How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC


Newsletter

Weekly highlights of stories, conversations, and API knowledge delivered Monday mornings.

Join the conversation on Commune

Read past issues →

Discover APIs
apis.io — API Search

Search across thousands of APIs on apis.io

Where This Data Comes From

The short version. Every company profile, API listing, and rating published by API Evangelist and APIs.io is built from publicly available information — material the company itself published on the open web, plus the specifications it distributes for public use.

Nothing here is obtained by breaching a system, defeating an access control, or using credentials. If a listing concerns you, email [email protected] and a human will answer.

Who publishes this

API Evangelist is an independent API surveying and assessment practice, operated by Kin Lane. APIs.io is its public discovery catalog. Neither is affiliated with, endorsed by, or a partner of the companies profiled, unless a partnership is stated explicitly on the page. We do not operate, host, resell, or support any of the APIs we profile.

What we collect, and from where

Profiles are assembled from sources a member of the public can reach with a browser and no credentials:

  • The company's own public website, developer portal, and documentation.
  • Machine-readable specifications the company publishes for public consumption — OpenAPI, AsyncAPI, JSON Schema, Postman collections, apis.json, llms.txt, and similar.
  • Public code repositories and package registries the company maintains.
  • Public status pages, changelogs, pricing pages, blogs, and press material.
  • Public registry and standards-body membership records.

Collection is automated. Crawlers identify themselves, respect robots.txt, and fetch at a deliberately low rate. Analysis and scoring are performed by software; editorial review and every reply you receive are performed by a person.

What we never collect

  • Anything behind a login, paywall, licence gate, or access control.
  • Anything requiring an API key, token, or credential — including our own accounts with a provider.
  • Customer data, traffic, personal data, or internal documents.
  • Anything obtained by circumventing a technical restriction, or from a breach or leak.

"But we never made that public"

This is the most common question a security team asks, and it is a fair one. An API can be publicly reachable without anyone having decided to publish it. Interfaces behind a mobile app, a single-page web app, or an embedded widget are served over the public internet, and their endpoints are visible to anyone who inspects ordinary network traffic from the application. A specification file left in a public repository or on a public host is readable by anyone who requests it, indexed or not.

API Evangelist indexes what is reachable this way because your customers' security teams, your competitors, and automated crawlers are already seeing it. Publishing what is discoverable is intended to close that gap, not widen it. If a listing has surfaced something your organization did not intend to expose, that is worth knowing, and we will help.

About the ratings

The Kin Score and Agent Readiness ratings are independently calculated assessments of the public API surface of an organization, produced by API Evangelist against a published rubric. They are not certifications, endorsements, security assessments, or audits, and they carry no contractual weight. They score the artifacts an organization publishes — not the quality, safety, or security of its software.

A rating reflects what was publicly available when it was calculated. Publish more, and the rating changes. Any organization may submit a correction or request a re-score at no charge.

Corrections, re-scores, and removal

Every one of these is free, and none requires a partnership, a contract, or a purchase.

  • Correct a fact — tell us what is wrong and we will fix it.
  • Re-score — if you have published new artifacts, ask and we will re-run the rating.
  • Restrict a listing — we reduce the page to your company name, a factual description, and a link to your own site. Listings, specifications, artifacts, developer-surface links, and the rating are deleted, and the company is recorded as unrated. It is never scored zero for having asked.

Requests are honored on request. We do not require a legal demand, and we do not ask you to justify the request.

How fast we respond

API Evangelist is a one-person practice. Inbound requests across email, GitHub issues, and social channels are swept and triaged daily.

  • Acknowledgement — within one business day.
  • Removal or restriction of a listing — within two business days of the request, with confirmation once it is done.
  • Corrections and re-scores — within five business days.

Cached and third-party copies (search engines, AI crawlers, archives) are outside our control and may persist after we have removed a page.

If you are on a security or compliance team

You are welcome to contact us directly, and you will get a person rather than a form. We will tell you exactly which URLs a profile was built from, so your team can see the same public surface we did, and we will remove the listing on request while you work through it.

If what you have found is an exposure you did not know about, we are glad to help you understand the public footprint — and where it goes beyond what we do, we can refer you to independent API security specialists. Referrals may be commercial relationships, and we will say so at the time.

Contact: [email protected] — put listing, removal, or security in the subject line and it is routed to the top of the queue.

Names, marks, and copyright

Company names, product names, and logos are the property of their respective owners and are used here for identification in the course of independent commentary, research, and comparison. Descriptions are factual summaries. Specifications are linked or reproduced only where the publisher has released them for public use, and are attributed to the publisher.