Anchore website screenshot

Anchore

Anchore is a container and software supply chain security company providing open source and enterprise tools for vulnerability scanning, SBOM generation, policy enforcement, and continuous compliance. Core open source products include Syft (SBOM generator for container images and filesystems), Grype (vulnerability scanner), and Grant (license scanner). The Anchore Enterprise platform adds policy engines, CI/CD integrations, registry connectors, Kubernetes admission control, and reporting. Anchore supports CycloneDX and SPDX SBOM formats and integrates with Docker, Kubernetes, GitHub Actions, Jenkins, and major cloud registries.

Anchore publishes 6 APIs on the APIs.io network, including Images API, Policies API, Registries API, and 3 more. Tagged areas include Container Security, Containers, SBOM, Software Supply Chain, and Vulnerability Scanning.

The Anchore catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Anchore’s developer surface includes authentication, developer portal, documentation, getting-started guide, engineering blog, support, pricing, and 23 more developer resources.

65.8/100 strong ▼ -5.6 Agent 41/100 agent ready Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
6 APIs 1 MCP Servers 10 Features 7 Use Cases
Container SecurityContainersSBOMSoftware Supply ChainVulnerability Scanning

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 65.8/100 · strong
Contract Quality 17.4 / 25
Developer Ergonomics 11.7 / 20
Commercial Clarity 14.2 / 20
Operational Transparency 6.8 / 13
Governance 8.3 / 12
Discoverability 7.4 / 10
Agent readiness — 41/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/anchore: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 6

Individual APIs this provider publishes, each with its own machine-readable definition.

Anchore Images API

The Images API from Anchore — 2 operation(s) for images.

Anchore Policies API

The Policies API from Anchore — 2 operation(s) for policies.

Anchore Registries API

The Registries API from Anchore — 1 operation(s) for registries.

Anchore SBOM API

The SBOM API from Anchore — 1 operation(s) for sbom.

Anchore Subscriptions API

The Subscriptions API from Anchore — 1 operation(s) for subscriptions.

Anchore Vulnerabilities API

The Vulnerabilities API from Anchore — 1 operation(s) for vulnerabilities.

Postman Collections 1

Ready-to-run Postman collections for exercising this provider's APIs.

Arazzo Workflows 6

Multi-step API workflows described with the Arazzo specification.

Anchore Analyze Image End to End

Submit a container image for analysis, poll until analyzed, then pull its vulnerabilities and policy evaluation.

ARAZZO

Anchore Create Policy and Evaluate Image

Create a new security policy, then immediately evaluate an analyzed image against it to observe the gate result.

ARAZZO

Anchore Image SBOM and Vulnerability Pull

Confirm an image is analyzed, then export its CycloneDX SBOM and its vulnerability report for downstream compliance use.

ARAZZO

Anchore Registry Image Onboarding

Confirm a registry is configured, then submit an image from it for analysis and confirm the queue.

ARAZZO

Anchore Rescan Active Image and Gate

Find an active analyzed image by tag, force a fresh vulnerability scan, and gate it against policy.

ARAZZO

Anchore Subscribe on Policy Failure

Evaluate an analyzed image against policy and, when it fails the gate, subscribe to ongoing policy-evaluation notifications for its tag.

ARAZZO

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

MCP Server

MCP SERVER

Pricing Plans 1

Published pricing tiers and plan structures.

Anchore Plans Pricing

3 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Anchore Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 10

Notable capabilities this provider offers.

Container image vulnerability scanning (OS and language packages)
SBOM generation in CycloneDX and SPDX formats (Syft)
Policy-based compliance enforcement
Kubernetes admission controller integration
CI/CD pipeline integration (GitHub Actions, Jenkins, GitLab)
Registry connectors (Docker Hub, ECR, GCR, ACR, Harbor)
License scanning and compliance (Grant)
Grype vulnerability database with NVD, GitHub Advisory, and custom feeds
Anchore Enterprise reporting and audit logging
REST API for image analysis, subscriptions, and notifications

Scroll for all 10

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Anchore Enterprise Api Context

0 classes · 14 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Anchore API Rules

5 rules · 3 warnings 2 info

SPECTRAL

Anchore API Rules

19 rules · 5 errors 12 warnings 1 info

SPECTRAL

JSON Schema 3

Standalone JSON Schema definitions for this provider's data models.

Anchore Image

6 properties

JSON SCHEMA

Anchore SBOM

5 properties

JSON SCHEMA

Anchore Vulnerability

9 properties

JSON SCHEMA

JSON Structure 1

JSON Structure definitions describing this provider's data shapes.

Anchore Image Structure

0 properties

JSON STRUCTURE

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Anchore Authentication

http · 2 schemes

SECURITY

Anchore Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Anchore Agentic Access

11 operations · 3 acting

11 operations · 3 acting

AGENTIC

Use Cases 7

What developers build with this provider.

Shift-left container security scanning in CI/CD pipelines
Generate SBOMs for software supply chain transparency
Enforce image policies at Kubernetes admission control
Track vulnerabilities across container registries and deployed images
License compliance scanning for open source components
Continuous compliance monitoring for regulated industries
Developer self-service security scanning via CLI tools

Scroll for all 7

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 4

Reference material describing how the API behaves

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 9

Pagination, idempotency, versioning, errors, and events

Scroll for all 9

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: anchore
name: Anchore
description: Anchore is a container and software supply chain security company providing open source and enterprise tools
  for vulnerability scanning, SBOM generation, policy enforcement, and continuous compliance. Core open source products include
  Syft (SBOM generator for container images and filesystems), Grype (vulnerability scanner), and Grant (license scanner).
  The Anchore Enterprise platform adds policy engines, CI/CD integrations, registry connectors, Kubernetes admission control,
  and reporting. Anchore supports CycloneDX and SPDX SBOM formats and integrates with Docker, Kubernetes, GitHub Actions,
  Jenkins, and major cloud registries.
type: Index
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/anchore.png
tags:
- Container Security
- Containers
- SBOM
- Software Supply Chain
- Vulnerability Scanning
url: https://raw.githubusercontent.com/api-evangelist/anchore/refs/heads/main/apis.yml
created: '2026-03-26'
modified: '2026-05-19'
specificationVersion: '0.19'
apis:
- aid: anchore:anchore-images-api
  name: Anchore Images API
  description: The Images API from Anchore — 2 operation(s) for images.
  humanURL: https://docs.anchore.com/current/docs/using/api_usage/
  baseURL: https://anchore.example.com/v2
  tags:
  - Images
  properties:
  - type: OpenAPI
    url: openapi/anchore-images-api-openapi.yml
  - type: Documentation
    url: https://docs.anchore.com/current/docs/using/api_usage/
  - type: JSONSchema
    url: json-schema/anchore-image-schema.json
  - type: JSONSchema
    url: json-schema/anchore-vulnerability-schema.json
  - type: JSONSchema
    url: json-schema/anchore-sbom-schema.json
  - type: SpectralRules
    url: rules/anchore-spectral-rules.yml
  - type: JSONStructure
    url: json-structure/anchore-image-structure.json
  - type: JSONLD
    url: json-ld/anchore-enterprise-api-context.jsonld
  - type: Vocabulary
    url: vocabulary/anchore-vocabulary.yaml
- aid: anchore:anchore-policies-api
  name: Anchore Policies API
  description: The Policies API from Anchore — 2 operation(s) for policies.
  humanURL: https://docs.anchore.com/current/docs/using/api_usage/
  baseURL: https://anchore.example.com/v2
  tags:
  - Policies
  properties:
  - type: OpenAPI
    url: openapi/anchore-policies-api-openapi.yml
  - type: Documentation
    url: https://docs.anchore.com/current/docs/using/api_usage/
  - type: JSONSchema
    url: json-schema/anchore-image-schema.json
  - type: JSONSchema
    url: json-schema/anchore-vulnerability-schema.json
  - type: JSONSchema
    url: json-schema/anchore-sbom-schema.json
  - type: SpectralRules
    url: rules/anchore-spectral-rules.yml
  - type: JSONStructure
    url: json-structure/anchore-image-structure.json
  - type: JSONLD
    url: json-ld/anchore-enterprise-api-context.jsonld
  - type: Vocabulary
    url: vocabulary/anchore-vocabulary.yaml
- aid: anchore:anchore-registries-api
  name: Anchore Registries API
  description: The Registries API from Anchore — 1 operation(s) for registries.
  humanURL: https://docs.anchore.com/current/docs/using/api_usage/
  baseURL: https://anchore.example.com/v2
  tags:
  - Registries
  properties:
  - type: OpenAPI
    url: openapi/anchore-registries-api-openapi.yml
  - type: Documentation
    url: https://docs.anchore.com/current/docs/using/api_usage/
  - type: JSONSchema
    url: json-schema/anchore-image-schema.json
  - type: JSONSchema
    url: json-schema/anchore-vulnerability-schema.json
  - type: JSONSchema
    url: json-schema/anchore-sbom-schema.json
  - type: SpectralRules
    url: rules/anchore-spectral-rules.yml
  - type: JSONStructure
    url: json-structure/anchore-image-structure.json
  - type: JSONLD
    url: json-ld/anchore-enterprise-api-context.jsonld
  - type: Vocabulary
    url: vocabulary/anchore-vocabulary.yaml
- aid: anchore:anchore-sbom-api
  name: Anchore SBOM API
  description: The SBOM API from Anchore — 1 operation(s) for sbom.
  humanURL: https://docs.anchore.com/current/docs/using/api_usage/
  baseURL: https://anchore.example.com/v2
  tags:
  - SBOM
  properties:
  - type: OpenAPI
    url: openapi/anchore-sbom-api-openapi.yml
  - type: Documentation
    url: https://docs.anchore.com/current/docs/using/api_usage/
  - type: JSONSchema
    url: json-schema/anchore-image-schema.json
  - type: JSONSchema
    url: json-schema/anchore-vulnerability-schema.json
  - type: JSONSchema
    url: json-schema/anchore-sbom-schema.json
  - type: SpectralRules
    url: rules/anchore-spectral-rules.yml
  - type: JSONStructure
    url: json-structure/anchore-image-structure.json
  - type: JSONLD
    url: json-ld/anchore-enterprise-api-context.jsonld
  - type: Vocabulary
    url: vocabulary/anchore-vocabulary.yaml
- aid: anchore:anchore-subscriptions-api
  name: Anchore Subscriptions API
  description: The Subscriptions API from Anchore — 1 operation(s) for subscriptions.
  humanURL: https://docs.anchore.com/current/docs/using/api_usage/
  baseURL: https://anchore.example.com/v2
  tags:
  - Subscriptions
  properties:
  - type: OpenAPI
    url: openapi/anchore-subscriptions-api-openapi.yml
  - type: Documentation
    url: https://docs.anchore.com/current/docs/using/api_usage/
  - type: JSONSchema
    url: json-schema/anchore-image-schema.json
  - type: JSONSchema
    url: json-schema/anchore-vulnerability-schema.json
  - type: JSONSchema
    url: json-schema/anchore-sbom-schema.json
  - type: SpectralRules
    url: rules/anchore-spectral-rules.yml
  - type: JSONStructure
    url: json-structure/anchore-image-structure.json
  - type: JSONLD
    url: json-ld/anchore-enterprise-api-context.jsonld
  - type: Vocabulary
    url: vocabulary/anchore-vocabulary.yaml
- aid: anchore:anchore-vulnerabilities-api
  name: Anchore Vulnerabilities API
  description: The Vulnerabilities API from Anchore — 1 operation(s) for vulnerabilities.
  humanURL: https://docs.anchore.com/current/docs/using/api_usage/
  baseURL: https://anchore.example.com/v2
  tags:
  - Vulnerabilities
  properties:
  - type: OpenAPI
    url: openapi/anchore-vulnerabilities-api-openapi.yml
  - type: Documentation
    url: https://docs.anchore.com/current/docs/using/api_usage/
  - type: JSONSchema
    url: json-schema/anchore-image-schema.json
  - type: JSONSchema
    url: json-schema/anchore-vulnerability-schema.json
  - type: JSONSchema
    url: json-schema/anchore-sbom-schema.json
  - type: SpectralRules
    url: rules/anchore-spectral-rules.yml
  - type: JSONStructure
    url: json-structure/anchore-image-structure.json
  - type: JSONLD
    url: json-ld/anchore-enterprise-api-context.jsonld
  - type: Vocabulary
    url: vocabulary/anchore-vocabulary.yaml
common:
- type: AgenticAccess
  url: agentic-access/anchore-agentic-access.yml
- type: DomainSecurity
  url: security/anchore-domain-security.yml
- type: Authentication
  url: authentication/anchore-authentication.yml
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/anchore/overview
- type: Arazzo
  url: arazzo/anchore-analyze-image-workflow.yml
  name: Anchore Analyze Image End to End
- type: Arazzo
  url: arazzo/anchore-create-policy-and-evaluate-workflow.yml
  name: Anchore Create Policy and Evaluate Image
- type: Arazzo
  url: arazzo/anchore-image-sbom-and-vulns-workflow.yml
  name: Anchore Image SBOM and Vulnerability Pull
- type: Arazzo
  url: arazzo/anchore-registry-scan-workflow.yml
  name: Anchore Registry Image Onboarding
- type: Arazzo
  url: arazzo/anchore-rescan-active-images-workflow.yml
  name: Anchore Rescan Active Image and Gate
- type: Arazzo
  url: arazzo/anchore-subscribe-on-policy-fail-workflow.yml
  name: Anchore Subscribe on Policy Failure
- type: LinkedIn
  url: https://www.linkedin.com/company/anchore
- type: Portal
  url: https://anchore.com/
- type: Documentation
  url: https://docs.anchore.com/
- type: GettingStarted
  url: https://docs.anchore.com/current/docs/quickstart/
- type: Authentication
  url: https://docs.anchore.com/current/docs/using/api_usage/
- type: GitHubOrganization
  url: https://github.com/anchore
- type: Blog
  url: https://anchore.com/blog/
- type: Support
  url: https://anchore.com/support/
- type: Pricing
  url: https://anchore.com/pricing/
- type: StatusPage
  url: https://status.anchore.com/
- type: TermsOfService
  url: https://anchore.com/terms-of-service/
- type: PrivacyPolicy
  url: https://anchore.com/privacy-policy/
- type: JSONSchema
  url: json-schema/anchore-image-schema.json
- type: JSONSchema
  url: json-schema/anchore-vulnerability-schema.json
- type: JSONSchema
  url: json-schema/anchore-sbom-schema.json
- type: SpectralRules
  url: rules/anchore-spectral-rules.yml
- type: Vocabulary
  url: vocabulary/anchore-vocabulary.yaml
- type: JSONLD
  url: json-ld/anchore-enterprise-api-context.jsonld
- type: Features
  data:
  - Container image vulnerability scanning (OS and language packages)
  - SBOM generation in CycloneDX and SPDX formats (Syft)
  - Policy-based compliance enforcement
  - Kubernetes admission controller integration
  - CI/CD pipeline integration (GitHub Actions, Jenkins, GitLab)
  - Registry connectors (Docker Hub, ECR, GCR, ACR, Harbor)
  - License scanning and compliance (Grant)
  - Grype vulnerability database with NVD, GitHub Advisory, and custom feeds
  - Anchore Enterprise reporting and audit logging
  - REST API for image analysis, subscriptions, and notifications
- type: UseCases
  data:
  - Shift-left container security scanning in CI/CD pipelines
  - Generate SBOMs for software supply chain transparency
  - Enforce image policies at Kubernetes admission control
  - Track vulnerabilities across container registries and deployed images
  - License compliance scanning for open source components
  - Continuous compliance monitoring for regulated industries
  - Developer self-service security scanning via CLI tools
- type: Integrations
  data:
  - GitHub Actions (syft-action, scan-action)
  - Kubernetes (anchore-charts, admission controller)
  - Docker and OCI registries
  - Jenkins pipeline integration
  - Harbor registry integration
  - Amazon ECR, Google GCR, Azure ACR
  - Grype vulnerability database
  - CycloneDX and SPDX SBOM standards
- type: Integrations
  url: https://anchore.com/integrations/
- name: MCP Server
  url: https://github.com/anchore/grype-mcp
  type: MCPServer
- type: LlmsText
  url: https://docs.anchore.com/llms.txt
integrations:
- name: Anchore
- name: Icon
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com