Fossa
FOSSA is a software supply chain security and open source management platform that scans codebases, containers, and binaries to detect open source dependencies, then enforces open source license compliance, vulnerability management, and SBOM (CycloneDX/SPDX) obligations across the software development lifecycle. FOSSA exposes a REST API at app.fossa.com/api plus the language-agnostic FOSSA CLI, integrating with 20+ build systems and CI/CD to surface licensing, security, and quality issues, generate attribution and audit reports, and gate pull requests on policy violations. Backed by Bain Capital Ventures and Norwest Venture Partners.
Fossa publishes 1 API on the APIs.io network. Tagged areas include Company, Security, Software Supply Chain, Open Source, and License Compliance.
The Fossa catalog on APIs.io includes 1 event-driven AsyncAPI specification.
Fossa’s developer surface includes documentation, API reference, getting-started guide, support, engineering blog, pricing, signup flow, and 22 more developer resources.
API Rating
APIs
FOSSA REST API
The FOSSA REST API lets you build integrations and automate open source management workflows — manage projects, revisions, issues, users and teams, release groups, and reports; ...
MCP Servers
fossa-mcp.yml
MCP SERVEREvent Specifications
Fossa Webhooks
ASYNCAPIResources
Get Started 3
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 2
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 6
Pagination, idempotency, versioning, errors, and events
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 4
Authentication, authorization, and security posture
Operate 3
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API