Trivy Server API

Server metadata and version information

Operations 1

GET /version Get Server Version #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/trivy-server-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

trivy-server-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Trivy Health Server API
  description: The Trivy Server API exposes HTTP endpoints when running Trivy in client/server mode. In this mode, the server maintains a local vulnerability database and clients submit scan requests without needing to download the database themselves. The server listens on port 4954 by default and supports optional token-based authentication.
  version: 0.70.0
  contact:
    url: https://trivy.dev/
  license:
    name: Apache 2.0
    url: https://github.com/aquasecurity/trivy/blob/main/LICENSE
servers:
- url: http://localhost:4954
  description: Trivy server default endpoint
- url: http://{host}:{port}
  description: Custom Trivy server endpoint
  variables:
    host:
      default: localhost
      description: Trivy server hostname
    port:
      default: '4954'
      description: Trivy server port
tags:
- name: Server
  description: Server metadata and version information
paths:
  /version:
    get:
      operationId: getVersion
      summary: Get Server Version
      description: Retrieve the Trivy server version, vulnerability database version, Java database version, and policy bundle version. Does not require authentication.
      tags:
      - Server
      responses:
        '200':
          description: Server version information
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VersionResponse'
components:
  schemas:
    VersionResponse:
      type: object
      description: Trivy server version and database information
      properties:
        Version:
          type: string
          description: Trivy server version
          example: 0.70.0
        VulnerabilityDB:
          type: object
          description: Vulnerability database metadata
          properties:
            Version:
              type: integer
              description: Database schema version
            NextUpdate:
              type: string
              format: date-time
              description: Next scheduled database update
            UpdatedAt:
              type: string
              format: date-time
              description: Last database update timestamp
            DownloadedAt:
              type: string
              format: date-time
              description: When this database was downloaded
        JavaDB:
          type: object
          description: Java vulnerability database metadata
          properties:
            Version:
              type: integer
            UpdatedAt:
              type: string
              format: date-time
            NextUpdate:
              type: string
              format: date-time
        PolicyBundle:
          type: object
          description: OPA policy bundle metadata
          properties:
            Digest:
              type: string
              description: Bundle content digest
            DownloadedAt:
              type: string
              format: date-time
  securitySchemes:
    TrivyToken:
      type: apiKey
      in: header
      name: Trivy-Token
      description: Optional token-based authentication. When the server is started with --token, all requests must include the token in the Trivy-Token header.
externalDocs:
  description: Trivy Client/Server Documentation
  url: https://trivy.dev/latest/docs/references/modes/client-server/