# Cycode

**Canonical:** https://apis.io/providers/cycode/  
**Website:** https://cycode.com/  
**APIs profiled:** 1

Cycode is a complete Application Security Posture Management (ASPM) and software supply chain security platform that delivers visibility, security, and integrity across the entire software development lifecycle. Its Risk Intelligence Graph (RIG) correlates findings from SAST, SCA, secrets, IaC, and container scanning into a single risk model. Cycode exposes a REST API and webhooks, an official command-line interface (the `cycode` CLI for pip/Homebrew), and an official Model Context Protocol (MCP) server for AI-assisted scanning. Founded in 2019 and backed by Insight Partners, Cycode is certified SOC 2 Type II, ISO 27001, and CSA STAR Level 1. This profile was enriched by the API Evangelist pipeline.

## Kin Score — 29.9 / 100 (thin)

Scored 2026-08-30 under rubric 0.17.2. Trend: flat (+0.0 from 29.9).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 0.0 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 28.9 |
| Developer Ergonomics | 21.4 |
| Commercial Clarity | 60.5 |
| Access Clarity | 60.5 |

## Agent readiness — 6.0 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **Cycode API** — Cycode's REST API and webhooks for the ASPM / software supply chain security platform, including the Risk Intelligence Graph (RIG) reporting API. JWT bearer authentication obtai...

## MCP servers (1)

- **Cycode MCP Server** — Official Cycode MCP server, shipped inside the cycode CLI, exposing Cycode's security scanning capabilities to AI assistants and agents. Started locally with `cycode mcp`; not a...

## Security (4)

- **Cycode Authentication** — apiToken/oauth2 · 2 schemes
- **Cycode Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Cycode Vulnerability Disclosure** — contact published
- **Cycode Trust Center** — SOC 2 Type II, ISO 27001, CSA STAR Level 1

## Tags

Company, Cybersecurity, Application Security, Software Supply Chain Security, ASPM, DevSecOps, Secrets Scanning, SAST, SCA, Developer Tools, MCP, CLI

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/cycode/). Scores are computed from the provider's own public artifacts under a published rubric.
