emerging · 1.5 market domain

Zero Trust

Score 21.8 / 100 98 providers 26 APIs Search apis.io →
Variants seen in the corpus: Zero Trustzero-trust

Providers using this tag (98)

Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.

Exemplar 1 Complete, well-documented, and agent-ready
Strong 7 Solid coverage with minor gaps
Developing 17 Usable, with meaningful gaps to close
Thin 27 Limited public surface area
AryakaCompanyNetworkingSASESD-WAN39.0WatchGuardCloud SecurityEndpoint SecurityFirewallMFA11 APIs38.7CyberArkAuthenticationCloud SecurityConjurCredential Vault10 APIs37.8RubrikBackupCyber RecoveryData SecurityData Security Posture Management8 APIs37.7Skyhigh SecurityCompanyCybersecuritySecurity Service EdgeCASB1 API37.1StrongDMCompanySecurityPrivileged Access Management1 API37.1SPIREAuthenticationCloud-NativeGraduatedIdentity5 APIs36.8Google BeyondCorpAccess ControlEnterprise SecurityIdentitySecurity3 APIs35.4AviatrixCompanyCloud NetworkingCloud SecurityMulti-Cloud35.3AppOmniSaaS SecurityComplianceThreat DetectionCASB3 APIs35.1SSHSSHSecure ShellRemote AccessCryptography6 APIs34.5Consul ConnectConsulEnvoyHashiCorpIntentions4 APIs34.0JumpCloudIdentityDirectory ServicesSSOMFA7 APIs33.1Zero Trust Network AccessAccess ControlCloud SecurityCybersecurityIdentity Management12 APIs33.1VirsecCompanySecurityCybersecurityApplication Security2 APIs32.8NetBirdNetworkingVPNOpen-Source39 APIs32.6SPIFFEAuthenticationCloud-NativeGraduatedIdentity4 APIs32.0TailscaleVPNMesh NetworkingWireGuard7 APIs31.8Perimeter 81CompanyCybersecuritySASE17 APIs31.6Versa NetworksCompanyNetworkingSecuritySASE2 APIs28.9VPNEncryptionNetworkingPrivacySecurity6 APIs28.8IllumioCompanySecurityCybersecurity1 API28.6CentrifyCompanyIdentityPrivileged Access ManagementAccess Management1 API28.3Cisco Secure ClientEndpoint SecurityRemote AccessSecurityVPN11 APIs28.3BeyondTrustAccessAccess ManagementComplianceCredentials6 APIs28.0CyberArk IdentityIdentityAccess ManagementIAMSingle Sign-On8 APIs27.3Cato NetworksCompanyCybersecuritySASESSE1 API26.6
Emerging 34 Early or largely undocumented
Zero-Trust Security ModelAccess ControlCybersecurityFederalIdentity Management5 APIs25.8AppaegisCompanySecurityEnterprise Browser1 API25.1SilverfortCompanyIdentitySecurityAuthentication1 API24.7HPE Aruba NetworkingNetworkingSwitchingWi-FiSD-WAN10 APIs23.1Zero Trust ArchitectureAccess ControlAuthenticationAuthorizationCybersecurity5 APIs22.6ForescoutCompanyCybersecurityNetwork SecurityDevice Visibility3 APIs22.5UnisysFortune 1000SecurityNetwork Security4 APIs21.6BuoyantAI ObservabilityKubernetesLinkerdmTLS2 APIs20.7Duo SecurityAuthenticationMFAIdentity7 APIs20.0AdytonCompanyEnterprise SaasDefense19.9Ambient MeshService MeshIstioKubernetes1 API19.6GreymatterEnterpriseKubernetesNetworkingService Mesh3 APIs19.5PulseIvantiNetwork SecuritySecure AccessSSL VPN3 APIs18.9OtterizeCompanyBusiness ApplicationsKubernetesAccess Control18.6ElisityCompanyCybersecurityMicrosegmentation18.0SonicWallCybersecurityNetwork SecurityFirewallNext-Generation Firewall17.7OpenVPNVPNNetwork SecurityRemote Access2 APIs16.0Cloudflare.comAliasApplication ServicesCDNDNS1 API15.5VeniceCompanySecurityPrivileged Access ManagementIdentity Security15.5AceissCompanySecurityIdentity and Access ManagementAccess Control15.2Menlo SecurityCompanySecurityCybersecurityBrowser Security15.1TwingateZTNANetwork AccessVPN Replacement1 API14.8SpirlCompanySecurityIdentityNon-Human Identity14.6NewCoreCompanySecurityIdentityIAM14.2API DynamicsAPI SecurityAPI DiscoveryAPI Observability1 API13.6IslandCompanyCybersecurityEnterprise Browser13.5NileNetworkingEnterprise NetworkingNetwork as a ServiceNaaS13.0ZscalerCloud SecuritySASENetwork Security2 APIs12.4Red AccessCompanySecurityCybersecuritySecure Service Edge12.3Menlo SecurityCompanySecurityBrowser Security12.2NetskopeSecuritySASESSECASB2 APIs11.7WenspiredataCompanyCybersecurityPrivileged Access Management11.7ZorusCompanyCybersecurityDNS FilteringWeb Protection11.5IvantiEndpoint ManagementIT Asset ManagementITSMPatch Management5 APIs11.1
Minimal 12 Almost no public developer surface

APIs with this tag (26)

Ranked by the provider's API Evangelist rating — the Kin Score is scored per provider, not per API, so every API of a provider shares its band. How the rating works →

Strong 2 Solid coverage with minor gaps
Developing 3 Usable, with meaningful gaps to close
Thin 4 Limited public surface area
Emerging 16 Early or largely undocumented
NIST SP 800-207 Zero Trust ArchitectureThe foundational specification of the Zero Trust security model. Defines the seven tenets, the PDP/PEP/PA l...25.8HPE Aruba Networking SSE APIThe HPE Aruba Networking SSE (Security Service Edge) API exposes the Axis Security / HPE SSE cloud-delivere...23.1NIST SP 800-207 Zero Trust ArchitectureNIST Special Publication 800-207 defines zero trust architecture (ZTA) and provides a roadmap for organizat...22.6NIST SP 800-207A ZTA for Cloud-Native ApplicationsNIST SP 800-207A extends the original ZTA guidance to cover cloud-native applications in multi-cloud enviro...22.6Open Policy Agent (OPA)Open Policy Agent is a CNCF-graduated open source general-purpose policy engine that enables unified, conte...22.6SPIFFE - Secure Production Identity Framework for EveryoneSPIFFE is a CNCF-graduated open standard for workload identity in dynamic environments. It provides a frame...22.6SPIRE - SPIFFE Runtime EnvironmentSPIRE is the reference implementation of SPIFFE, a CNCF-graduated production-ready toolchain for establishi...22.6Linkerd Service MeshLinkerd is a CNCF-graduated service mesh for Kubernetes that transparently adds mutual TLS encryption, late...20.7Ambient MeshAmbient Mesh provides a sidecar-less service mesh via the Kubernetes Gateway API and Istio ambient mode. It...19.6Greymatter Platform APIThe Greymatter Platform API provides programmatic access to configure and manage the Greymatter zero trust ...19.5Ivanti Neurons for Zero Trust Access REST APIREST API for managing Ivanti Neurons for Zero Trust Access (nZTA), providing endpoints for managing zero tr...18.9CloudConnexa Public APIREST API for managing CloudConnexa Zero Trust networks, users, networks, connectors, DNS, routes, and acces...16.0Twingate Admin APIGraphQL Admin API for managing Twingate resources, remote networks, connectors, users, groups, devices, ser...14.8API Dynamics PlatformThe APIDynamics platform provides AI-driven API security and observability including API discovery, traffic...13.6Zscaler Private Access (ZPA) APIREST API for managing Zscaler Private Access (ZPA) configurations including segment groups, application seg...12.4Ivanti Neurons for Zero-Trust AccessREST API for Ivanti Neurons for Zero-Trust Access, providing programmatic configuration of zero-trust polic...11.1
Minimal 1 Almost no public developer surface

Score breakdown

Frequency
57.1
log-scaled weighted occurrences
Breadth
2.7
spread across providers
Quality lift
34.5
mean composite of providers using it
Cohesion
0.0
strength of nearest seed neighbor

Related tags

Network Security 23 co-occurrences SASE 16 co-occurrences Cloud Security 20 co-occurrences VPN 11 co-occurrences Privileged Access Management 9 co-occurrences ZTNA 8 co-occurrences Microsegmentation 7 co-occurrences MFA 8 co-occurrences

Where this tag comes from

Provider tag94
Api tag26

Cohort brief

Auto-generated

The 98 providers in the APIs.io catalog tagged Zero Trust, scored on the Kin Score. Every figure below is computed from the catalog — nothing here is written.

Providers
98
all scored
Mean Kin Score
28.7
+8.0 vs catalog 20.7
Mean Agent Readiness
13.3
+3.6 vs catalog 9.7
Spread
3–67.8
median 28.2 · σ 16.1
How the 98 split by band
Exemplar 1Strong 7Developing 17Thin 27Emerging 34Minimal 12
Facet averages, against the whole catalog
FacetThis cohortCatalogDifferenceScored
Developer Ergonomics 30.2 17.9 +12.3 98
Contract Quality 26.4 17.5 +8.9 98
Discoverability 66.7 60.4 +6.3 98
Operational Transparency 17.5 11.3 +6.2 98
Contract Governance 12 6.4 +5.6 98
Access Clarity 27.9 22.3 +5.6 98

A facet is averaged over the members that carry it, not over the whole cohort — the “Scored” column is that count. Averaging an absent facet as zero would score our own coverage gaps as the providers’ posture.

What this cohort publishes
ArtifactThis cohortCatalogDifference
MCP server (any) 19% 16% +3
MCP server (first-party) 6% 7% -1
Agent Skills 0% 0% 0
OAuth scopes 7% 9% -2
Security 96% 88% +8
Arazzo workflows 3% 2% +1
Governance rules 26% 13% +13

mcp_pct counts any mcp/ artifact including ones API Evangelist derived from the provider OpenAPI; mcp_first_party_pct counts only servers the provider publishes. Prefer the latter.

All 98 members of this roster resolve to a scored provider in the catalog.Generated from the catalog build of 25 August 2026, across 26891 providers, using the same computation served by the APIs.io cohort API. Briefs are published for rosters of 5 or more scored providers; below that a distribution is not meaningful.

Work with this as data

Every tag here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for tags

7 MCP tools reach this
  • find_tagsBrowse and filter every tag in the catalog.
  • get_cohortThis tag as a scored cohort — every provider carrying it, with scores.
  • cohort_statsPRO — the distribution across this tag: mean, median, band split, adoption rates.
  • cohort_rankingsPRO — the leaderboard, on composite AND agent-readiness axes.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This tag
curl "https://apis.io/api/v1/tags/zero-trust"
All tags
curl "https://apis.io/api/v1/tags?limit=25"
As a scored cohort
curl "https://apis.io/api/v1/cohorts/tag/zero-trust"
The distribution (Pro)
curl "https://apis.io/api/v1/cohorts/tag/zero-trust/stats" \
  -H "X-API-Key: $APIS_IO_KEY"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.