SmallStep Protect API declares
2 security schemes
for authenticating requests.
It accepts HTTP bearer tokens (JWT).
It requires mutual TLS (mtls).
By default, every request must be authenticated.
mtls — Use a client certificate issued by a trusted root to get short-lived bearer tokens with the step CLI.
Paths & Operations 43
Across 17 paths, the API surfaces 43 operations — 9 DELETE, 17 GET, 8 POST, 9 PUT. Each is listed below with its method, path, parameters, and response codes.
The contract defines 36 schemas that model the data the API accepts and returns. The most detailed are x509Fields (15 properties), endpointCertificateInfo (10 properties), managedRadius (10 properties), endpointConfigurationRequest (9 properties). Each schema is shown below with its type and property counts.
endpointConfiguration
An endpoint configuration represents the details for issuing a certificate a device uses to connect to a protected resource.
policyMatchCriteria
object
Policy to select the devices an account is assigned to. An empty policy indicates an account will be provisioned for all devices.
5 properties
certificateFieldList
object
A certificate field that accepts multiple string values, e.g. SANs.
3 properties
endpointKeyInfo
object
The attributes of the cryptographic key.
4 properties
wifi
object
Configuration to use a credential to connect to a protected Wi-Fi network.
8 properties4 required
x509CustomExtension
object
An arbitrary X.509 certificate extension.
3 properties2 required
deviceAssurance
string
The assurance level of the device. High-assurance devices are those that have a user binding, have been approved, and have performed cryptographic remote attes…
idpClient
object
4 properties2 required
vpn
Configuration to use a credential to connect a device to a VPN.
x509Fields
object
Populate certificate fields using using static names or device metadata.
15 properties
ethernet
object
Configuration for connecting a device to an EAP-TLS 802.1X wired network.
5 properties3 required
vpnAccount
object
Configuration to connect a device to a VPN.
5 properties2 required
wifiAccount
object
Configuration to connect a device to a protected WiFi network.
7 properties1 required
deviceOS
string
The device operating system. This field may be populated with a value derived from data synced from your team's MDMs. Setting this value explicitly will mask a…
endpointConfigurationRequest
object
The configuration settings of an endpoint.
9 properties2 required
deviceOwnership
string
Whether the device is owned by the user or the company. This field may be populated with a value derived from data synced from your team's MDMs. Setting this v…
replyAttribute
browser
object
Configuration to use a credential for browser mTLS.
4 properties3 required
endpointReloadInfo
object
The properties used to reload a service.
4 properties1 required
endpointManagementMode
string
Determines who manages the certificate lifecycle for the workload. Defaults to agent if not set. - agent: The Smallstep Agent manages the certificate lifecycle…
identityProvider
object
5 properties5 required
browserAccount
object
Configuration to use a client certificate.
accountRequest
object
The configuration settings of an account.
7 properties1 required
error
object
1 property1 required
ikeV2Config
object
Configuration for VPNs that use the IKEv2 protocol.
3 properties1 required
vpnType
string
The type of VPN connection.
x509TypedSANs
object
Explicitly typed subject alternative names. When set, takes precedence over the untyped sans field.
5 properties
x509ExtendedKeyUsage
string
A purpose for which a certified public key may be used.
endpointCertificateInfo
object
Details on a managed certificate.
10 properties1 required
vpnVendor
string
For SSL-type VPN connections, the vendor of the VPN.
managedRadius
object
10 properties8 required
certificateField
object
A certificate field that takes a single string value, e.g. Common Name. Static values are used as a fallback when device metadata is not present.
2 properties
account
An account configures the certificate a device uses to connect to a protected resource.
deviceDiscoverySource
string
The source from which this device was discovered.
ethernetAccount
object
Configuration to connect a device to a protected LAN.
4 properties
sshFields
object
Populate certificate fields using static names or device metadata.
2 properties
Specification
The full machine-readable OpenAPI contract behind this narrative.
Every API here is available over the API and to AI agents over MCP. APIs is not yet its own endpoint on the v1 API. Reach this content through network search and the tag graph, or the MCP server below.
Installs https://mcp.apievangelist.com/mcp in Claude, Cursor, VS Code and the rest — one button, every client.
MCP tools for apis
4 tools reach this content
search_api_evangelistSearch every content type across the network at once.
find_relatedThe shared-tag relevance graph — what else covers this.
get_tagEverything one tag labels, across all content types.
guide_topicPRO — a curated bundle for a topic: area, guidance, rules, papers, stories, services.
A second provider on the same verified email joins the account you already have.
Your account
ⓘWhere this information came from
This is an independent, third-party profile of SmallStep Protect API, published by
API Evangelist. We do not operate, host, resell, or
support these APIs, and we are not affiliated with or endorsed by the company unless stated above.
Everything here is built from publicly available information — the company's own site,
developer portal, documentation, public repositories, and the specifications it publishes for public use.
Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's
public API artifacts, scored against a published rubric. They are not certifications,
endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and
you do not need to justify the request. A removed company is recorded as unrated, never scored
zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy → On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.