# Kolide (1Password Device Trust) > Kolide is a device trust and endpoint security platform, now part of 1Password Extended > Access Management. It blocks non-compliant devices from authenticating into corporate > apps (Zero Trust access for Okta, Google and Entra), runs continuous security and > compliance checks across Linux, macOS, Windows, iOS and Android, and maintains a > fleet-wide device inventory. Its distinguishing philosophy is user-first remediation: > rather than silently blocking, it educates the end user and guides self-remediation. The public developer surface is the **K2 API** at `https://api.kolide.com`, a REST API with 65 operations across 52 paths, published as OpenAPI 3.0 on two dated version lines. ## Authentication - Bearer API key: `Authorization: Bearer $KOLIDE_API_TOKEN` - Token format `$PREFIX_$VERSION_$SECRET`, prefix `k2sk` (e.g. `k2sk_v1_...`) - Created by an admin at Settings > Developers > API Keys - Read access on all plans; **write permissions are Kolide Max only**, granted explicitly per key with a documented rationale - No OAuth 2.0, no OpenID Connect, no scopes ## Versioning - Optional header `X-Kolide-Api-Version`; omitting it floats to latest - Current line `2026-04-07`; also supported `2023-05-26` - Breaking changes ship as a new dated line rather than mutating an existing one ## Conventions - Cursor pagination: `per_page` (default 25, max 100); response `pagination` object with `next`, `next_cursor`, `current_cursor`, `count` - Search via a `query` parameter, ``, operators `:` exact, `~` substring, `>` / `<` datetime, combined with `AND` / `OR` - Rate limit 270 requests/minute; 429 with `Retry-After`, `RateLimit-Limit`, `Ratelimit-Remaining`, `Ratelimit-Reset` (draft-polli-ratelimit-headers-02) - Errors are `application/json`; only 401 and 403 are declared in the spec. No RFC 9457 problem+json, no error-code registry - **No idempotency keys** are supported ## Resource surface Devices, device groups, people, person groups, deprovisioned people, issues, checks and check results, check configurations, custom check drafts, live query (osquery) campaigns and results, exemption requests, registration requests, software packages, admin users, audit logs, auth log sessions, and reporting tables/queries. ## Events Two real event surfaces; **no AsyncAPI document is published**. - **Webhooks** — HMAC-SHA256 hex digest of the body in the `Authorization` header, plus `X-Kolide-Webhook-Identifier`. Sent from AWS us-east-1 with no reserved IPs. Delivery logs retained 6 months. Events: `audit_log.recorded`, `admin_users.created`, `auth_logs.success`, `auth_logs.failure`, `devices.created`, `devices.registered`, `devices.destroyed`, `device_trust.status_changed`, `issues.new`, `issues.resolved`, `requests.issue_exemption`, `requests.registration`. - **SSF streams** — OpenID Shared Signals Framework 1.0 with the CAEP profile. Discovery at `https://api.kolide.com/.well-known/ssf-configuration`. Emits `https://schemas.openid.net/secevent/caep/event-type/device-compliance-change`. Push (RFC 8935) and poll (RFC 8936) delivery. ## MCP Kolide ships a first-party MCP server, run locally (stdio or HTTP on `http://127.0.0.1:8000/mcp`), exposing ~55 tools over the K2 API plus three documentation resources. It is installed from source; it is not published to PyPI. ## Docs - Developer docs: https://www.kolide.com/docs/developers - API overview: https://www.kolide.com/docs/developers/api - API reference: https://kolideapi.readme.io/reference - OpenAPI 2026-04-07: https://www.kolide.com/docs/openapi/2026-04-07 - OpenAPI 2023-05-26: https://www.kolide.com/docs/openapi/2023-05-26 - Webhooks: https://www.kolide.com/docs/developers/webhooks - SSF streams: https://www.kolide.com/docs/developers/ssf-streams - MCP server: https://www.kolide.com/docs/developers/kolide-mcp-server - API changelog: https://www.kolide.com/docs/developers/changelog - Use cases: https://www.kolide.com/docs/developers/usecases - Product docs: https://www.kolide.com/docs - Support: https://www.kolide.com/docs/about-kolide/support - Blog: https://www.kolide.com/blog - Pricing: https://www.kolide.com/pricing - Security: https://www.kolide.com/security - Status: https://status.1password.com - GitHub: https://github.com/kolide ## Optional - Agent (open source): https://github.com/kolide/launcher - MCP server source: https://github.com/kolide/device-trust-mcp-server - Terms: https://www.kolide.com/legal/terms — API/SDK terms: https://1password.com/legal/api-sdk-terms-of-service - Privacy: https://www.kolide.com/legal/privacy - SOC 2: https://www.kolide.com/legal/soc2 — GDPR: https://www.kolide.com/legal/gdpr --- generated: 2026-07-19 method: generated source: apis.yml + repo artifacts (kolide.com/llms.txt returns 404)