Sonatype SPDX API

Use this REST API to generate SPDX SBOMs in XML or JSON formats.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/sonatype-spdx-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

sonatype-spdx-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: Sonatype Lifecycle Public REST Advanced Search SPDX API
  version: 1.201.0-02
  description: Use the Advanced Search REST API to perform searches on Lifecycle application scan reports.
security:
- BasicAuth: []
  BearerAuth: []
tags:
- description: Use this REST API to generate SPDX SBOMs in XML or JSON formats.
  name: SPDX
paths:
  /api/v2/spdx/{applicationId}/reports/{scanId}:
    get:
      description: 'Use this method to generate SBOM(s) based on a specific application scan.


        Permissions required: View IQ Elemets'
      operationId: getByScanId
      parameters:
      - description: Enter the applicationId for the application you want to generate the SBOM(s).
        in: path
        name: applicationId
        required: true
        schema:
          type: string
      - description: Enter the scanId of the application scan.
        in: path
        name: scanId
        required: true
        schema:
          type: string
      - description: Enter the format for the SBOM(s) to be generated.
        in: query
        name: format
        schema:
          default: json
          type: string
      - description: Set to `true` to generate an equivalent CycloneDx SBOM. Both SBOMs will be combined as a tar.gz archive.
        in: query
        name: generateCycloneDx
        schema:
          default: false
          type: boolean
      - description: Enter the desired SPDX version, possible values are 2.2|2.3
        in: query
        name: spdxVersion
        schema:
          default: '2.3'
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                description: SBOM in JSON format
                type: string
            application/octet-stream:
              schema:
                description: SBOM archive (tar.gz)
                format: binary
                type: string
            application/xml:
              schema:
                description: SBOM in XML format
                type: string
          description: The requested SBOM(s).
      tags:
      - SPDX
  /api/v2/spdx/{applicationId}/stages/{stageId}:
    get:
      description: 'Use this method to generate SBOM(s) based on the latest application evaluation report at the specified stage.


        Permissions required: View IQ Elements'
      operationId: getLatestForStage
      parameters:
      - description: Enter the applicationId for the application you want to generate the SBOM(s).
        in: path
        name: applicationId
        required: true
        schema:
          type: string
      - description: Specify the stageId for the application evaluation. Allowed values are `develop`, `build`, `stage-release`, `release` and `operate`.
        in: path
        name: stageId
        required: true
        schema:
          type: string
      - description: Enter the format for the SBOM(s) to be generated.
        in: query
        name: format
        schema:
          default: json
          type: string
      - description: Set to `true` to generate an equivalent CycloneDx SBOM. Both SBOMs will be combined as a tar.gz archive.
        in: query
        name: generateCycloneDx
        schema:
          default: false
          type: boolean
      - description: Enter the desired SPDX version, possible values are 2.2|2.3
        in: query
        name: spdxVersion
        schema:
          default: '2.3'
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                description: SBOM in JSON format
                type: string
            application/octet-stream:
              schema:
                description: SBOM archive (tar.gz)
                format: binary
                type: string
            application/xml:
              schema:
                description: SBOM in XML format
                type: string
          description: The requested SBOM(s).
      tags:
      - SPDX
components:
  securitySchemes:
    BasicAuth:
      scheme: basic
      type: http
    BearerAuth:
      bearerFormat: JWT
      scheme: bearer
      type: http