Akamai API Security
Akamai API Security (formerly Noname Security) provides comprehensive API discovery, posture management, and threat protection for organizations across cloud, on-premises, and hybrid environments. The platform continuously discovers and monitors all APIs, identifies vulnerabilities and misconfigurations, detects and responds to API threats in real time, and provides pre-production security testing integrated into CI/CD pipelines.
Real signal across most facets with visible, nameable gaps — the contract exists but is thin, or the portal is good while governance and commercial terms are absent.
API Evangelist profiles Akamai API Security the way a machine reads it — 303 machine-readable artifacts across 65 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Akamai API Security scores 53.8/100 (developing), with a separate agent-readiness read of 39/100 (agent aware). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.
How we profile Akamai API Security
Each block below is one kind of artifact we hold for Akamai API Security. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
APIs 65
Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.
Individual APIs this provider publishes, each with its own machine-readable definition.
Akamai APIs
Akamai provides a comprehensive set of REST APIs for managing and configuring their platform services, including API security, CDN, edge computing, and security products. The AP...
Akamai API Security Activation history API
Get the activation history for a configuration.
Akamai API Security Activation status API
Get status information about your activations and activation requests.
Akamai API Security Activations API
Manage your security configuration activations.
Akamai API Security API endpoints API
Get the list of API endpoints associated with a security policy.
Akamai API Security API request constraints API
Manage API request limits and the actions to take when those limits are met.
Akamai API Security Attack payload logs API
Manage the attack payload log settings for your security configurations.
Akamai API Security Available hostnames API
List all hostnames for a given contract and group.
Akamai API Security Bypass network lists API
Manage the bypass network lists used with your security policies.
Akamai API Security Client reputation API
Manage your client reputation profiles.
Akamai API Security Client-Side Protections & Compliance API
The Client-Side Protections & Compliance API from Akamai API Security — 1 operation(s) for client-side protections & compliance.
Akamai API Security Configuration: Evaluation hostnames API
Manage hostnames you're currently evaluating for a configuration version. If using Web Application Protector, manage hostnames currently in evaluation mode. This mode lets you t...
Akamai API Security Configuration version diff API
The Configuration version diff API from Akamai API Security — 1 operation(s) for configuration version diff.
Akamai API Security Configuration version export API
Get comprehensive details about a security configuration version.
Akamai API Security Contracts and groups API
List the contracts and groups for your account.
Akamai API Security Cookie Settings API
The Cookie Settings API from Akamai API Security — 1 operation(s) for cookie settings.
Akamai API Security Custom rule actions API
Manage the actions contained in your custom rules. Use custom rules to handle scenarios not covered by the included standard rules or to quickly patch new website vulnerabilities.
Akamai API Security CVE Protections lookup API
See which CVEs are covered by App & API Protector. The catalog contains only CVEs that the Akamai Threat Research team is aware of. App & API Protector can identify and block at...
Akamai API Security Discovered APIs API
Get information about APIs discovered in your traffic that are new or not yet protected under API protections.
Akamai API Security Endpoints API
Manage the API endpoints associated with a security policy.
Akamai API Security Evasive path match API
Manage the evasive path match for your security configurations.
Akamai API Security Failover hostnames API
Get a list of the failover hostnames in a security configuration.
Akamai API Security General configuration settings API
Manage security configurations and their versions.
Akamai API Security General policy settings API
Manage security policies and their versions.
Akamai API Security Hostname coverage API
Get the list of hostnames in an account with their current protections, activation statuses, and other summary information.
Akamai API Security Hostnames API
Manage the hostnames in your configuration settings.
Akamai API Security HTTP header logs API
Manage the HTTP header log settings for security policies.
Akamai API Security IP/Geo Firewall settings API
Manage which network lists are used in the IP/Geo Firewall settings. If you want to add or remove IP addresses from the network lists, use the Network Lists API.
Akamai API Security Malware policy actions API
Manage the actions taken by your malware policies.
Akamai API Security Match targets API
Manage your match targets, which define which security policy applies to an API, hostname, or path.
Akamai API Security Onboarding: Activations and status API
Manage your onboardings' activations, and the activation history for each onboarding.
Akamai API Security Onboarding: Creation and settings API
Manage onboardings and their settings.
Akamai API Security Onboarding: Post-activation validation API
Manage your post activations validations and cname your hostnames to akamai in order to go live.
Akamai API Security PII learning API
Manage settings for Personally Identifiable Information (PII) learning. With this feature, the network discovers PII on your behalf.
Akamai API Security Pragma settings API
Manage the Pragma header settings for your security policies.
Akamai API Security Prefetch requests API
Manage your prefetch request protections. When enabled, your application firewall rules inspect internal requests, which are those between your origin and Akamai's servers, for ...
Akamai API Security Protections API
Manage various security policy protections. These settings enable or disable each protection on your policy. However, you set the protections themselves in their corresponding o...
Akamai API Security Rate policy actions API
Manage rate policy actions, which are the actions each policy takes when conditions are met.
Akamai API Security Reputation analysis API
If using Kona Site Defender, manage the reputation analysis settings.
Akamai API Security Request body inspection limits API
Manage limits for the maximum request body size allowed.
Akamai API Security Request body size API
Manage a security configuration's inspection limit settings for request bodies.
Akamai API Security Security policy: Conditions and exceptions API
Manage the attack groups and rules that you're currently evaluating for your security policies.
Akamai API Security Security policy: Evaluation attack groups API
Manage the attack groups that you're evaluating for your security configurations and policies.
Akamai API Security Security policy: Evaluation hostnames API
Manage hostnames you're currently evaluating for security policies.
Akamai API Security Security policy: Evaluation mode API
Set the evaluation mode for your security policies. This mode runs concurrently with your existing Web Application Firewall Rule settings and records how the rules would respond...
Akamai API Security Security policy: Evaluation penalty box API
Manage the penalty box settings that you're evaluating for your security policies.
Akamai API Security Security policy: Evaluation rules API
Manage the rules you're currently evaluating for security policies.
Akamai API Security Shared resources: Custom deny actions API
Manage your custom deny actions for security configurations and policies. Custom deny actions let you serve error messages, pages, and responses that meet your organization's un...
Akamai API Security Shared resources: Custom rules API
Manage your custom rules for security configurations and policies.
Akamai API Security Shared resources: Malware policies API
Manage your malware policies.
Akamai API Security Shared resources: Rate policies API
Manage rate policies for security configurations.
Akamai API Security Shared resources: Reputation profiles API
Manage your reputation profiles. Reputation protections identify potentially malicious IP addresses, scoring them based on prior interactions with other Akamai customers.
Akamai API Security SIEM settings API
Manage SIEM settings for your security configurations.
Akamai API Security Slow POST protections API
Manage your slow POST protection settings for your security policies.
Akamai API Security Subscriptions API
Manage the email subscriptions for features within a specific security configuration.
Akamai API Security URL protection policies API
Manage your URL protection policies.
Akamai API Security URL protection policy actions API
Manage your URL protection settings for your security policies.
Akamai API Security WAF rules: Attack groups API
Manage your WAF attack groups.
Akamai API Security WAF rules: Evaluation Penalty box conditions API
Manage the penalty box condition settings for your firewall rules.
Akamai API Security WAF rules: General settings API
Manage your Web Application Firewall (WAF) rules and rule sets.
Akamai API Security WAF rules: Penalty box API
Manage the penalty box settings for your Web Application Firewall implementation.
Akamai API Security WAF rules: Penalty box conditions API
Manage the conditions used with your Web Application Firewall's penalty box.
Akamai API Security WAF rules: Rapid rules API
Quickly manage and mitigate risks resulting from the most recent high-profile, critical vulnerabilities. __Note__. Rapid rules are rules you can apply while we are still testing...
Akamai API Security WAF rules: Tuning recommendations API
Manage the tuning recommendations for your WAF attack groups.
Akamai API Security WAF rules: Update mode API
Manage the mode used with your WAF rules. Your mode you set determines how your rule sets are updated.
Scroll within the panel for all 65 ·
Open Collections 1
Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Akamai: Application Security API
OPEN COLLECTIONPricing Plans 1
Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.
Published pricing tiers and plan structures.
Rate Limits 1
Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.
Documented rate limits and quota policies.
Akamai Api Security Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.
Cost, billing, and metering signals for API financial operations.
Features 6
The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.
Notable capabilities this provider offers.
API Discovery
Automatically discovers all APIs including shadow, zombie, GenAI, LLM, and MCP server APIs across cloud, on-premises, and hybrid environments.
Posture Management
Audits APIs for vulnerabilities and misconfigurations including the full OWASP API Top 10, generating posture findings from runtime incidents.
Runtime Protection
Uses contextual insights to detect and block API threats including business logic abuse, credential attacks, data scraping, and malicious bots in real time.
CI/CD Security Testing
Runs 200+ dynamic security tests simulating OWASP API Top 10 attacks integrated into CI/CD pipelines without sacrificing development speed.
GitHub Integration
Automatically scans GitHub repositories for OpenAPI specs and adds them to the API library for security analysis and posture assessment.
App and API Protector Integration
Direct integration with Akamai App and API Protector for blocking API threats detected at runtime.
Semantic Vocabularies 1
JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.
JSON-LD contexts and semantic vocabularies used across these APIs.
Akamai Api Security Context
JSON-LDSpectral Rules 2
Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.
Akamai API Security API Rules
SPECTRALAkamai API Security API Rules
SPECTRALJSON Schema 71
Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.
Standalone JSON Schema definitions for this provider's data models.
attack-payload-logging-get-200
JSON SCHEMAattack-payload-logging-put-200
JSON SCHEMAattack-payload-logging-put
JSON SCHEMAattack-payload-logging
JSON SCHEMAbypass-network-lists-get
JSON SCHEMAbypass-network-lists-put
JSON SCHEMAclient-reputation-condition
JSON SCHEMAconfig-clone-post
JSON SCHEMAconfig-get
JSON SCHEMAconfig-post
JSON SCHEMAconfig-rename
JSON SCHEMAconfigs-get
JSON SCHEMAcookie-settings
JSON SCHEMAcustom-denies
JSON SCHEMAcustom-deny
JSON SCHEMAcustom-rule
JSON SCHEMAcustom-rules
JSON SCHEMAeffectiveTimePeriod
JSON SCHEMAevasive-path-match-get-200
JSON SCHEMAevasive-path-match-put-200
JSON SCHEMAevasive-path-match-put
JSON SCHEMAheader-logging-get-200
JSON SCHEMAheader-logging-put-200
JSON SCHEMAheader-logging-put
JSON SCHEMAhost-info-in-config
JSON SCHEMAhostname-coverage-match-target-get-200
JSON SCHEMAhostname-coverage-match-target
JSON SCHEMAhostname-coverage-overlapping-get-200
JSON SCHEMAhostname-object
JSON SCHEMAhostnames
JSON SCHEMAlogging-header-setting
JSON SCHEMAlogging-option
JSON SCHEMAmalware-policies-content-types
JSON SCHEMAmalware-policies
JSON SCHEMAmalware-policy
JSON SCHEMAmatch-target
JSON SCHEMAmatch-targets
JSON SCHEMAmatch-targets-sequence
JSON SCHEMAoverlap-config
JSON SCHEMApii-learning
JSON SCHEMApragma-header
JSON SCHEMAprefetch-request-get-200
JSON SCHEMAprefetch-request-put-200
JSON SCHEMAprefetch-request-put
JSON SCHEMAproblem-details
JSON SCHEMArate-policies
JSON SCHEMArate-policy-evaluation-put
JSON SCHEMArate-policy
JSON SCHEMAreputation-profile
JSON SCHEMAreputation-profiles
JSON SCHEMArequest-body
JSON SCHEMArequest-header-condition-2
JSON SCHEMAsecurity-controls
JSON SCHEMAsiem-settings
JSON SCHEMAsiem-version
JSON SCHEMAsiem-versions
JSON SCHEMAtls-fingerprint-condition
JSON SCHEMAurl-protection-bypass-client-list-condition
JSON SCHEMAurl-protection-category
JSON SCHEMAurl-protection-client-list-category
JSON SCHEMAurl-protection-policies
JSON SCHEMAurl-protection-policy-hostpath
JSON SCHEMAurl-protection-policy
JSON SCHEMAvalidation
JSON SCHEMAvalidations
JSON SCHEMAversion-notes-get-200
JSON SCHEMAversion-notes-put-200
JSON SCHEMAversion-notes-put
JSON SCHEMAwaf-config-version
JSON SCHEMAwaf-config-versions
JSON SCHEMAScroll within the panel for all 71 ·
JSON Structure 71
JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.
JSON Structure definitions describing this provider's data shapes.
Api Security Attack Payload Logging Get 200 Structure
JSON STRUCTUREApi Security Attack Payload Logging Put 200 Structure
JSON STRUCTUREApi Security Attack Payload Logging Put Structure
JSON STRUCTUREApi Security Attack Payload Logging Structure
JSON STRUCTUREApi Security Bypass Network Lists Get Structure
JSON STRUCTUREApi Security Bypass Network Lists Put Structure
JSON STRUCTUREApi Security Client Reputation Condition Structure
JSON STRUCTUREApi Security Config Clone Post Structure
JSON STRUCTUREApi Security Config Get Structure
JSON STRUCTUREApi Security Config Post Structure
JSON STRUCTUREApi Security Config Rename Structure
JSON STRUCTUREApi Security Configs Get Structure
JSON STRUCTUREApi Security Cookie Settings Structure
JSON STRUCTUREApi Security Custom Denies Structure
JSON STRUCTUREApi Security Custom Deny Structure
JSON STRUCTUREApi Security Custom Rule Structure
JSON STRUCTUREApi Security Custom Rules Structure
JSON STRUCTUREApi Security Effective Time Period Structure
JSON STRUCTUREApi Security Evasive Path Match Get 200 Structure
JSON STRUCTUREApi Security Evasive Path Match Put 200 Structure
JSON STRUCTUREApi Security Evasive Path Match Put Structure
JSON STRUCTUREApi Security Header Logging Get 200 Structure
JSON STRUCTUREApi Security Header Logging Put 200 Structure
JSON STRUCTUREApi Security Header Logging Put Structure
JSON STRUCTUREApi Security Host Info In Config Structure
JSON STRUCTUREApi Security Hostname Coverage Match Target Structure
JSON STRUCTUREApi Security Hostname Object Structure
JSON STRUCTUREApi Security Hostnames Structure
JSON STRUCTUREApi Security Logging Header Setting Structure
JSON STRUCTUREApi Security Logging Option Structure
JSON STRUCTUREApi Security Malware Policies Content Types Structure
JSON STRUCTUREApi Security Malware Policies Structure
JSON STRUCTUREApi Security Malware Policy Structure
JSON STRUCTUREApi Security Match Target Structure
JSON STRUCTUREApi Security Match Targets Sequence Structure
JSON STRUCTUREApi Security Match Targets Structure
JSON STRUCTUREApi Security Overlap Config Structure
JSON STRUCTUREApi Security Pii Learning Structure
JSON STRUCTUREApi Security Pragma Header Structure
JSON STRUCTUREApi Security Prefetch Request Get 200 Structure
JSON STRUCTUREApi Security Prefetch Request Put 200 Structure
JSON STRUCTUREApi Security Prefetch Request Put Structure
JSON STRUCTUREApi Security Problem Details Structure
JSON STRUCTUREApi Security Rate Policies Structure
JSON STRUCTUREApi Security Rate Policy Evaluation Put Structure
JSON STRUCTUREApi Security Rate Policy Structure
JSON STRUCTUREApi Security Reputation Profile Structure
JSON STRUCTUREApi Security Reputation Profiles Structure
JSON STRUCTUREApi Security Request Body Structure
JSON STRUCTUREApi Security Request Header Condition 2 Structure
JSON STRUCTUREApi Security Security Controls Structure
JSON STRUCTUREApi Security Siem Settings Structure
JSON STRUCTUREApi Security Siem Version Structure
JSON STRUCTUREApi Security Siem Versions Structure
JSON STRUCTUREApi Security Tls Fingerprint Condition Structure
JSON STRUCTUREApi Security Url Protection Category Structure
JSON STRUCTUREApi Security Url Protection Policies Structure
JSON STRUCTUREApi Security Url Protection Policy Hostpath Structure
JSON STRUCTUREApi Security Url Protection Policy Structure
JSON STRUCTUREApi Security Validation Structure
JSON STRUCTUREApi Security Validations Structure
JSON STRUCTUREApi Security Version Notes Get 200 Structure
JSON STRUCTUREApi Security Version Notes Put 200 Structure
JSON STRUCTUREApi Security Version Notes Put Structure
JSON STRUCTUREApi Security Waf Config Version Structure
JSON STRUCTUREApi Security Waf Config Versions Structure
JSON STRUCTUREScroll within the panel for all 71 ·
Examples 71
Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.
Example request and response payloads for these APIs.
Scroll within the panel for all 71 ·
Security Posture 1
Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.
Recommended x-agentic-access execution contracts for AI agents.
Use Cases 5
What developers actually build with this provider — captured so the catalogue answers 'what is this for', not just 'what does this expose'.
What developers build with this provider.
Shadow API Discovery
Security teams automatically discover undocumented and shadow APIs across their environment to eliminate blind spots.
API Vulnerability Assessment
Security engineers assess API posture against OWASP API Top 10 and compliance frameworks to prioritize remediation.
Real-Time Threat Detection
SOC analysts detect and respond to API attacks, data leakage, and suspicious behavior in real time.
Pre-Production API Testing
Development teams integrate API security testing into CI/CD pipelines to find and fix vulnerabilities before production.
Compliance Reporting
Compliance teams assess API security posture against industry frameworks and generate audit-ready reports.
Integrations 5
Pre-built integrations with other platforms tell you where this provider already fits in a stack.
Pre-built integrations with other platforms and tools.
Akamai App and API Protector
Direct integration for blocking API threats detected by API Security
GitHub
Automatic OpenAPI spec discovery from GitHub repositories
CI/CD Pipelines
Integration with development pipelines for pre-production security testing
SIEM
Export security events to SIEM platforms for centralized monitoring
AWS Marketplace
Available on AWS Marketplace for cloud-native deployments
Resources
Every other property we hold for Akamai API Security — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Get Started 2
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 2
Pagination, idempotency, versioning, errors, and events
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 1
Authentication, authorization, and security posture
Operate 2
Status, limits, changes, and where to get help
Commercial 1
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Other 1
Properties that don't map to a standard resource type
← All providers · Data indexed from github.com/api-evangelist/akamai-api-security · machine-readable index on apis.io