# Dependency-Track

**Canonical:** https://apis.io/providers/dependency-track/  
**Website:** https://dependencytrack.org/  
**APIs profiled:** 4

Dependency-Track is an OWASP flagship open source Component Analysis platform for Software Bill of Materials (SBOM) analysis. Per its site, over 20,000 organizations use it to inventory components, find vulnerabilities, and enforce policy across the software supply chain. It is self-hosted (distributed as Docker images) and exposes a REST API, documented with OpenAPI/Swagger, on each deployed instance at /api.

## Kin Score — 49.6 / 100 (developing)

Scored 2026-10-09 under rubric 0.23.0.

| Facet | Score |
|---|---|
| Discoverability | 62.5 |
| Contract Quality | 61.4 |
| Contract Governance | 71.1 |
| Operational Transparency | 28.9 |
| Developer Ergonomics | 56.5 |
| Access Clarity | 21.1 |

Regulatory layer — **Horizontal (data, software, accessibility, platform)**: 16.7 (matched via fallback).

## Agent readiness — 45.5 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | served |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | yes |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | served |
| Protected Resource Metadata | verified |
| Dynamic Client Registration | yes |
| Agentic Commerce | no |

## APIs (48)

- **Dependency-Track Notifications** — Protocol Buffers (proto3, package org.dependencytrack.notification.v1) message definitions for Dependency-Track notification payloads, published in the DependencyTrack/docs repo...
- **Dependency-Track Acl API** — The acl API from Dependency-Track — 3 operation(s) for acl.
- **Dependency-Track Analysis API** — The analysis API from Dependency-Track — 1 operation(s) for analysis.
- **Dependency-Track Badge API** — The badge API from Dependency-Track — 4 operation(s) for badge.
- **Dependency-Track Bom API** — The bom API from Dependency-Track — 4 operation(s) for bom.
- **Dependency-Track Calculator API** — The calculator API from Dependency-Track — 2 operation(s) for calculator.
- **Dependency-Track Component API** — The component API from Dependency-Track — 8 operation(s) for component.
- **Dependency-Track Component Property API** — The componentProperty API from Dependency-Track — 2 operation(s) for componentproperty.
- **Dependency-Track Components API** — Endpoints related to components
- **Dependency-Track Config Property API** — The configProperty API from Dependency-Track — 4 operation(s) for configproperty.
- **Dependency-Track Cwe API** — The cwe API from Dependency-Track — 2 operation(s) for cwe.
- **Dependency-Track Dependency Graph API** — The dependencyGraph API from Dependency-Track — 2 operation(s) for dependencygraph.
- **Dependency-Track Event API** — The event API from Dependency-Track — 1 operation(s) for event.
- **Dependency-Track Extensions API** — Endpoints related to extensions
- **Dependency-Track Finding API** — The finding API from Dependency-Track — 5 operation(s) for finding.
- **Dependency-Track Kev Data Sources API** — Endpoints related to KEV data sources
- **Dependency-Track Ldap API** — The ldap API from Dependency-Track — 4 operation(s) for ldap.
- **Dependency-Track License API** — The license API from Dependency-Track — 3 operation(s) for license.
- **Dependency-Track License Group API** — The licenseGroup API from Dependency-Track — 3 operation(s) for licensegroup.
- **Dependency-Track Metrics API** — The metrics API from Dependency-Track — 13 operation(s) for metrics.
- **Dependency-Track Notification API** — The notification API from Dependency-Track — 8 operation(s) for notification.
- **Dependency-Track OAuth API** — Endpoints related to OAuth 2.0 token issuance
- **Dependency-Track Oidc API** — The oidc API from Dependency-Track — 7 operation(s) for oidc.
- **Dependency-Track Permission API** — The permission API from Dependency-Track — 5 operation(s) for permission.
- **Dependency-Track Policy API** — The policy API from Dependency-Track — 3 operation(s) for policy.
- **Dependency-Track Policy Condition API** — The policyCondition API from Dependency-Track — 3 operation(s) for policycondition.
- **Dependency-Track Project API** — The project API from Dependency-Track — 14 operation(s) for project.
- **Dependency-Track Project Property API** — The projectProperty API from Dependency-Track — 1 operation(s) for projectproperty.
- **Dependency-Track Projects API** — Endpoints related to projects
- **Dependency-Track Repository API** — The repository API from Dependency-Track — 4 operation(s) for repository.
- **Dependency-Track Secrets API** — Endpoints related to secrets
- **Dependency-Track Service Accounts API** — Endpoints related to service accounts
- **Dependency-Track Service API** — The service API from Dependency-Track — 3 operation(s) for service.
- **Dependency-Track System Capabilities API** — Endpoints exposing the capabilities of the running server
- **Dependency-Track Tag API** — The tag API from Dependency-Track — 7 operation(s) for tag.
- **Dependency-Track Task Queues API** — Endpoints related to task queue management
- **Dependency-Track Team API** — The team API from Dependency-Track — 7 operation(s) for team.
- **Dependency-Track User API** — The user API from Dependency-Track — 11 operation(s) for user.
- **Dependency-Track Version API** — The version API from Dependency-Track — 1 operation(s) for version.
- **Dependency-Track Vex API** — The vex API from Dependency-Track — 2 operation(s) for vex.
- …and 8 more, listed in full on the page.

## Agentic access (1)

- **Dependency Track Agentic Access** — 272 operations · 137 acting · 1 human-in-the-loop

## Security (2)

- **Dependency Track Authentication** — apiKey/http · 2 schemes
- **Dependency Track Domain Security** — TLSv1.3 · HSTS · DMARC

## Plans (1)

- **Dependency Track Plans Pricing**

## Tags

Company, SBOM, Software Supply Chain, Vulnerability Management, Open Source, OWASP, Security, CycloneDX

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/dependency-track/). Scores are computed from the provider's own public artifacts under a published rubric.
