emerging · 0.0 market domain

Zero Trust

Score 22.3 / 100 102 providers +4 via APIs 30 APIs Search apis.io →

Providers using this tag (102)

Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.

Exemplar 2 Complete, well-documented, and agent-ready
Strong 10 Solid coverage with minor gaps
Developing 19 Usable, with meaningful gaps to close
Thin 29 Limited public surface area
AryakaCompanyNetworkingSASESD-WAN38.7RubrikBackupCyber RecoveryData SecurityData Security Posture Management1 API38.4WatchGuardCloud SecurityEndpoint SecurityFirewallMFA2 APIs38.2StrongDMCompanySecurityPrivileged Access Management1 API37.9WanderaCompanyCybersecurityMobile Security2 APIs37.8CyberArkAuthenticationCloud SecurityConjurCredential Vault1 API37.7PulseIvantiNetwork SecuritySecure AccessSSL VPN3 APIs37.3Consul ConnectConsulEnvoyHashiCorpIntentions1 API36.4Google BeyondCorpAccess ControlEnterprise SecurityIdentitySecurity1 API36.1Skyhigh SecurityCompanyCybersecuritySecurity Service EdgeCASB1 API35.9Zero Trust Network AccessAccess ControlCloud SecurityCybersecurityIdentity Management1 API35.7AviatrixCompanyCloud NetworkingCloud SecurityMulti-Cloud35.3Ambient MeshService MeshIstioKubernetes1 API35.0Via ScienceCompanySecurityIdentityAuthentication1 API33.7SPIFFEAuthenticationCloud-NativeGraduatedIdentity1 API33.5VirsecCompanySecurityCybersecurityApplication Security2 APIs32.5NetBirdNetworkingVPNOpen-Source1 API32.1JumpCloudIdentityDirectory ServicesSSOMFA1 API31.8HyporiCompanySecurityMobileVirtualization1 API30.8TailscaleVPNMesh NetworkingWireGuard1 API30.5Perimeter 81CompanyCybersecuritySASE1 API30.1BeyondTrustAccessAccess ManagementComplianceCredentials6 APIs30.0IllumioCompanySecurityCybersecurity1 API29.6Versa NetworksCompanyNetworkingSecuritySASE2 APIs28.9Cisco Secure ClientEndpoint SecurityRemote AccessSecurityVPN1 API28.0Zero-Trust Security ModelAccess ControlCybersecurityFederalIdentity Management5 APIs27.3CentrifyCompanyIdentityPrivileged Access ManagementAccess Management1 API27.2Cato NetworksCompanyCybersecuritySASESSE1 API26.6Secret Double OctopusCompanyAuthenticationIdentity and Access ManagementPasswordless1 API26.4
Emerging 31 Early or largely undocumented
CyberArk IdentityIdentityAccess ManagementIAMSingle Sign-On1 API26.1AppaegisCompanySecurityEnterprise Browser1 API25.1SilverfortCompanyIdentitySecurityAuthentication1 API24.7TodylCompanyCybersecuritySecurityManaged Service Providers1 API23.9UnisysFortune 1000SecurityNetwork Security4 APIs23.5ibossCompanySecurityCybersecurity1 API23.4API DynamicsAPI SecurityAPI DiscoveryAPI Observability1 API23.1Zero Trust ArchitectureAccess ControlAuthenticationAuthorizationCybersecurity5 APIs22.6ForescoutCompanyCybersecurityNetwork SecurityDevice Visibility3 APIs22.5AdytonCompanyEnterprise SaasDefense19.9GreymatterEnterpriseKubernetesNetworkingService Mesh3 APIs19.5Duo SecurityAuthenticationMFAIdentity1 API18.7SonicWallCybersecurityNetwork SecurityFirewallNext-Generation Firewall18.7OtterizeCompanyBusiness ApplicationsKubernetesAccess Control18.6ElisityCompanyCybersecurityMicrosegmentation18.0OpenVPNVPNNetwork SecurityRemote Access2 APIs17.2VeniceCompanySecurityPrivileged Access ManagementIdentity Security15.5AceissCompanySecurityIdentity and Access ManagementAccess Control15.2Menlo SecurityCompanySecurityCybersecurityBrowser Security15.1TwingateZTNANetwork AccessVPN Replacement1 API14.8SpirlCompanySecurityIdentityNon-Human Identity14.6NewCoreCompanySecurityIdentityIAM14.2IslandCompanyCybersecurityEnterprise Browser13.5XageCompanySecurityCybersecurity13.1IvantiEndpoint ManagementIT Asset ManagementITSMPatch Management5 APIs13.0NileNetworkingEnterprise NetworkingNetwork as a ServiceNaaS13.0NetskopeSecuritySASESSECASB2 APIs12.5ZscalerCloud SecuritySASENetwork Security2 APIs12.4Red AccessCompanySecurityCybersecuritySecure Service Edge12.3WenspiredataCompanyCybersecurityPrivileged Access Management11.7ZorusCompanyCybersecurityDNS FilteringWeb Protection11.5
Minimal 10 Almost no public developer surface
Unrated 1 Not yet scored

APIs with this tag (28)

Ranked by the provider's API Evangelist rating — the Kin Score is scored per provider, not per API, so every API of a provider shares its band. How the rating works →

Strong 3 Solid coverage with minor gaps
Developing 3 Usable, with meaningful gaps to close
Thin 8 Limited public surface area
Emerging 13 Early or largely undocumented
iboss Zero Trust SSE Platform APIAuthenticated REST administration and reporting surface for the iboss Zero Trust SASE/SSE cloud platform, s...23.4API Dynamics PlatformThe APIDynamics platform provides AI-driven API security and observability including API discovery, traffic...23.1HPE Aruba Networking SSE APIThe HPE Aruba Networking SSE (Security Service Edge) API exposes the Axis Security / HPE SSE cloud-delivere...23.1NIST SP 800-207 Zero Trust ArchitectureNIST Special Publication 800-207 defines zero trust architecture (ZTA) and provides a roadmap for organizat...22.6NIST SP 800-207A ZTA for Cloud-Native ApplicationsNIST SP 800-207A extends the original ZTA guidance to cover cloud-native applications in multi-cloud enviro...22.6Open Policy Agent (OPA)Open Policy Agent is a CNCF-graduated open source general-purpose policy engine that enables unified, conte...22.6SPIFFE - Secure Production Identity Framework for EveryoneSPIFFE is a CNCF-graduated open standard for workload identity in dynamic environments. It provides a frame...22.6SPIRE - SPIFFE Runtime EnvironmentSPIRE is the reference implementation of SPIFFE, a CNCF-graduated production-ready toolchain for establishi...22.6Greymatter Platform APIThe Greymatter Platform API provides programmatic access to configure and manage the Greymatter zero trust ...19.5CloudConnexa Public APIREST API for managing CloudConnexa Zero Trust networks, users, networks, connectors, DNS, routes, and acces...17.2Twingate Admin APIGraphQL Admin API for managing Twingate resources, remote networks, connectors, users, groups, devices, ser...14.8Ivanti Neurons for Zero-Trust AccessREST API for Ivanti Neurons for Zero-Trust Access, providing programmatic configuration of zero-trust polic...13.0Zscaler Private Access (ZPA) APIREST API for managing Zscaler Private Access (ZPA) configurations including segment groups, application seg...12.4
Minimal 1 Almost no public developer surface

Companies reaching this through an API (4)

These companies publish an API, specification or operation carrying “Zero Trust” but do not classify their business under it. Listed unranked and kept out of the count above, because one tagged operation is not a statement about what a company does.

Cloudflare HPE Aruba Networking SSH VPN

Score breakdown

Frequency
57.8
log-scaled weighted occurrences
Breadth
2.8
spread across providers
Quality lift
35.8
mean composite of providers using it
Cohesion
0.0
strength of nearest seed neighbor

Related tags

SASE 18 co-occurrences Network Security 25 co-occurrences Cloud Security 22 co-occurrences ZTNA 10 co-occurrences Privileged Access Management 10 co-occurrences VPN 11 co-occurrences Microsegmentation 8 co-occurrences Access Management 11 co-occurrences

Where this tag comes from

Provider tag102
Api tag30

Cohort brief

Auto-generated

The 97 providers in the APIs.io catalog tagged Zero Trust, scored on the Kin Score. Every figure below is computed from the catalog — nothing here is written.

Providers
97
all scored
Mean Kin Score
32.6
+8.7 vs catalog 23.9
Mean Agent Readiness
15.1
+3.1 vs catalog 12
Spread
3–71.5
median 31.8 · σ 16.3
How the 97 split by band
Exemplar 2Strong 10Developing 19Thin 29Emerging 31Minimal 6
Facet averages, against the whole catalog
FacetThis cohortCatalogDifferenceScored
Developer Ergonomics 37.6 23.4 +14.2 97
Contract Quality 28 19.8 +8.2 97
Operational Transparency 21.7 14 +7.7 97
Access Clarity 33.3 26.5 +6.8 97
Contract Governance 12.8 6.4 +6.4 97
Discoverability 67.1 61.2 +5.9 97

A facet is averaged over the members that carry it, not over the whole cohort — the “Scored” column is that count. Averaging an absent facet as zero would score our own coverage gaps as the providers’ posture.

What this cohort publishes
ArtifactThis cohortCatalogDifference
MCP server (any) 14% 10% +4
MCP server (first-party) 13% 13% 0
Agent Skills 0% 0% 0
OAuth scopes 10% 11% -1
Security 100% 97% +3
Arazzo workflows 2% 2% 0
Governance rules 22% 14% +8

mcp_pct counts any mcp/ artifact including ones API Evangelist derived from the provider OpenAPI; mcp_first_party_pct counts only servers the provider publishes. Prefer the latter.

All 102 members of this roster resolve to a scored provider in the catalog.Generated from the catalog build of 15 September 2026, across 27661 providers, using the same computation served by the APIs.io cohort API. Briefs are published for rosters of 5 or more scored providers; below that a distribution is not meaningful.

Work with this as data

Every tag here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for tags

7 MCP tools reach this
  • find_tagsBrowse and filter every tag in the catalog.
  • get_cohortThis tag as a scored cohort — every provider carrying it, with scores.
  • cohort_statsPRO — the distribution across this tag: mean, median, band split, adoption rates.
  • cohort_rankingsPRO — the leaderboard, on composite AND agent-readiness axes.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This tag
curl "https://apis.io/api/v1/tags/zero-trust"
All tags
curl "https://apis.io/api/v1/tags?limit=25"
As a scored cohort
curl "https://apis.io/api/v1/cohorts/tag/zero-trust"
The distribution (Pro)
curl "https://apis.io/api/v1/cohorts/tag/zero-trust/stats" \
  -H "X-API-Key: $APIS_IO_KEY"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.