Vendor API selection and capability matrix
Compare APIs against the required workflow. Record product versions, access conditions, identity handling, event support and the operations your application needs.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Capability level comparison from official material reviewed on 25 August 2026; cells do not assert endpoint parity, licence inclusion, product compatibility, or availability in every region.
On this page
Overview#
Vendor APIs / Selection and capability matrix
Use this matrix to shortlist a surface, then read its vendor page and current official contract. “Documented” means the vendor publicly establishes the capability class; it doesn't mean every operation is available to every product, account, licence, or role.
Device and edge video#
| Vendor family | Primary deployment | Documented native surfaces | Capability classes evidenced | Documentation/package access | Grade |
|---|---|---|---|---|---|
| Axis | Device and on device app | VAPIX; Device Configuration APIs; ACAP | Discovery, configuration, media/events/I/O by API family, application lifecycle, edge apps | Core docs public; SDK public; model/OS/API compatibility applies | V2 |
| Hikvision | Device and on device app | ISAPI; HEOP | Cross product HTTP integration; embedded applications | TPP registration/login and restricted material for normative guides | V1 |
| Dahua | Device and native client SDK | CGI; NetSDK | Device integration, events/media/control by product/package | Public product/release evidence; current complete contracts are not consistently public | V1 |
| Hanwha Vision | Device and on camera app | SUNAPI; SUNAPI SDK; Open Platform SDK | Device integration and edge applications; exact functions model specific | Product pages public; SDK/guides commonly STEP account gated | V1 |
| Bosch / Keenfinity | Device, VMS component, native SDK | Video SDK and integration tools | Video/device integration and plugin tooling | Portals public at catalogue level; packages, licences, compatibility can be partner/download gated | V1 |
| 2N | Intercom/access device and management server | 2N IP HTTP API; Access Commander API; selected platform APIs | Status, events, configuration and device functions; access/intercom actuation where enabled | Manuals and API references public; feature/licence/model gates apply | V2 |
| Zenitel | Intercom server/client integration | VS SDK; .NET libraries; recorder interface | ICX/AlphaCom state and control; recording integration | Official wiki public; binaries/features/licences and lifecycle vary | V1 |
VMS and cloud video#
| Vendor family | Primary deployment | Documented native surfaces | Capability classes evidenced | Documentation/package access | Grade |
|---|---|---|---|---|---|
| Milestone | On premises VMS and gateway | MIP SDK; protocol APIs; API Gateway REST | Configuration, events/alarms, messaging, control, media/metadata, plugins | Documentation public; product/licence and installed environment required | V2 |
| Genetec | On premises Security Center | Security Center SDK; Web SDK; product specific web APIs | Video, access, intrusion, ALPR, events, media and platform extensions | Overview public; DAP membership, package and licences for development/deployment | V2 |
| Network Optix | Nx Meta/OEM VMS | Server REST API; C++ plugin SDK; Cloud API; open source client | Resource/user administration, media, events/rules, PTZ, server plugins | Core docs public; account/program, developer licences and build compatibility apply | V2 |
| Motorola Solutions / Avigilon | Unity, Alta and product specific platforms | Developer program and product specific web/REST/SDK surfaces | Video, access, alarms, web endpoint and partner integration interfaces by product | Public catalogue is fragmented; detailed contracts and entitlements often partner/product gated | V1 |
| Eagle Eye Networks | Cloud VMS | Video API v3 | Cameras, live/recorded media, events, alerts, SSE/webhooks | Docs public; developer account, OAuth client and customer authorisation required | V2 |
| Verkada | Multi region cloud platform | Command APIs and webhooks | Camera, access and other product APIs; token, pagination and limit contract | Reference public; organization, region, permissions and product subscription required | V2 |
Access and identity#
| Vendor family | Primary deployment | Documented native surfaces | Capability classes evidenced | Documentation/package access | Grade |
|---|---|---|---|---|---|
| HID Origo | Cloud identity and mobile credentials | Mobile Identities; User/Credential Management; Events; mobile SDK ecosystem | User and digital credential lifecycle, callbacks, wallet/app provisioning | API docs public but intended for enrolled technology partners; credentials from HID | V2 |
| Gallagher | On premises Command Centre, optional cloud gateway | REST API families; controller interfaces; Video Viewer and Mobile Connect SDKs | Cardholders, events/alarms, status, overrides, inbound events, mobile credentials | Product summaries public; guides, token, demo licence and endorsement workflow partner gated | V1 |
| LenelS2 | OnGuard on prem/cloud; Elements SaaS | OpenAccess Web Services and partner interfaces | OnGuard data, event and command integrations; Elements connector evidenced separately | Detailed docs/packages through LenelS2 Connect; Elements developer API not publicly established here | V1 |
| Johnson Controls C•CURE | On premises C•CURE 9000/victor | Product SDK/web service and licensed integration interfaces | Personnel, devices, alarms, command and platform integrations by package | Public product/integration docs are partial; developer packages/licensing require vendor channel | V1 |
| SALTO | KS cloud, Nebula cloud, Space on premises | KS Connect/Core; Nebula; Space Hospitality; SHIP | Identity/access lifecycle, locks, events and credentials by platform | Cloud API references public; client credentials from SALTO; SHIP licensed and NDA gated | V2 |
| Brivo | Cloud access platform | Brivo Access API | Sites, users, credentials, doors, events and high impact commands | Documentation public; developer portal and customer specific app credentials required | V2 |
| Suprema | On premises BioStar 2 | New Local API; separate Device SDK and TA API | Users, credentials, doors, devices, events, biometrics and administration | API collection/support docs public; exact server/API version and licence determine availability | V2 |
| Kisi | Cloud access platform and mobile SDK | JSON API; webhooks; iOS/Android SDKs | Users, access rights, locks, unlocks, events and embedded mobile access | API reference public; sandbox/partner ID and SDK access require vendor onboarding | V2 |
Selection tests#
Before selecting a surface, answer all of these:
| Test | Required evidence |
|---|---|
| Authority | Which installed product or cloud tenant is authoritative for identities, configuration, events, media, and physical state? |
| Direction | Is the integration observing, provisioning, subscribing, embedding media, hosting a plugin, or commanding a device? |
| Entitlement | Which account, partner agreement, licence, subscription, role, scope, and site/tenant permission enables it? |
| Compatibility | Which exact product build, API/SDK version, firmware, model, architecture, runtime, and region are supported together? |
| Security | How are clients enrolled, secrets/certificates rotated, privileges bounded, callbacks authenticated, and audit records correlated? |
| Failure | What happens on timeout, token expiry, reconnect, duplicate event, lost callback, server failover, cloud outage, and uncertain command outcome? |
| Lifecycle | Where are release notes, deprecation notices, security advisories, and support windows published? |
| Safety | Can the surface unlock, override, activate output, issue/revoke a credential, alter alarm behaviour, expose audio/video, or process biometrics? |
What can't be compared safely in one cell#
Endpoint counts, “RESTful” labels, nominal API versions, and SDK download availability are poor proxies for integration quality. Compare the exact workflow: authorisation depth, event durability, media transport, reconciliation, offline behaviour, audit quality, compatibility policy, and vendor support. See retries and idempotency and polling, subscriptions, and reconciliation.