# Mend

**Canonical:** https://apis.io/providers/mend/  
**Website:** https://www.mend.io/  
**APIs profiled:** 47

Mend.io (formerly WhiteSource) is a unified application security and AI security platform that helps engineering and security teams find and automatically remediate vulnerabilities across open-source dependencies, proprietary code, containers, and AI models/agents. Its products span Software Composition Analysis (SCA), Static Application Security Testing (SAST), container image scanning, SBOM generation, automated dependency updates (Renovate), and AI-native security for LLM-powered applications. Mend exposes a REST-compliant AppSec Platform API (v3.0) and an SCA API (v2.0) for automating scans, projects, applications, findings, reports, and administration, secured with a short-lived per-organization JWT obtained from a user key.

## Kin Score — 50.7 / 100 (developing)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 50.7).

| Facet | Score |
|---|---|
| Discoverability | 92.6 |
| Contract Quality | 54.2 |
| Governance | 11.5 |
| Operational Transparency | 36.8 |
| Developer Ergonomics | 69.0 |
| Commercial Clarity | 39.5 |

## Agent readiness — 49.8 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | yes |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (47)

- **Mend Access Management API** — The Access Management API from Mend — 5 operation(s) for access management.
- **Mend Access Management - Organizations API** — The Access Management - Organizations API from Mend — 2 operation(s) for access management - organizations.
- **Mend Administration - Groups API** — The Administration - Groups API from Mend — 6 operation(s) for administration - groups.
- **Mend Administration - Labels API** — The Administration - Labels API from Mend — 2 operation(s) for administration - labels.
- **Mend Administration - Users API** — The Administration - Users API from Mend — 5 operation(s) for administration - users.
- **Mend AI API** — The AI API from Mend — 1 operation(s) for ai.
- **Mend Alerts - Product API** — The Alerts - Product API from Mend — 3 operation(s) for alerts - product.
- **Mend Alerts - Project API** — The Alerts - Project API from Mend — 6 operation(s) for alerts - project.
- **Mend Applications API** — The Applications API from Mend — 8 operation(s) for applications.
- **Mend Asynchronous Process Control API** — The Asynchronous Process Control API from Mend — 1 operation(s) for asynchronous process control.
- **Mend CustomAttribute - Organization API** — The CustomAttribute - Organization API from Mend — 2 operation(s) for customattribute - organization.
- **Mend CustomAttribute - Product API** — The CustomAttribute - Product API from Mend — 1 operation(s) for customattribute - product.
- **Mend CustomAttribute - Project API** — The CustomAttribute - Project API from Mend — 1 operation(s) for customattribute - project.
- **Mend Dependencies Source Files API** — The Dependencies Source Files API from Mend — 8 operation(s) for dependencies source files.
- **Mend domain-controller API** — The domain-controller API from Mend — 1 operation(s) for domain-controller.
- **Mend Entities - Organization API** — The Entities - Organization API from Mend — 7 operation(s) for entities - organization.
- **Mend Entities - Product API** — The Entities - Product API from Mend — 2 operation(s) for entities - product.
- **Mend Entities - Project API** — The Entities - Project API from Mend — 3 operation(s) for entities - project.
- **Mend Findings - Project API** — The Findings - Project API from Mend — 26 operation(s) for findings - project.
- **Mend Findings - Scan API** — The Findings - Scan API from Mend — 5 operation(s) for findings - scan.
- **Mend General Info - Licenses API** — The General Info - Licenses API from Mend — 2 operation(s) for general info - licenses.
- **Mend General Info - Permissions API** — The General Info - Permissions API from Mend — 1 operation(s) for general info - permissions.
- **Mend General Info - Vulnerabilities API** — The General Info - Vulnerabilities API from Mend — 2 operation(s) for general info - vulnerabilities.
- **Mend Integrations API** — The Integrations API from Mend — 1 operation(s) for integrations.
- **Mend Library - Organization API** — The Library - Organization API from Mend — 10 operation(s) for library - organization.
- **Mend Library - Product API** — The Library - Product API from Mend — 6 operation(s) for library - product.
- **Mend Library - Project API** — The Library - Project API from Mend — 5 operation(s) for library - project.
- **Mend Library - Source Files API** — The Library - Source Files API from Mend — 2 operation(s) for library - source files.
- **Mend Policies - Organization API** — The Policies - Organization API from Mend — 4 operation(s) for policies - organization.
- **Mend Policies - Product API** — The Policies - Product API from Mend — 4 operation(s) for policies - product.
- **Mend Policies - Project API** — The Policies - Project API from Mend — 4 operation(s) for policies - project.
- **Mend product-attribution-report-controller API** — The product-attribution-report-controller API from Mend — 1 operation(s) for product-attribution-report-controller.
- **Mend project-attribution-report-controller API** — The project-attribution-report-controller API from Mend — 1 operation(s) for project-attribution-report-controller.
- **Mend Projects API** — The Projects API from Mend — 11 operation(s) for projects.
- **Mend Red Team API** — The Red Team API from Mend — 1 operation(s) for red team.
- **Mend Reports API** — The Reports API from Mend — 43 operation(s) for reports.
- **Mend Scans API** — The Scans API from Mend — 6 operation(s) for scans.
- **Mend Settings - In-House API** — The Settings - In-House API from Mend — 4 operation(s) for settings - in-house.
- **Mend Settings - Whitelist API** — The Settings - Whitelist API from Mend — 4 operation(s) for settings - whitelist.
- **Mend Summary - Organization API** — The Summary - Organization API from Mend — 12 operation(s) for summary - organization.
- …and 7 more, listed in full on the page.

## MCP servers (1)

- **mend-mcp.yml**

## Agentic access (1)

- **Mend Agentic Access** — 291 operations · 156 acting · 3 human-in-the-loop

## Security (3)

- **Mend Authentication** — http · 1 scheme
- **Mend Domain Security** — TLSv1.3 · HSTS · DMARC
- **Mend Trust Center** — trust center published

## Tags

Application Security, Software Composition Analysis, SAST, Container Security, AI Security, Dependency Management, Vulnerability Management, DevSecOps, SBOM, Open Source Security, Company

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/mend/). Scores are computed from the provider's own public artifacts under a published rubric.
