# Xage Security > Xage Security is a Palo Alto, California zero trust access and protection company. The Xage Fabric > Platform enforces identity-based access control across operational technology (OT), IT, cloud and > edge environments for critical infrastructure operators. Xage also markets a control layer that > governs how AI agents reach resources over MCP, A2A and REST APIs. This file was GENERATED by API Evangelist from the public Xage Security web surface on 2026-09-04. Xage does not publish an llms.txt of its own — https://xage.com/llms.txt returns HTTP 404. ## What is and is not publicly callable - Xage's product API — the Xage Fabric Manager REST API that third-party platforms integrate against — has NO public reference, NO published OpenAPI, and NO public base URL. Its host is the customer's own Fabric Manager (a hostname or IP the customer supplies). Documentation is published only inside the authenticated Xage support portal. - The one publicly reachable Xage API surface is a Model Context Protocol server mounted on the xage.com WordPress marketing site. It serves site content and WordPress abilities — NOT the Fabric Platform. It requires OAuth and returns 401 anonymously. ## Machine-readable surfaces - [MCP server](https://xage.com/wp-json/mcp/mcp-oauth-server): Streamable HTTP MCP endpoint, OAuth required, HTTP 401 anonymously. Website-content scope only. - [OAuth authorization server metadata](https://xage.com/.well-known/oauth-authorization-server): RFC 8414. Issuer https://xage.com, authorization_code + refresh_token, PKCE S256, scope `mcp`. - [OAuth protected resource metadata](https://xage.com/.well-known/oauth-protected-resource): RFC 9728. Names the MCP resource and its authorization server. - [MCP route index](https://xage.com/wp-json/mcp): public list of the two MCP servers mounted. - [Sitemap index](https://xage.com/sitemap_index.xml): crawlable index of the whole public site. - [Blog feed](https://xage.com/feed/): RSS. ## Products - [Xage Fabric Platform](https://xage.com/products/xage-fabric-platform/) - [Zero Trust Access / secure remote access](https://xage.com/zero-trust-access/) - [Privileged Access Management](https://xage.com/privileged-access-management-pam/) - [Zero Trust Segmentation](https://xage.com/zero-trust-segmentation/) - [Critical Asset Protection](https://xage.com/critical-asset-protection-for-ot-data-center-and-cloud/) - [Zero Trust Data Exchange](https://xage.com/products/zero-trust-data-exchange-critical-infrastructure-ot-it-cloud/) - [Unified Zero Trust for LLMs and AI Agents](https://xage.com/unified-zero-trust-for-llms-and-ai-agents/) - [VPN Replacement](https://xage.com/vpn-replacement/) - [Vendor Access Management](https://xage.com/vendor-access-management/) - [Multi-User Session Collaboration](https://xage.com/multi-user-session-collaboration/) - [Technology Integrations](https://xage.com/products/technology-integrations/) ## Industries - [Electric utilities](https://xage.com/industries/zero-trust-cybersecurity-for-electric-utilities/) - [Oil and gas](https://xage.com/industries/oil-gas/) - [Clean and renewable energy](https://xage.com/industries/operational-cybersecurity-clean-renewable-energy/) - [Manufacturing](https://xage.com/industries/zero-trust-cybersecurity-for-manufacturers/) - [Transportation](https://xage.com/industries/cybersecurity-for-transportation/) - [Federal government](https://xage.com/industries/zero-trust-cybersecurity-federal-government/) - [Defense industrial base](https://xage.com/industries/defense-industrial-base-dib-cybersecurity/) - [Space](https://xage.com/industries/cybersecurity-in-space/) - [Healthcare](https://xage.com/industries/zero-trust-for-healthcare/) ## Company and support - [Website](https://xage.com/) - [About](https://xage.com/about-us/) - [Blog](https://xage.com/blog/) - [Press](https://xage.com/press/) - [Case studies](https://xage.com/case-studies/) - [Partners](https://xage.com/partners/) - [Resources](https://xage.com/resources/) - [Support](https://xage.com/support/): the documentation library requires a support-portal login. - [Privacy policy](https://xage.com/privacy-policy/) ## Optional - No public pricing page (HTTP 404); enterprise contact-sales only. - No public status page, changelog, terms of service, security.txt, GitHub organization, SDK, CLI, Postman collection or A2A agent card were found.