ControlUp
ControlUp is a Digital Employee Experience (DEX) and Autonomous Endpoint Management (AEM) platform that monitors, scores and remediates the end-user computing estate — physical desktops and laptops, VDI and DaaS (Citrix CVAD / Citrix Cloud, Omnissa Horizon, Azure Virtual Desktop, Windows 365, Parallels RAS), the applications and sessions running on them, and the network path in between. The ControlUp ONE platform spans ControlUp for Desktops, for VDI, for Apps, for Frontline Workers and for Compliance, plus Synthetic Monitoring (Scouts and Hives), Workflows, and Pulse AI. It publishes a public REST API surface at api.controlup.com documented on a ReadMe hub at api.controlup.io, an RFC 9727 /.well-known/api-catalog linkset enumerating twelve OpenAPI definitions, an official Model Context Protocol server on npm (@controlup-ai/mcp) exposing 106 tools across six product domains, PowerShell cmdlets for monitor and agent automation, and llms.txt indexes on both the documentation and API hosts.
Solid contracts, transparent operations, and an easy start — typically complete on four or five facets with one clear soft spot.
API Evangelist profiles ControlUp the way a machine reads it — 129 machine-readable artifacts across 61 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — ControlUp scores 65.4/100 (strong), with a separate agent-readiness read of 59/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.
Put this on your own site. The badge is drawn live from ControlUp's current Kin Score — paste it once and it updates itself every time the score is recomputed. It follows your visitor's light or dark setting, and it links back here so anyone who sees it can read the full breakdown.
<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/controlup/"
title="ControlUp on API Evangelist — API profile and Kin Score">
<img src="https://apis.io/badge/controlup.svg"
alt="ControlUp Kin Score — API readiness rating by API Evangelist" width="150" height="150" loading="lazy">
</a>
[](https://providers.apievangelist.com/providers/controlup/)
<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/controlup/"
title="ControlUp on API Evangelist — API profile and Kin Score">
<img src="https://apis.io/badge/controlup/card.svg"
alt="ControlUp Kin Score — API readiness rating by API Evangelist" width="340" height="120" loading="lazy">
</a>
More shapes, themes and sizes → · Score as JSON · How badges work
How we profile ControlUp
Each block below is one kind of artifact we hold for ControlUp. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
APIs 61
Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.
Individual APIs this provider publishes, each with its own machine-readable definition.
ControlUp MCP Server
Official Model Context Protocol server published by ControlUp as the npm package @controlup-ai/mcp. Runs locally over stdio via npx, authenticates with a ControlUp API key plus ...
ControlUp Alerts API
Alerts let you receive notifications or automatically run an action when certain conditions occur on a device.
ControlUp Alerts - Devices API
The Alerts - Devices API from ControlUp — 2 operation(s) for alerts - devices.
ControlUp Applications API
Applications usage reports
ControlUp Audit Log API
The Audit Log API from ControlUp — 1 operation(s) for audit log.
ControlUp Cloud providers API
The Cloud providers API from ControlUp — 3 operation(s) for cloud providers.
ControlUp Dal API
The DAL (data access layer) is an advanced way to get data from an index.
ControlUp Data API
These endpoints are for interacting with the raw data stored in data indices.
ControlUp Devices API
Get information about devices.
ControlUp Dynamic Query API API
Dynamic SQL transformation and execution
ControlUp Events API
The System Events log reports important events and alerts in your ControlUp for Desktops environment.
ControlUp Features API
The Features API from ControlUp — 2 operation(s) for features.
ControlUp Health API
The Health API from ControlUp — 3 operation(s) for health.
ControlUp Hives API
Hives are the locations from which Scouts (tests) are initiated. Custom Hives allow you to test internal resources from within your network. They must be installed on a computer...
ControlUp Host API
Host usage reports
ControlUp Host pool cost API
The Host pool cost API from ControlUp — 4 operation(s) for host pool cost.
ControlUp Host pool deployments API
The Host pool deployments API from ControlUp — 1 operation(s) for host pool deployments.
ControlUp Host pool scaling policies API
The Host pool scaling policies API from ControlUp — 2 operation(s) for host pool scaling policies.
ControlUp Host pool session host deployments API
The Host pool session host deployments API from ControlUp — 1 operation(s) for host pool session host deployments.
ControlUp Host pool session hosts API
The Host pool session hosts API from ControlUp — 1 operation(s) for host pool session hosts.
ControlUp Host pool user sessions API
The Host pool user sessions API from ControlUp — 1 operation(s) for host pool user sessions.
ControlUp Host pool VM settings API
The Host pool VM settings API from ControlUp — 2 operation(s) for host pool vm settings.
ControlUp Host pools API
The Host pools API from ControlUp — 6 operation(s) for host pools.
ControlUp Integrations API
The Integrations API from ControlUp — 1 operation(s) for integrations.
ControlUp Invitations API
The Invitations API from ControlUp — 1 operation(s) for invitations.
ControlUp IP Allowlist API
The IP Allowlist API from ControlUp — 2 operation(s) for ip allowlist.
ControlUp Jobs API
The Jobs API from ControlUp — 8 operation(s) for jobs.
ControlUp License API
The License API from ControlUp — 1 operation(s) for license.
ControlUp License Usage API
The License Usage API from ControlUp — 1 operation(s) for license usage.
ControlUp Machine API
Machine usage reports
ControlUp Machines API
Endpoints to manage and query machines
ControlUp Master images API
The Master images API from ControlUp — 20 operation(s) for master images.
ControlUp Metrics API
Endpoints to manage and query metrics
ControlUp MF As API
Multi-factor authentication (MFA) is supported for gateway access on all EUC platforms except Citrix Storefront. Use this resource to retrieve the sets of usernames and phone nu...
ControlUp Net Scaler API
Netscaler usage reports
ControlUp Onboarding API
The Onboarding API from ControlUp — 5 operation(s) for onboarding.
ControlUp Organization Settings API
The Organization Settings API from ControlUp — 1 operation(s) for organization settings.
ControlUp Organizations API
The Organizations API from ControlUp — 2 operation(s) for organizations.
ControlUp Overview API
The Overview API from ControlUp — 11 operation(s) for overview.
ControlUp Processes API
Process usage reports
ControlUp Public API API
The Public API API from ControlUp — 11 operation(s) for public api.
ControlUp Roles API
The Roles API from ControlUp — 2 operation(s) for roles.
ControlUp SAML API
The SAML API from ControlUp — 2 operation(s) for saml.
ControlUp Scaling profiles API
The Scaling profiles API from ControlUp — 3 operation(s) for scaling profiles.
ControlUp Scouts API
Scouts are the proactive tests that you configure to monitor the availability and health of various resources. There are different types of Scouts, depending on the type of reso...
ControlUp Scripts API
The Scripts API from ControlUp — 1 operation(s) for scripts.
ControlUp Session API
Session statistics report
ControlUp Session hosts API
The Session hosts API from ControlUp — 2 operation(s) for session hosts.
ControlUp SSO Groups API
The SSO Groups API from ControlUp — 2 operation(s) for sso groups.
ControlUp Subscriptions API
The Subscriptions API from ControlUp — 27 operation(s) for subscriptions.
ControlUp Support endpoint API
Provides an additional information about customer's data
ControlUp Surveys API
These endpoints are for interacting with Employee Sentiment surveys.
ControlUp Tags API
The Tags API from ControlUp — 2 operation(s) for tags.
ControlUp Tenants API
The Tenants API from ControlUp — 23 operation(s) for tenants.
ControlUp Tests API
The output of the scout tests
ControlUp Triggers API
The Triggers API from ControlUp — 2 operation(s) for triggers.
ControlUp Trigger Schedules API
The TriggerSchedules API from ControlUp — 2 operation(s) for triggerschedules.
ControlUp User API
User activity reports
ControlUp User sessions API
The User sessions API from ControlUp — 1 operation(s) for user sessions.
ControlUp Users API
The Users API from ControlUp — 4 operation(s) for users.
ControlUp Windows Events API
Windows Event Log Monitoring history
Scroll within the panel for all 61 ·
Open Collections 61
Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
API Collection
OPEN COLLECTIONControlup Alerts API
OPEN COLLECTIONDex Alerts Alerts - Devices API
OPEN COLLECTIONVDI & DAAS Applications API
OPEN COLLECTIONDex Audit Log API
OPEN COLLECTIONDaaS IQ Cloud providers API
OPEN COLLECTIONControlUp for Desktops Dal API
OPEN COLLECTIONControlUp for Desktops Data API
OPEN COLLECTIONControlup Devices API
OPEN COLLECTIONVDI & DAAS Dynamic Query API API
OPEN COLLECTIONControlup Events API
OPEN COLLECTIONDaaS IQ Features API
OPEN COLLECTIONDaaS IQ Health API
OPEN COLLECTIONSynthetic Monitoring Hives API
OPEN COLLECTIONVDI & DAAS Host API
OPEN COLLECTIONDaaS IQ Host pool cost API
OPEN COLLECTIONDaaS IQ Host pool deployments API
OPEN COLLECTIONDaaS IQ Host pool scaling policies API
OPEN COLLECTIONDaaS IQ Host pool session host deployments API
OPEN COLLECTIONDaaS IQ Host pool session hosts API
OPEN COLLECTIONDaaS IQ Host pool user sessions API
OPEN COLLECTIONDaaS IQ Host pool VM settings API
OPEN COLLECTIONDaaS IQ Host pools API
OPEN COLLECTIONSynthetic Monitoring Integrations API
OPEN COLLECTIONDex Invitations API
OPEN COLLECTIONDex IP Allowlist API
OPEN COLLECTIONDaaS IQ Jobs API
OPEN COLLECTIONDaaS IQ License API
OPEN COLLECTIONDex License Usage API
OPEN COLLECTIONVDI & DAAS Machine API
OPEN COLLECTIONVDI & DaaS Configuration Machines API
OPEN COLLECTIONDaaS IQ Master images API
OPEN COLLECTIONVDI & DaaS Realtime Metrics API
OPEN COLLECTIONSynthetic Monitoring MF As API
OPEN COLLECTIONVDI & DAAS Net Scaler API
OPEN COLLECTIONDaaS IQ Onboarding API
OPEN COLLECTIONDex Organization Settings API
OPEN COLLECTIONDex Organizations API
OPEN COLLECTIONDaaS IQ Overview API
OPEN COLLECTIONVDI & DAAS Processes API
OPEN COLLECTIONFlow3 Public Public API API
OPEN COLLECTIONDex Roles API
OPEN COLLECTIONDex SAML API
OPEN COLLECTIONDaaS IQ Scaling profiles API
OPEN COLLECTIONSynthetic Monitoring Scouts API
OPEN COLLECTIONControlUp for Desktops Scripts API
OPEN COLLECTIONVDI & DAAS Session API
OPEN COLLECTIONDaaS IQ Session hosts API
OPEN COLLECTIONDex SSO Groups API
OPEN COLLECTIONDaaS IQ Subscriptions API
OPEN COLLECTIONVDI & DAAS Support endpoint API
OPEN COLLECTIONControlUp for Desktops Surveys API
OPEN COLLECTIONDex Tags API
OPEN COLLECTIONDaaS IQ Tenants API
OPEN COLLECTIONSynthetic Monitoring Tests API
OPEN COLLECTIONVDI & DaaS Configuration Triggers API
OPEN COLLECTIONVDI & DaaS Configuration Trigger Schedules API
OPEN COLLECTIONVDI & DAAS User API
OPEN COLLECTIONDaaS IQ User sessions API
OPEN COLLECTIONControlup Users API
OPEN COLLECTIONVDI & DAAS Windows Events API
OPEN COLLECTIONScroll within the panel for all 61 ·
MCP Servers 1
Model Context Protocol servers expose these APIs directly to AI agents. We profile them because agent-native access is the fastest-growing way this provider's capabilities actually get used.
Model Context Protocol servers that expose these APIs to AI agents.
controlup-mcp.yml
MCP SERVERRate Limits 1
Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.
Documented rate limits and quota policies.
Controlup Rate Limits
RATE LIMITSEvent Specifications 1
Not every API is request/response. AsyncAPI describes the event-driven and streaming side — the webhooks and channels — so the asynchronous half of the interface is documented the same way the synchronous half is.
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Controlup Webhooks
ASYNCAPISecurity Posture 4
Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Controlup Trust Center
ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, ISO/IEC 27701:2019, SOC 2 Type 2, SOC 3, FIPS 140-2 Level 1, CSA STAR Level 1, GDPR
SECURITYResources
Every other property we hold for ControlUp — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Get Started 4
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 4
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 6
Pagination, idempotency, versioning, errors, and events
Build 5
SDKs, sample code, and the tooling you integrate with
Access & Security 7
Authentication, authorization, and security posture
Scroll within the panel for all 7 ·
Operate 7
Status, limits, changes, and where to get help
Scroll within the panel for all 7 ·
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 13
Properties that don't map to a standard resource type
Scroll within the panel for all 13 ·
← All providers · Data indexed from github.com/api-evangelist/controlup · machine-readable index on apis.io
This is an independent, third-party profile of ControlUp, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.