# Fossa

**Canonical:** https://apis.io/providers/fossa/  
**Website:** https://fossa.com/  
**APIs profiled:** 1

FOSSA is a software supply chain security and open source management platform that scans codebases, containers, and binaries to detect open source dependencies, then enforces open source license compliance, vulnerability management, and SBOM (CycloneDX/SPDX) obligations across the software development lifecycle. FOSSA exposes a REST API at app.fossa.com/api plus the language-agnostic FOSSA CLI, integrating with 20+ build systems and CI/CD to surface licensing, security, and quality issues, generate attribution and audit reports, and gate pull requests on policy violations. Backed by Bain Capital Ventures and Norwest Venture Partners.

## Kin Score — 48.7 / 100 (developing)

Scored 2026-08-30 under rubric 0.17.2. Trend: flat (+0.0 from 48.7).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 42.7 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 42.1 |
| Developer Ergonomics | 66.7 |
| Commercial Clarity | 47.4 |
| Access Clarity | 47.4 |

## Agent readiness — 22.7 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **FOSSA REST API** — The FOSSA REST API lets you build integrations and automate open source management workflows — manage projects, revisions, issues, users and teams, release groups, and reports; ...

## MCP servers (1)

- **Fossa MCP Server**

## Security (3)

- **Fossa Authentication** — http · 1 scheme
- **Fossa Domain Security** — TLSv1.3 · HSTS · DMARC
- **Fossa Trust Center** — SOC 2

## Tags

Company, Security, Software Supply Chain, Open-Source, License Compliance, Vulnerability Management, SBOM, Software Composition Analysis, DevSecOps

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/fossa/). Scores are computed from the provider's own public artifacts under a published rubric.
