# Anchore

**Canonical:** https://apis.io/providers/anchore/  
**Website:** https://anchore.com/  
**APIs profiled:** 6

Anchore is a container and software supply chain security company providing open source and enterprise tools for vulnerability scanning, SBOM generation, policy enforcement, and continuous compliance. Core open source products include Syft (SBOM generator for container images and filesystems), Grype (vulnerability scanner), and Grant (license scanner). The Anchore Enterprise platform adds policy engines, CI/CD integrations, registry connectors, Kubernetes admission control, and reporting. Anchore supports CycloneDX and SPDX SBOM formats and integrates with Docker, Kubernetes, GitHub Actions, Jenkins, and major cloud registries.

## Kin Score — 42.7 / 100 (developing)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 42.7).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 65.0 |
| Governance | 25.0 |
| Contract Governance | 25.0 |
| Operational Transparency | 18.4 |
| Developer Ergonomics | 38.1 |
| Commercial Clarity | 26.3 |
| Access Clarity | 26.3 |

## Agent readiness — 33.2 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (6)

- **Anchore Images API** — The Images API from Anchore — 2 operation(s) for images.
- **Anchore Policies API** — The Policies API from Anchore — 2 operation(s) for policies.
- **Anchore Registries API** — The Registries API from Anchore — 1 operation(s) for registries.
- **Anchore SBOM API** — The SBOM API from Anchore — 1 operation(s) for sbom.
- **Anchore Subscriptions API** — The Subscriptions API from Anchore — 1 operation(s) for subscriptions.
- **Anchore Vulnerabilities API** — The Vulnerabilities API from Anchore — 1 operation(s) for vulnerabilities.

## MCP servers (1)

- **MCP Server**

## Agentic access (1)

- **Anchore Agentic Access** — 11 operations · 3 acting

## Security (2)

- **Anchore Authentication** — http · 2 schemes
- **Anchore Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC

## Plans (1)

- **Anchore Plans Pricing**

## Use cases (7)

- **Shift-left container security scanning in CI/CD pipelines**
- **Generate SBOMs for software supply chain transparency**
- **Enforce image policies at Kubernetes admission control**
- **Track vulnerabilities across container registries and deployed images**
- **License compliance scanning for open source components**
- **Continuous compliance monitoring for regulated industries**
- **Developer self-service security scanning via CLI tools**

## Tags

Container Security, Containers, SBOM, Software Supply Chain, Vulnerability Scanning

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/anchore/). Scores are computed from the provider's own public artifacts under a published rubric.
