# Black Duck

**Canonical:** https://apis.io/providers/black-duck/  
**Website:** https://documentation.blackduck.com/  
**APIs profiled:** 1

Black Duck Software (formerly the Synopsys Software Integrity Group) is an application security company whose platform spans software composition analysis (SCA), static application security testing (SAST), dynamic application security testing (DAST), interactive application security testing (IAST), and open-source license and vulnerability management. Its API-first products — Black Duck SCA (Hub), Polaris, Coverity, and Seeker — expose REST APIs, webhooks, native CI/CD plug-ins, and the Detect command-line scanner so teams can automate open-source discovery, policy enforcement, and risk remediation across build pipelines such as Jenkins, GitHub Actions, GitLab CI, and Azure DevOps. Each Black Duck server publishes its own OpenAPI 3 document and Postman collection at /api-doc, and first-party Python and Go client libraries plus the Detect CLI wrap the API surface. This profile was seeded as a general-catalyst portfolio lead and enriched by the API Evangelist pipeline.

## Kin Score — 33.7 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 33.7).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 0.0 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 44.7 |
| Developer Ergonomics | 61.9 |
| Commercial Clarity | 39.5 |
| Access Clarity | 39.5 |

## Agent readiness — 12.6 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **Black Duck SCA REST API** — REST API for Black Duck SCA (Hub) — projects, versions, components, vulnerabilities, policies, scans, and reports. Each Black Duck server publishes its own OpenAPI 3 document at...

## MCP servers (1)

- **Black Duck MCP Server**

## Security (4)

- **Black Duck Authentication** — apiKey/http · 2 schemes
- **Black Duck Domain Security** — TLSv1.3 · HSTS · DMARC
- **Black Duck Vulnerability Disclosure** — Hackerone
- **Black Duck Trust Center** — SOC 2 Type 2, SOC 3 Type 2, ISO 27001, ISO 27017, ISO 26262, CSA STAR Self-Assessment, TISAX (Assessment Level 2), TX-RAMP Level 2

## Tags

Company, Enterprise, Application Security, Software Composition Analysis, SAST, DAST, Open Source Security, DevSecOps, Vulnerability Management

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/black-duck/). Scores are computed from the provider's own public artifacts under a published rubric.
