Rapid7
Rapid7 is a cybersecurity company providing the Insight Platform with products for vulnerability management (InsightVM), SIEM/XDR (InsightIDR), application security (InsightAppSec), cloud security (InsightCloudSec), and SOAR (InsightConnect). The Rapid7 Command/Insight Platform API exposes REST endpoints across regional hosts such as us.api.insight.rapid7.com for managing assets, vulnerabilities, investigations, and integrations. Authentication is performed with an organization or user API key passed in the `X-Api-Key` header.
Real signal across most facets with visible, nameable gaps — the contract exists but is thin, or the portal is good while governance and commercial terms are absent.
API Evangelist profiles Rapid7 the way a machine reads it — 273 machine-readable artifacts across 50 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Rapid7 scores 49.3/100 (developing), with a separate agent-readiness read of 60/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.
How we profile Rapid7
Each block below is one kind of artifact we hold for Rapid7. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
APIs 50
Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.
Individual APIs this provider publishes, each with its own machine-readable definition.
Rapid7 InsightVM Cloud API
REST API for the InsightVM vulnerability management product, exposing assets, scans, vulnerabilities, remediation projects, and reports. Authentication uses an Insight Platform ...
Rapid7 Insight Platform API
Cross-product REST API for the Insight Platform that covers user and key management, organizations, audit logs, and platform-level integrations. Authentication uses `X-Api-Key` ...
Rapid7 InsightIDR API
REST API for the InsightIDR SIEM/XDR product covering investigations, alerts, log search, threats, and SOC workflows. Authentication uses `X-Api-Key` against the regional Insigh...
Rapid7 Accounts API
An API used to find and search InsightIDR accounts. See https://docs.rapid7.com/insightidr/users-and-accounts-on-your-domain for further information on accounts.
Rapid7 Administration API
Provides access administrative operations and procedures.
Rapid7 Apps API
An App owns Scan Configs, Schedules, Scans and Vulnerabilities; you must create an App in order to create any of these other resources. Consequently, if an App is deleted...
Rapid7 Asset API
Resources and operations for managing assets. Assets can be created under the Site Assets resource.
Rapid7 Asset Discovery API
Resources for managing and viewing the mechanisms used to automatically discover assets.
Rapid7 Asset Group API
Resources and operations for managing asset groups.
Rapid7 Assets API
An API used to find and search InsightIDR assets. See https://docs.rapid7.com/insightidr/assets-on-your-domain for further information on assets.
Rapid7 Attachments API
An API used to upload, list, download and delete attachments. For example, the create API can be used to upload an attachment.
Rapid7 Attack Templates API
An Attack Template describes if and how Attacks should be executed during the execution of a Scan. There exist pre-defined, system-provided and immutable templates...
Rapid7 Blackouts API
A blackout is a period of time when all scanning activities for the specified scope are blocked. A blackout can be scoped globally or to a specific App, this is implied by the <...
Rapid7 Collectors API
An API used to manage collectors for an organization.
Rapid7 Comments API
An API used to find, create, and delete comments. For example, these APIs can be used to create a comment for a particular investigation.
Rapid7 Community Threats API
An API used to add and replace indicators for Community Threats. See https://insightidr.help.rapid7.com/docs/threats#section-threat-api for further information on how to generat...
Rapid7 Credential API
Resources and operations for managing shared credentials.
Rapid7 Engine Groups API
An Engine Group is a resource which defines a container for a logical grouping of Engines and therefore the purpose of assigning Scans to one of those Engines. Any created Engin...
Rapid7 Engines API
An Engine encapsulates the state and high-level attributes of the components which may be installed and running on a specific On-Premise host. The status of an Engine is not mut...
Rapid7 Files API
Files are used primarily to manage content that can be required to successfully scan an App. For example, many supported methods of configuring authentication in a Scan Config r...
Rapid7 Health Metrics API
An API used to retrieve health metrics of an organization.
Rapid7 Investigations API
The Investigations API from Rapid7 — 4 operation(s) for investigations.
Rapid7 Local Accounts API
An API used to find and search InsightIDR local accounts. See https://docs.rapid7.com/insightidr/users-and-accounts-on-your-domain for further information on local accounts.
Rapid7 Policy API
Resources and operations for managing policies.
Rapid7 Policy Override API
Policy Override Resource Controller
Rapid7 Remediation API
Resources for determining the details required to remediate vulnerabilities.
Rapid7 Report API
Resources and operations for managing and generating reports. Reports are broadly categorized into `document`, `export`, and `file` types. `document` reports use section-based r...
Rapid7 Reports API
Reports provide the ability to share information with stakeholders at both scan and app levels. The following table lists the report templates and the various formats that are a...
Rapid7 Root API
Provides access to primary entry point for discovering the available resources in this API.
Rapid7 Scan API
Resources and operations for managing scans.
Rapid7 Scan Configs API
A Scan Config defines all the necessary information required to perform a Scan of an App. An App must be created prior to creating a Scan Config. It is the main document ...
Rapid7 Scan Engine API
Resources and operations for managing scan engines.
Rapid7 Scan Template API
Scan Template Resource Controller
Rapid7 Scans API
A Scan encapsulates all the information for a single execution of the criteria defined in the provided Scan Config. An App and a Scan Config must be created prior to subm...
Rapid7 Schedules API
A Schedule defines the automated execution of a Scan, using a specified Scan Config. Both the App and Scan Config must be created prior to creating a Schedule. There are two opt...
Rapid7 Search API
A global Search API is exposed to facilitate the execution of user-defined queries that can perform a Search across the supported resource types exposed via the API. Each Search...
Rapid7 Site API
Resources and operations for managing sites.
Rapid7 Tag API
Resources and operations for managing tags.
Rapid7 Tags API
Tags are customer-defined labels that can be used for a variety of purposes. The management of Tags is performed by this API, and other APIs facilitate applying these Tags to ot...
Rapid7 Targets API
A Target essentially specifies an allowlisted Fully Qualified Domain Name (FQDN) which can be Scanned by InsightAppSec. A Target can be created, edited and deleted by an API con...
Rapid7 User API
Resources and operations for managing users, permissions, and privileges.
Rapid7 Users API
An API used to find and search InsightIDR users. See https://docs.rapid7.com/insightidr/users-and-accounts-on-your-domain for further information on users.
Rapid7 Variances Documentation API
The Variances Documentation API from Rapid7 — 2 operation(s) for variances documentation.
Rapid7 Vulnerabilities API
A Vulnerability is a resource that encapsulates any information found by any Scan over the lifetime of an App, that may identify where and how an App could be exploited. ...
Rapid7 Vulnerability API
Resources and operations for viewing vulnerability content and managing exceptions.
Rapid7 Vulnerability Check API
Resources and operations for view vulnerability checks that can be run as a part of vulnerability content.
Rapid7 Vulnerability Comments API
A Vulnerability Comment is a resource that allows users to add context to the Vulnerability.
Rapid7 Vulnerability Exception API
Vulnerability Exception Resource Controller
Rapid7 Vulnerability History API
A Vulnerability History resource represents the change applied to a specific Vulnerability at a point of time in its existence.
Rapid7 Vulnerability Result API
Resources and operations for retrieving vulnerability results on assessed assets.
Scroll within the panel for all 50 ·
Open Collections 3
Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
MCP Servers 1
Model Context Protocol servers expose these APIs directly to AI agents. We profile them because agent-native access is the fastest-growing way this provider's capabilities actually get used.
Model Context Protocol servers that expose these APIs to AI agents.
MCP Server
MCP SERVERGraphQL 1
Where a provider ships GraphQL, the schema is the contract. We profile it alongside the REST surface so the whole interface is legible in one place.
GraphQL schemas published by this provider.
Rapid7 GraphQL Schema
This conceptual GraphQL schema represents the Rapid7 Insight Platform API surface, covering InsightVM (vulnerability management), InsightIDR (SIEM/XDR), and InsightConnect (SOAR...
GRAPHQLPricing Plans 1
Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.
Published pricing tiers and plan structures.
Rapid7 Plans Pricing
PLANSRate Limits 1
Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.
Documented rate limits and quota policies.
Rapid7 Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.
Cost, billing, and metering signals for API financial operations.
Rapid7 Finops
FINOPSSpectral Rules 1
Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.
Rapid7 API Rules
SPECTRALJSON Schema 205
Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.
Standalone JSON Schema definitions for this provider's data models.
AccountV2
JSON SCHEMAAddCollectorRequest
JSON SCHEMAAddCollectorResponse
JSON SCHEMAAlertInfo
JSON SCHEMAAlfDataFile
JSON SCHEMAapp
JSON SCHEMAAssetV2
JSON SCHEMAAssignee
JSON SCHEMAAssignUserToInvestigationRequest
JSON SCHEMAAttachment
JSON SCHEMAattack_template
JSON SCHEMAAttackDocumentation
JSON SCHEMAAttackerConfig
JSON SCHEMAAttackMetadata
JSON SCHEMAAttackModule
JSON SCHEMAAttackTemplate
JSON SCHEMAAuthConfig
JSON SCHEMAAutoSequenceConfig
JSON SCHEMABinaryContentType
JSON SCHEMABinaryExtension
JSON SCHEMABlackout
JSON SCHEMABrowserDoNotDownloadContentType
JSON SCHEMABrowserDoNotDownloadExtension
JSON SCHEMABrowserDownloadAllowlist
JSON SCHEMABrowserFormLoginConfig
JSON SCHEMABulkCloseInvestigationsRequest
JSON SCHEMAChatbotConfig
JSON SCHEMAChromeHostConfig
JSON SCHEMAClosedInvestigations
JSON SCHEMAComment
JSON SCHEMACommentCreateRequest
JSON SCHEMACrawlConfig
JSON SCHEMACrawlerInitializationConfig
JSON SCHEMACrawlerMonitoringConfig
JSON SCHEMACreator
JSON SCHEMACredentialResource
JSON SCHEMACustomHeaders
JSON SCHEMACustomParameterFile
JSON SCHEMADefaultDoNotAttackParam
JSON SCHEMADeleteThreatEvent
JSON SCHEMADenyListExtension
JSON SCHEMADomElementRestriction
JSON SCHEMADomRestrictions
JSON SCHEMAEngine
JSON SCHEMAEngine
JSON SCHEMAEngineAssignment
JSON SCHEMAEngineGroup
JSON SCHEMAEntityModelApp
JSON SCHEMAEntityModelAttackTemplate
JSON SCHEMAEntityModelBlackout
JSON SCHEMAEntityModelEngine
JSON SCHEMAEntityModelEngineGroup
JSON SCHEMAEntityModelFile
JSON SCHEMAEntityModelReport
JSON SCHEMAEntityModelScan
JSON SCHEMAEntityModelScanConfig
JSON SCHEMAEntityModelSchedule
JSON SCHEMAEntityModelTag
JSON SCHEMAEntityModelTarget
JSON SCHEMAEntityModelVulnerability
JSON SCHEMAEntityModelVulnerabilityComment
JSON SCHEMAEntityModelVulnerabilityDiscovery
JSON SCHEMAError
JSON SCHEMAErrorResponse
JSON SCHEMAErrorResponse1
JSON SCHEMAErrorResponse2
JSON SCHEMAErrorResponse3
JSON SCHEMAExchange
JSON SCHEMAFile
JSON SCHEMAFrameworkConfig
JSON SCHEMAFrameworksCrawlConfig
JSON SCHEMASchedule
JSON SCHEMAGlobalTokenReplacement
JSON SCHEMAGraphQlConfigObject
JSON SCHEMAGrayListExtension
JSON SCHEMAHmacConfig
JSON SCHEMAHtmlContentType
JSON SCHEMAHttpAuthExt
JSON SCHEMAHttpHeadersConfig
JSON SCHEMAHttpParameter
JSON SCHEMAIdResource
JSON SCHEMAInvestigation
JSON SCHEMALink
JSON SCHEMALocalAccountV2
JSON SCHEMALockedCookie
JSON SCHEMALogEvent
JSON SCHEMALuxorPageable
JSON SCHEMAMacroConfig
JSON SCHEMAMacroFile__1
JSON SCHEMAMacroFile
JSON SCHEMAManualCrawlingConfig
JSON SCHEMAManualSequenceConfig
JSON SCHEMAModuleConfig
JSON SCHEMAModuleMetadata
JSON SCHEMAMsalConfig
JSON SCHEMAMultiRegexUrlParserConfig
JSON SCHEMANetworkSettingsConfig
JSON SCHEMAOauthConfig
JSON SCHEMAOAuthCustomField
JSON SCHEMAOneTimePasswordConfig
JSON SCHEMAOneTimeTokenConfig
JSON SCHEMAPage
JSON SCHEMAPageAccountV2
JSON SCHEMAPageApp
JSON SCHEMAPageAssetV2
JSON SCHEMAPageAttachment
JSON SCHEMAPageAttackTemplate
JSON SCHEMAPageBlackout
JSON SCHEMAPageComment
JSON SCHEMAPageEngine
JSON SCHEMAPageEngineGroup
JSON SCHEMAPageFile
JSON SCHEMAPageInvestigation
JSON SCHEMAPageLocalAccountV2
JSON SCHEMAPageMetadata
JSON SCHEMAPageMetadata1
JSON SCHEMAPageMetadata2
JSON SCHEMAPageMetadata3
JSON SCHEMAPageObject
JSON SCHEMAPageReport
JSON SCHEMAPageScan
JSON SCHEMAPageScanConfig
JSON SCHEMAPageSchedule
JSON SCHEMAPageTag
JSON SCHEMAPageTarget
JSON SCHEMAPageUserV2
JSON SCHEMAPageVulnerability
JSON SCHEMAPageVulnerabilityComment
JSON SCHEMAPageVulnerabilityDiscovery
JSON SCHEMAParameterParserConfig
JSON SCHEMAParameterTrainingConfig
JSON SCHEMAParameterValue
JSON SCHEMAParameterValueConfig
JSON SCHEMAPerformanceConfig
JSON SCHEMAProxyConfig
JSON SCHEMAProxyExclusions
JSON SCHEMAReadOnlyIdResource
JSON SCHEMAReferenceResource
JSON SCHEMAReport
JSON SCHEMAReport Generation
JSON SCHEMARequiredIdResource
JSON SCHEMARootCause
JSON SCHEMARRN
JSON SCHEMARRN1
JSON SCHEMAscan_config
JSON SCHEMAScan
JSON SCHEMAScanConfig
JSON SCHEMAScanConfigOptions
JSON SCHEMAScanExecutionDetails
JSON SCHEMAScanModuleParameterFiles
JSON SCHEMAScanStateActionResource
JSON SCHEMAScanSubmitter
JSON SCHEMAScanVerificationResource
JSON SCHEMASchedule
JSON SCHEMAScopeConstraint
JSON SCHEMASearchRequest
JSON SCHEMASearchRequestCriteria
JSON SCHEMASearchRequestSort
JSON SCHEMASeedUrl
JSON SCHEMASeleniumConfig
JSON SCHEMASeleniumFile
JSON SCHEMASequenceConfig
JSON SCHEMASequenceIgnoreContentType
JSON SCHEMASequenceIgnoreExtension
JSON SCHEMASequenceRequest
JSON SCHEMASort
JSON SCHEMASpecializedScanParamsResource
JSON SCHEMASslCertConfig
JSON SCHEMAStandardUrlParserConfig
JSON SCHEMAStringReferenceResource
JSON SCHEMASwaggerFile
JSON SCHEMATag
JSON SCHEMATarget
JSON SCHEMATextContentType
JSON SCHEMATextExtension
JSON SCHEMAThreat
JSON SCHEMAThreatUpdateResult
JSON SCHEMATokenReplacement
JSON SCHEMATokenReplacementConfig
JSON SCHEMATrafficFile
JSON SCHEMATrafficHeader
JSON SCHEMATrainingParameter
JSON SCHEMAUploadAttachmentRequest
JSON SCHEMAUserDoNotAttackParam
JSON SCHEMAUserSummaryV2
JSON SCHEMAUserSummaryV21
JSON SCHEMAUserV2
JSON SCHEMAValidationError
JSON SCHEMAValidationErrors
JSON SCHEMAVariance
JSON SCHEMAVarianceDocumentation
JSON SCHEMAVarianceFilterRequest
JSON SCHEMAVulnerability
JSON SCHEMAVulnerabilityChange
JSON SCHEMAVulnerabilityComment
JSON SCHEMAVulnerabilityDiscovery
JSON SCHEMAVulnerabilityHistory
JSON SCHEMAVulnerabilityHistory
JSON SCHEMAVulnerabilityUpdateSource
JSON SCHEMAWebDriverConfig
JSON SCHEMAWebServiceAuthConfig
JSON SCHEMAWebServiceConfig
JSON SCHEMAWebServiceParameter
JSON SCHEMAWsdl
JSON SCHEMAXmlContentType
JSON SCHEMAScroll within the panel for all 205 ·
JSON Structure 1
JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.
JSON Structure definitions describing this provider's data shapes.
Rapid7 Structure
JSON STRUCTUREExamples 4
Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.
Example request and response payloads for these APIs.
Rapid7 Addindicators Example
EXAMPLERapid7 Getmetrics Example
EXAMPLESecurity Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.
Recommended x-agentic-access execution contracts for AI agents.
Resources
Every other property we hold for Rapid7 — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Get Started 1
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 2
MCP servers, agent skills, and machine-readable catalogs
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 3
Authentication, authorization, and security posture
Operate 3
Status, limits, changes, and where to get help
Commercial 1
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Other 1
Properties that don't map to a standard resource type
← All providers · Data indexed from github.com/api-evangelist/rapid7 · machine-readable index on apis.io