pct counts only servers the provider publishes. Prefer the latter.

Top by Kin Score
  1. 1 Cisco XDR 61.4
  2. 2 Splunk Observability Cloud 61
  3. 3 IRONSCALES 55.5
  4. 4 Coalition 50.2
  5. 5 Corelayer 49.4
  6. 6 LevelBlue 48
  7. 7 Cyware 47.1
  8. 8 IncidentFox (Brownie) 47
  9. 9 Tracebit 45.2
  10. 10 RunWhen 45.1
Top by Agent Readiness
  1. 1 IRONSCALES 51.6
  2. 2 RunWhen 42.6
  3. 3 Cisco XDR 38.5
  4. 4 Splunk Observability Cloud 34.6
  5. 5 Cyware 34.6
  6. 6 Spyderbat 32.4
  7. 7 Stairwell 32.2
  8. 8 Corelayer 29.3
  9. 9 LevelBlue 28.6
  10. 10 Coalition 28.1
All 62 members of this roster resolve to a scored provider in the catalog.Generated from the catalog build of 20 September 2026, across 27620 providers, using the same computation served by the APIs.io cohort API. Briefs are published for rosters of 5 or more scored providers; below that a distribution is not meaningful.

Work with this as data

Every tag here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for tags

7 MCP tools reach this
  • find_tagsBrowse and filter every tag in the catalog.
  • get_cohortThis tag as a scored cohort — every provider carrying it, with scores.
  • cohort_statsPRO — the distribution across this tag: mean, median, band split, adoption rates.
  • cohort_rankingsPRO — the leaderboard, on composite AND agent-readiness axes.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This tag
curl "https://apis.io/api/v1/tags/incident-response"
All tags
curl "https://apis.io/api/v1/tags?limit=25"
As a scored cohort
curl "https://apis.io/api/v1/cohorts/tag/incident-response"
The distribution (Pro)
curl "https://apis.io/api/v1/cohorts/tag/incident-response/stats" \
  -H "X-API-Key: $APIS_IO_KEY"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.