Security APIs for AI agents

Reference guides for the security apps an AI agent can work with: every endpoint, the permission each one needs, and how to give agents safe, governed access.

1Password

15 endpoints

The 1Password API is how an app or AI agent works with a team's vaults: listing the vaults it can reach, reading and creating items such as logins and API credentials, updating or deleting them, and downloading files attached to an item.

Updated 23 June 2026 · API v1
View full guide

Auth0

28 endpoints

The Auth0 API is how an app or AI agent administers an Auth0 tenant: listing and creating users, assigning roles, registering applications and connections, and searching tenant logs.

Updated 23 June 2026 · API v2
View full guide

Clerk

35 endpoints

The Clerk API is how an app or AI agent manages an application's accounts from a server: listing and creating users, banning or deleting one, building organizations and their memberships, and revoking live sessions.

Updated 23 June 2026 · API 2026-05-12
View full guide

CrowdStrike

33 endpoints

The CrowdStrike API is how an app or AI agent works with a Falcon tenant: searching alerts, reading host details and containing a compromised machine, managing custom indicators, and running commands on a live endpoint.

Updated 23 June 2026 · API v1
View full guide

Duo

47 endpoints

The Duo API is how an app or AI agent manages a Cisco Duo account: listing and editing users, enrolling phones and hardware tokens, generating bypass codes, managing administrators and the applications Duo protects, and reading authentication and administrator logs.

Updated 23 June 2026 · API v1
View full guide

JumpCloud

33 endpoints

The JumpCloud API is how an app or AI agent works with a company's directory: listing and updating enrolled devices, creating and deleting users, adding people to groups, and reading a record of who signed in to what.

Updated 23 June 2026 · API v1
View full guide

Microsoft Entra ID

31 endpoints

The Microsoft Entra ID API is how an app or AI agent works with an organization's directory: listing and creating users, adding and removing group members, registering applications, reading the sign-in logs, and assigning directory roles.

Updated 23 June 2026 · API v1.0
View full guide

Okta

33 endpoints

The Okta API is how an app or AI agent works with an Okta org: listing and creating users, adding people to groups, assigning applications, reading the system log, and deactivating an account when someone leaves.

Updated 23 June 2026 · API v1
View full guide

Stytch

29 endpoints

The Stytch API is how an app or AI agent adds login to a product: sending a magic link or one-time passcode, checking a password, creating and looking up users, and validating or revoking their sessions.

Updated 23 June 2026 · API v1
View full guide

WorkOS

36 endpoints

The WorkOS API is how an app or AI agent works with a WorkOS environment: creating and reading users and organizations, authenticating people through single sign-on and magic codes, listing the users and groups in a synced directory, and recording audit events.

Updated 23 June 2026 · API Current
View full guide
Orientation

About security APIs for AI agents

A security API is how an app or AI agent works with identity, login, and access management. The platforms here, including Okta, Auth0, 1Password, and Microsoft Entra ID, hold users, credentials, and the rules that govern access, and their APIs let an agent read a user, provision or deactivate an account, or check a login.

These systems control who can reach everything else, so an access token here can be far-reaching, and provisioning or deactivating accounts changes who has access. Access runs on an access token, scoped to particular actions like reading users or managing accounts. A governed layer lets an agent that reviews accounts read users without being able to create or remove them.

Frequently asked questions

Which identity and security APIs can an AI agent use?+
The Atlas covers Okta, Auth0, Microsoft Entra ID, 1Password, Clerk, Stytch, WorkOS, JumpCloud, Duo, and CrowdStrike. Their APIs handle users, authentication, and access management.
Can an AI agent create or deactivate a user account?+
Yes, with a write permission. Platforms like Okta and Entra ID expose endpoints to provision and deactivate users, which is how an agent can onboard or offboard an account.
Can a security agent be limited to reading users only?+
Yes. Reading users and managing them are separate permissions, so an agent can review accounts and logs without being able to change them.
Can an AI agent read sign-in or audit logs?+
Yes, with a read permission. These platforms expose log endpoints that return sign-ins and changes, which an agent can pull to review activity.
What is Bollard AI?

Control what every AI agent can do.

Bollard AI sits between a team's AI agents and the apps it runs on. Grant each agent exactly the access it needs, read or write, app by app, and every call is checked and logged.