# Fortify Software

**Canonical:** https://apis.io/providers/fortify-software/  
**Website:** https://www.opentext.com/products/fortify-on-demand  
**APIs profiled:** 28

Fortify Software is the application security (AppSec) business now delivered as OpenText Core Application Security, better known by its long-running Fortify brand. Founded in 2003 in San Mateo, California, Fortify pioneered static application security testing (SAST) and was acquired by HP in 2010, moved to Micro Focus in 2017, and to OpenText in 2023. Its flagship SaaS, Fortify on Demand (FoD), provides SAST, DAST, mobile (MAST), and open-source/software-composition analysis as a service, and exposes a documented Fortify on Demand REST API (v3) covering applications, releases, scans, vulnerabilities, reports, users, tenants, and personal access tokens. Authentication is OAuth 2.0 (client-credentials token endpoint) with granular tenant scopes, plus personal access tokens and API keys. A rich GitHub organization (github.com/fortify) ships first-party tooling including the fcli command-line utility and Software Security Center REST clients.

## Kin Score — 38.5 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 38.5).

| Facet | Score |
|---|---|
| Discoverability | 92.6 |
| Contract Quality | 51.9 |
| Governance | 16.7 |
| Contract Governance | 16.7 |
| Operational Transparency | 44.7 |
| Developer Ergonomics | 42.3 |
| Commercial Clarity | 0.0 |
| Access Clarity | 0.0 |

## Agent readiness — 21.1 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | documented |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (28)

- **Fortify Software ApiKeyManagement API** — The ApiKeyManagement API from Fortify Software — 5 operation(s) for apikeymanagement.
- **Fortify Software Applications API** — The Applications API from Fortify Software — 15 operation(s) for applications.
- **Fortify Software Attributes API** — The Attributes API from Fortify Software — 2 operation(s) for attributes.
- **Fortify Software AuditTemplate API** — The AuditTemplate API from Fortify Software — 1 operation(s) for audittemplate.
- **Fortify Software DastAutomatedScans API** — The DastAutomatedScans API from Fortify Software — 9 operation(s) for dastautomatedscans.
- **Fortify Software DynamicScans API** — The DynamicScans API from Fortify Software — 5 operation(s) for dynamicscans.
- **Fortify Software EventLogs API** — The EventLogs API from Fortify Software — 1 operation(s) for eventlogs.
- **Fortify Software FortifyOnDemandConnectNetworks API** — The FortifyOnDemandConnectNetworks API from Fortify Software — 1 operation(s) for fortifyondemandconnectnetworks.
- **Fortify Software LookupItems API** — The LookupItems API from Fortify Software — 1 operation(s) for lookupitems.
- **Fortify Software MobileScans API** — The MobileScans API from Fortify Software — 3 operation(s) for mobilescans.
- **Fortify Software MultiFactorAuthorizationCode API** — The MultiFactorAuthorizationCode API from Fortify Software — 1 operation(s) for multifactorauthorizationcode.
- **Fortify Software Notifications API** — The Notifications API from Fortify Software — 3 operation(s) for notifications.
- **Fortify Software OpenSourceComponents API** — The OpenSourceComponents API from Fortify Software — 2 operation(s) for opensourcecomponents.
- **Fortify Software OpenSourceScans API** — The OpenSourceScans API from Fortify Software — 1 operation(s) for opensourcescans.
- **Fortify Software PersonalAccessTokens API** — The PersonalAccessTokens API from Fortify Software — 3 operation(s) for personalaccesstokens.
- **Fortify Software Releases API** — The Releases API from Fortify Software — 15 operation(s) for releases.
- **Fortify Software Reports API** — The Reports API from Fortify Software — 7 operation(s) for reports.
- **Fortify Software Scans API** — The Scans API from Fortify Software — 8 operation(s) for scans.
- **Fortify Software StaticScans API** — The StaticScans API from Fortify Software — 6 operation(s) for staticscans.
- **Fortify Software TenantEntitlements API** — The TenantEntitlements API from Fortify Software — 2 operation(s) for tenantentitlements.
- **Fortify Software TenantHeatMaps API** — The TenantHeatMaps API from Fortify Software — 1 operation(s) for tenantheatmaps.
- **Fortify Software Tenants API** — The Tenants API from Fortify Software — 2 operation(s) for tenants.
- **Fortify Software TenantSummary API** — The TenantSummary API from Fortify Software — 1 operation(s) for tenantsummary.
- **Fortify Software UserApplicationAccess API** — The UserApplicationAccess API from Fortify Software — 2 operation(s) for userapplicationaccess.
- **Fortify Software UserGroupApplicationAccess API** — The UserGroupApplicationAccess API from Fortify Software — 2 operation(s) for usergroupapplicationaccess.
- **Fortify Software UserManagement API** — The UserManagement API from Fortify Software — 3 operation(s) for usermanagement.
- **Fortify Software Users API** — The Users API from Fortify Software — 2 operation(s) for users.
- **Fortify Software Vulnerabilities API** — The Vulnerabilities API from Fortify Software — 20 operation(s) for vulnerabilities.

## MCP servers (1)

- **Fortify Software MCP Server**

## Security (3)

- **Fortify Software Authentication** — oauth2/apiKey · 4 schemes
- **Fortify Software Domain Security** — TLSv1.3 · DMARC
- **Fortify Software Vulnerability Disclosure** — security.txt · contact published

## Tags

Company, Security, Application Security, AppSec, SAST, DAST, Vulnerability Management, DevSecOps, Software Composition Analysis, API Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/fortify-software/). Scores are computed from the provider's own public artifacts under a published rubric.
