Atlassian Compass Package Dependencies API
This resource represents package dependencies. Use this resource to associate package dependencies with a component.
This resource represents package dependencies. Use this resource to associate package dependencies with a component.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/atlassian-compass-package-dependencies-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Compass REST Package Dependencies API
version: '1'
description: This resource represents package dependencies. Use this resource to associate package dependencies with a component.
servers:
- url: https://your-domain.atlassian.net/gateway/api
security:
- basicAuth: []
tags:
- name: Package Dependencies
description: This resource represents package dependencies. Use this resource to associate package dependencies with a component.
paths:
/compass/v1/package_dependencies/lock_file:
put:
tags:
- Package Dependencies
summary: Upload Package Dependencies via Lock File
description: 'Upload package dependencies for a component.
The file with package dependency information. Currently, we only accept package-lock.json files that are below 2MB. \
\
The baseSourceUrl should be a url link to your lock file, ideally with "#lines-" appended at the end, if from Bitbucket, or "#L" appended if a GitHub link. This will let link to specific lines in your lock file where dependencies were found. \
\
The sourceId should be a string that uniquely identifies the given lock file. We recommend using the filepath to the lock file, with the "/" characters replaced with "_" characters.
Example: This curl command uploads a lock file to populate package dependencies for the component.
```bash
curl --request PUT \
--url ''https://your-domain.atlassian.net/gateway/api/compass/v1/package_dependencies/lock_file'' \
--user ''email@example.com:'' \
--header ''Content-Type: multipart/form-data'' \
--form file=@/path/to/file/package-lock.json;type=application/json
--form componentId=
--form baseSourceUrl=
--form sourceId=
```'
operationId: uploadLockFile
parameters:
- name: sourceId
in: query
required: true
schema:
type: string
- name: baseSourceUrl
in: query
required: true
schema:
type: string
- name: componentId
in: query
required: true
schema:
type: string
requestBody:
content:
multipart/form-data:
schema:
type: object
properties:
file:
type: string
format: binary
required:
- file
responses:
'200':
description: Returned if the file upload is successful.
content:
'*/*':
schema:
type: string
'400':
description: Returned if the request is not valid.
content:
'*/*':
schema:
type: string
'403':
description: Returned if the user is not permitted to modify the given component.
content:
'*/*':
schema:
type: string
'404':
description: Returned if the component is not found.
content:
'*/*':
schema:
type: string
'422':
description: Returned if the uploaded file type is not accepted and/or file content cannot be parsed.
content:
'*/*':
schema:
type: string
/compass/v1/package_dependencies/lock_file/{componentId}/{sourceId}:
delete:
tags:
- Package Dependencies
summary: Delete Package Dependencies given a Source
description: Delete all the package dependencies associated with a particular source.The `sourceId` parameter needs to be Base64 encoded.
operationId: deleteLockFile
parameters:
- name: componentId
in: path
required: true
schema:
type: string
- name: sourceId
in: path
required: true
schema:
type: string
responses:
'200':
description: Returned if the file upload is successful.
content:
'*/*':
schema:
type: string
'400':
description: Returned if the request is not valid.
content:
'*/*':
schema:
type: string
'403':
description: Returned if the user is not permitted to modify the given component.
content:
'*/*':
schema:
type: string
'404':
description: Returned if the component is not found.
content:
'*/*':
schema:
type: string
components:
securitySchemes:
basicAuth:
type: http
scheme: basic
x-atlassian-narrative:
documents:
- title: About
anchor: about
body: 'This is the reference for the Compass REST API.
The REST API enables you to interact with [Compass](/cloud/compass/overview/what-is-compass/) programmatically.
Use this API for scripting interactions with Compass and sending data from external tools.
This page documents the REST resources available in Compass, including the HTTP response codes and example requests and responses.
In addition to the Compass REST API, you can use our [Atlassian platform GraphQL API](/cloud/compass/graphql/) to use many more Compass features.'
- title: Version
anchor: version
body: This documentation is for version 1 of the Compass REST API.
- title: Authentication
anchor: authentication
body: "The REST API supports basic auth.\n\n### Get an API token\nBasic auth requires API tokens. You generate an API token for your Atlassian account and use it to authenticate anywhere where you would have used a password. This authentication enhances security because:\n\n* you're not saving your primary account password outside of where you authenticate\n* you can quickly revoke individual API tokens on a per-use basis\n* API tokens allow you to authenticate even if your Atlassian Cloud organization has two-factor authentication or SAML enabled\n\nSee the Atlassian Cloud Support [API tokens](https://confluence.atlassian.com/x/Vo71Nw) article to discover how to generate an API token.\n\n### Simple example\nMost client software provides a simple mechanism for supplying a user name (in our case, the email address) and API token that the client uses to build the required authentication headers. For example, you can specify the `--user` argument in cURL as follows:\n\n```\ncurl --request POST \\\n --url 'https://your-domain.atlassian.net/gateway/api/compass/v1/metrics' \\\n --user 'email@example.com:<api_token>' \\\n --header 'Accept: application/json' \\\n --header 'Content-Type: application/json' \\\n --data '{\n \"metricSourceId\": \"<string>\",\n \"value\": 32,\n \"timestamp\": \"<string>\"\n}'\n```\n\n### Supply basic auth headers\nYou can construct and send basic auth headers, including a base64-encoded string that contains your Atlassian account email and API token.\n\nTo use basic auth headers, perform the following steps:\n\n1. Generate an API Token for your Atlassian Account: https://id.atlassian.com/manage/api-tokens\n1. Build a string of the form `your_email@domain.com:your_user_api_token`\n1. You need to encode your authorization credentials to base64. There are online tools (such as, https://www.base64encode.net/) that you can use to create your base64 encoded string. For example, `your_email@domain.com:your_user_api_token` base64 encoded is `eW91cl9lbWFpbEBkb21haW4uY29tOnlvdXJfdXNlcl9hcGlfdG9rZW4=`\n1. Supply an `Authorization` header with content `Basic` followed by the encoded string. Example: `Authorization: Basic eW91cl9lbWFpbEBkb21haW4uY29tOnlvdXJfdXNlcl9hcGlfdG9rZW4=`"
- title: Authorization
anchor: authorization
body: If you are making calls directly against the REST API, authorization is based on the user used in the authentication process.
- title: Status codes
anchor: status-code
body: "The Compass REST API uses the [standard HTTP status codes](https://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html).\n\nResponses that return an error status code also return a response body, similar to this:\n```json\n{\n \"errors\": [\n {\n \"type\": \"FORMAT_INVALID\",\n \"message\": \"Field [value] is invalid.\"\n }\n ]\n}\n```"