Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC
Akamai API Security website screenshot

Akamai API Security

Akamai API Security (formerly Noname Security) provides comprehensive API discovery, posture management, and threat protection for organizations across cloud, on-premises, and hybrid environments. The platform continuously discovers and monitors all APIs, identifies vulnerabilities and misconfigurations, detects and responds to API threats in real time, and provides pre-production security testing integrated into CI/CD pipelines.

agent aware

Real signal across most facets with visible, nameable gaps — the contract exists but is thin, or the portal is good while governance and commercial terms are absent.

Kin Score

API Evangelist profiles Akamai API Security the way a machine reads it — 303 machine-readable artifacts across 65 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.

Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Akamai API Security scores 53.8/100 (developing), with a separate agent-readiness read of 39/100 (agent aware). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.

Kin Score

This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 53.8/100 · developing
Contract Quality 14.2 / 25
Developer Ergonomics 3.0 / 20
Commercial Clarity 12.6 / 20
Operational Transparency 6.8 / 13
Governance 10.4 / 12
Discoverability 6.8 / 10
Agent readiness — 39/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3

How we profile Akamai API Security

Each block below is one kind of artifact we hold for Akamai API Security. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.

APIs 65

Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.

Individual APIs this provider publishes, each with its own machine-readable definition.

Akamai APIs

Akamai provides a comprehensive set of REST APIs for managing and configuring their platform services, including API security, CDN, edge computing, and security products. The AP...

Akamai API Security Activation history API

Get the activation history for a configuration.

Akamai API Security Activation status API

Get status information about your activations and activation requests.

Akamai API Security Activations API

Manage your security configuration activations.

Akamai API Security API endpoints API

Get the list of API endpoints associated with a security policy.

Akamai API Security API request constraints API

Manage API request limits and the actions to take when those limits are met.

Akamai API Security Attack payload logs API

Manage the attack payload log settings for your security configurations.

Akamai API Security Available hostnames API

List all hostnames for a given contract and group.

Akamai API Security Bypass network lists API

Manage the bypass network lists used with your security policies.

Akamai API Security Client reputation API

Manage your client reputation profiles.

Akamai API Security Client-Side Protections & Compliance API

The Client-Side Protections & Compliance API from Akamai API Security — 1 operation(s) for client-side protections & compliance.

Akamai API Security Configuration: Evaluation hostnames API

Manage hostnames you're currently evaluating for a configuration version. If using Web Application Protector, manage hostnames currently in evaluation mode. This mode lets you t...

Akamai API Security Configuration version diff API

The Configuration version diff API from Akamai API Security — 1 operation(s) for configuration version diff.

Akamai API Security Configuration version export API

Get comprehensive details about a security configuration version.

Akamai API Security Contracts and groups API

List the contracts and groups for your account.

Akamai API Security Cookie Settings API

The Cookie Settings API from Akamai API Security — 1 operation(s) for cookie settings.

Akamai API Security Custom rule actions API

Manage the actions contained in your custom rules. Use custom rules to handle scenarios not covered by the included standard rules or to quickly patch new website vulnerabilities.

Akamai API Security CVE Protections lookup API

See which CVEs are covered by App & API Protector. The catalog contains only CVEs that the Akamai Threat Research team is aware of. App & API Protector can identify and block at...

Akamai API Security Discovered APIs API

Get information about APIs discovered in your traffic that are new or not yet protected under API protections.

Akamai API Security Endpoints API

Manage the API endpoints associated with a security policy.

Akamai API Security Evasive path match API

Manage the evasive path match for your security configurations.

Akamai API Security Failover hostnames API

Get a list of the failover hostnames in a security configuration.

Akamai API Security General configuration settings API

Manage security configurations and their versions.

Akamai API Security General policy settings API

Manage security policies and their versions.

Akamai API Security Hostname coverage API

Get the list of hostnames in an account with their current protections, activation statuses, and other summary information.

Akamai API Security Hostnames API

Manage the hostnames in your configuration settings.

Akamai API Security HTTP header logs API

Manage the HTTP header log settings for security policies.

Akamai API Security IP/Geo Firewall settings API

Manage which network lists are used in the IP/Geo Firewall settings. If you want to add or remove IP addresses from the network lists, use the Network Lists API.

Akamai API Security Malware policy actions API

Manage the actions taken by your malware policies.

Akamai API Security Match targets API

Manage your match targets, which define which security policy applies to an API, hostname, or path.

Akamai API Security Onboarding: Activations and status API

Manage your onboardings' activations, and the activation history for each onboarding.

Akamai API Security Onboarding: Creation and settings API

Manage onboardings and their settings.

Akamai API Security Onboarding: Post-activation validation API

Manage your post activations validations and cname your hostnames to akamai in order to go live.

Akamai API Security PII learning API

Manage settings for Personally Identifiable Information (PII) learning. With this feature, the network discovers PII on your behalf.

Akamai API Security Pragma settings API

Manage the Pragma header settings for your security policies.

Akamai API Security Prefetch requests API

Manage your prefetch request protections. When enabled, your application firewall rules inspect internal requests, which are those between your origin and Akamai's servers, for ...

Akamai API Security Protections API

Manage various security policy protections. These settings enable or disable each protection on your policy. However, you set the protections themselves in their corresponding o...

Akamai API Security Rate policy actions API

Manage rate policy actions, which are the actions each policy takes when conditions are met.

Akamai API Security Reputation analysis API

If using Kona Site Defender, manage the reputation analysis settings.

Akamai API Security Request body inspection limits API

Manage limits for the maximum request body size allowed.

Akamai API Security Request body size API

Manage a security configuration's inspection limit settings for request bodies.

Akamai API Security Security policy: Conditions and exceptions API

Manage the attack groups and rules that you're currently evaluating for your security policies.

Akamai API Security Security policy: Evaluation attack groups API

Manage the attack groups that you're evaluating for your security configurations and policies.

Akamai API Security Security policy: Evaluation hostnames API

Manage hostnames you're currently evaluating for security policies.

Akamai API Security Security policy: Evaluation mode API

Set the evaluation mode for your security policies. This mode runs concurrently with your existing Web Application Firewall Rule settings and records how the rules would respond...

Akamai API Security Security policy: Evaluation penalty box API

Manage the penalty box settings that you're evaluating for your security policies.

Akamai API Security Security policy: Evaluation rules API

Manage the rules you're currently evaluating for security policies.

Akamai API Security Shared resources: Custom deny actions API

Manage your custom deny actions for security configurations and policies. Custom deny actions let you serve error messages, pages, and responses that meet your organization's un...

Akamai API Security Shared resources: Custom rules API

Manage your custom rules for security configurations and policies.

Akamai API Security Shared resources: Rate policies API

Manage rate policies for security configurations.

Akamai API Security Shared resources: Reputation profiles API

Manage your reputation profiles. Reputation protections identify potentially malicious IP addresses, scoring them based on prior interactions with other Akamai customers.

Akamai API Security SIEM settings API

Manage SIEM settings for your security configurations.

Akamai API Security Slow POST protections API

Manage your slow POST protection settings for your security policies.

Akamai API Security Subscriptions API

Manage the email subscriptions for features within a specific security configuration.

Akamai API Security URL protection policies API

Manage your URL protection policies.

Akamai API Security URL protection policy actions API

Manage your URL protection settings for your security policies.

Akamai API Security WAF rules: Attack groups API

Manage your WAF attack groups.

Akamai API Security WAF rules: Evaluation Penalty box conditions API

Manage the penalty box condition settings for your firewall rules.

Akamai API Security WAF rules: General settings API

Manage your Web Application Firewall (WAF) rules and rule sets.

Akamai API Security WAF rules: Penalty box API

Manage the penalty box settings for your Web Application Firewall implementation.

Akamai API Security WAF rules: Penalty box conditions API

Manage the conditions used with your Web Application Firewall's penalty box.

Akamai API Security WAF rules: Rapid rules API

Quickly manage and mitigate risks resulting from the most recent high-profile, critical vulnerabilities. __Note__. Rapid rules are rules you can apply while we are still testing...

Akamai API Security WAF rules: Tuning recommendations API

Manage the tuning recommendations for your WAF attack groups.

Akamai API Security WAF rules: Update mode API

Manage the mode used with your WAF rules. Your mode you set determines how your rule sets are updated.

Scroll within the panel for all 65 ·

Open Collections 1

Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Pricing Plans 1

Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.

Published pricing tiers and plan structures.

Rate Limits 1

Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.

Documented rate limits and quota policies.

Akamai Api Security Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.

Cost, billing, and metering signals for API financial operations.

Features 6

The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.

Notable capabilities this provider offers.

API Discovery

Automatically discovers all APIs including shadow, zombie, GenAI, LLM, and MCP server APIs across cloud, on-premises, and hybrid environments.

Posture Management

Audits APIs for vulnerabilities and misconfigurations including the full OWASP API Top 10, generating posture findings from runtime incidents.

Runtime Protection

Uses contextual insights to detect and block API threats including business logic abuse, credential attacks, data scraping, and malicious bots in real time.

CI/CD Security Testing

Runs 200+ dynamic security tests simulating OWASP API Top 10 attacks integrated into CI/CD pipelines without sacrificing development speed.

GitHub Integration

Automatically scans GitHub repositories for OpenAPI specs and adds them to the API library for security analysis and posture assessment.

App and API Protector Integration

Direct integration with Akamai App and API Protector for blocking API threats detected at runtime.

Semantic Vocabularies 1

JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.

JSON-LD contexts and semantic vocabularies used across these APIs.

Akamai Api Security Context

71 classes · 180 properties

JSON-LD

Spectral Rules 2

Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.

Akamai API Security API Rules

5 rules · 3 warnings

SPECTRAL

Akamai API Security API Rules

28 rules · 12 errors · 15 warnings

SPECTRAL

JSON Schema 71

Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.

Standalone JSON Schema definitions for this provider's data models.

attack-payload-logging-get-200

3 properties

JSON SCHEMA

attack-payload-logging-put-200

3 properties

JSON SCHEMA

attack-payload-logging-put

3 properties

JSON SCHEMA

attack-payload-logging

1 properties

JSON SCHEMA

bypass-network-lists-get

1 properties

JSON SCHEMA

bypass-network-lists-put

1 properties

JSON SCHEMA

client-reputation-condition

5 properties

JSON SCHEMA

config-clone-post

2 properties

JSON SCHEMA

config-get

7 properties

JSON SCHEMA

config-post

6 properties

JSON SCHEMA

config-rename

2 properties

JSON SCHEMA

configs-get

1 properties

JSON SCHEMA

cookie-settings

2 properties

JSON SCHEMA

custom-denies

1 properties

JSON SCHEMA

custom-deny

4 properties

JSON SCHEMA

custom-rule

16 properties

JSON SCHEMA

custom-rules

1 properties

JSON SCHEMA

effectiveTimePeriod

3 properties

JSON SCHEMA

evasive-path-match-get-200

1 properties

JSON SCHEMA

evasive-path-match-put-200

1 properties

JSON SCHEMA

evasive-path-match-put

1 properties

JSON SCHEMA

header-logging-get-200

4 properties

JSON SCHEMA

header-logging-put-200

4 properties

JSON SCHEMA

header-logging-put

4 properties

JSON SCHEMA

host-info-in-config

6 properties

JSON SCHEMA

hostname-coverage-match-target

14 properties

JSON SCHEMA

hostname-coverage-overlapping-get-200

1 properties

JSON SCHEMA

hostname-object

6 properties

JSON SCHEMA

hostnames

2 properties

JSON SCHEMA

logging-header-setting

2 properties

JSON SCHEMA

logging-option

3 properties

JSON SCHEMA

malware-policies-content-types

1 properties

JSON SCHEMA

malware-policies

1 properties

JSON SCHEMA

malware-policy

9 properties

JSON SCHEMA

match-target

16 properties

JSON SCHEMA

match-targets

1 properties

JSON SCHEMA

match-targets-sequence

2 properties

JSON SCHEMA

overlap-config

6 properties

JSON SCHEMA

pii-learning

1 properties

JSON SCHEMA

pragma-header

3 properties

JSON SCHEMA

prefetch-request-get-200

4 properties

JSON SCHEMA

prefetch-request-put-200

4 properties

JSON SCHEMA

prefetch-request-put

4 properties

JSON SCHEMA

problem-details

6 properties

JSON SCHEMA

rate-policies

1 properties

JSON SCHEMA

rate-policy-evaluation-put

1 properties

JSON SCHEMA

rate-policy

28 properties

JSON SCHEMA

reputation-profile

9 properties

JSON SCHEMA

reputation-profiles

1 properties

JSON SCHEMA

request-body

1 properties

JSON SCHEMA

request-header-condition-2

7 properties

JSON SCHEMA

security-controls

7 properties

JSON SCHEMA

siem-settings

6 properties

JSON SCHEMA

siem-version

2 properties

JSON SCHEMA

siem-versions

1 properties

JSON SCHEMA

tls-fingerprint-condition

3 properties

JSON SCHEMA

url-protection-category

1 properties

JSON SCHEMA

url-protection-client-list-category

3 properties

JSON SCHEMA

url-protection-policies

1 properties

JSON SCHEMA

url-protection-policy-hostpath

2 properties

JSON SCHEMA

url-protection-policy

18 properties

JSON SCHEMA

validation

5 properties

JSON SCHEMA

validations

3 properties

JSON SCHEMA

version-notes-get-200

1 properties

JSON SCHEMA

version-notes-put-200

1 properties

JSON SCHEMA

version-notes-put

1 properties

JSON SCHEMA

waf-config-version

9 properties

JSON SCHEMA

waf-config-versions

11 properties

JSON SCHEMA

Scroll within the panel for all 71 ·

JSON Structure 71

JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.

JSON Structure definitions describing this provider's data shapes.

Api Security Config Clone Post Structure

2 properties

JSON STRUCTURE

Api Security Config Get Structure

7 properties

JSON STRUCTURE

Api Security Config Post Structure

6 properties

JSON STRUCTURE

Api Security Config Rename Structure

2 properties

JSON STRUCTURE

Api Security Configs Get Structure

1 properties

JSON STRUCTURE

Api Security Cookie Settings Structure

2 properties

JSON STRUCTURE

Api Security Custom Denies Structure

1 properties

JSON STRUCTURE

Api Security Custom Deny Structure

4 properties

JSON STRUCTURE

Api Security Custom Rule Structure

16 properties

JSON STRUCTURE

Api Security Custom Rules Structure

1 properties

JSON STRUCTURE

Api Security Header Logging Put Structure

4 properties

JSON STRUCTURE

Api Security Host Info In Config Structure

6 properties

JSON STRUCTURE

Api Security Hostname Object Structure

6 properties

JSON STRUCTURE

Api Security Hostnames Structure

2 properties

JSON STRUCTURE

Api Security Logging Option Structure

3 properties

JSON STRUCTURE

Api Security Malware Policies Structure

1 properties

JSON STRUCTURE

Api Security Malware Policy Structure

9 properties

JSON STRUCTURE

Api Security Match Target Structure

16 properties

JSON STRUCTURE

Api Security Match Targets Structure

1 properties

JSON STRUCTURE

Api Security Overlap Config Structure

6 properties

JSON STRUCTURE

Api Security Pii Learning Structure

1 properties

JSON STRUCTURE

Api Security Pragma Header Structure

3 properties

JSON STRUCTURE

Api Security Problem Details Structure

6 properties

JSON STRUCTURE

Api Security Rate Policies Structure

1 properties

JSON STRUCTURE

Api Security Rate Policy Structure

28 properties

JSON STRUCTURE

Api Security Reputation Profile Structure

9 properties

JSON STRUCTURE

Api Security Reputation Profiles Structure

1 properties

JSON STRUCTURE

Api Security Request Body Structure

1 properties

JSON STRUCTURE

Api Security Security Controls Structure

7 properties

JSON STRUCTURE

Api Security Siem Settings Structure

6 properties

JSON STRUCTURE

Api Security Siem Version Structure

2 properties

JSON STRUCTURE

Api Security Siem Versions Structure

1 properties

JSON STRUCTURE

Api Security Validation Structure

5 properties

JSON STRUCTURE

Api Security Validations Structure

3 properties

JSON STRUCTURE

Api Security Version Notes Put Structure

1 properties

JSON STRUCTURE

Api Security Waf Config Version Structure

9 properties

JSON STRUCTURE

Api Security Waf Config Versions Structure

11 properties

JSON STRUCTURE

Scroll within the panel for all 71 ·

Examples 71

Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.

Example request and response payloads for these APIs.

Scroll within the panel for all 71 ·

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Akamai Api Security Domain Security

TLSv1.3 · DNSSEC · DMARC

SECURITY

Agentic Access 1

An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.

Recommended x-agentic-access execution contracts for AI agents.

Akamai Api Security Agentic Access

213 operations · 103 acting

213 operations · 103 acting

AGENTIC

Use Cases 5

What developers actually build with this provider — captured so the catalogue answers 'what is this for', not just 'what does this expose'.

What developers build with this provider.

Shadow API Discovery

Security teams automatically discover undocumented and shadow APIs across their environment to eliminate blind spots.

API Vulnerability Assessment

Security engineers assess API posture against OWASP API Top 10 and compliance frameworks to prioritize remediation.

Real-Time Threat Detection

SOC analysts detect and respond to API attacks, data leakage, and suspicious behavior in real time.

Pre-Production API Testing

Development teams integrate API security testing into CI/CD pipelines to find and fix vulnerabilities before production.

Compliance Reporting

Compliance teams assess API security posture against industry frameworks and generate audit-ready reports.

Integrations 5

Pre-built integrations with other platforms tell you where this provider already fits in a stack.

Pre-built integrations with other platforms and tools.

Akamai App and API Protector

Direct integration for blocking API threats detected by API Security

GitHub

Automatic OpenAPI spec discovery from GitHub repositories

CI/CD Pipelines

Integration with development pipelines for pre-production security testing

SIEM

Export security events to SIEM platforms for centralized monitoring

AWS Marketplace

Available on AWS Marketplace for cloud-native deployments

Resources

Every other property we hold for Akamai API Security — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.

Get Started 2

Portal, sign-up, and the first successful call

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 2

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 1

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 1

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 1

Properties that don't map to a standard resource type

← All providers · Data indexed from github.com/api-evangelist/akamai-api-security · machine-readable index on apis.io