OpenSSF
The Open Source Security Foundation (OpenSSF) is a collaborative initiative under the Linux Foundation dedicated to improving the security of open source software. It brings together industry leaders, developers, and security experts to address vulnerabilities, enhance supply chain security, and develop security tools and best practices. OpenSSF stewards a number of projects with public REST APIs, including the OSV (Open Source Vulnerabilities) database, the Scorecard automated security health-check service, and Sigstore signing infrastructure.
OpenSSF publishes 5 APIs on the APIs.io network, including Projects API, Query API, Querybatch API, and 2 more. Tagged areas include Linux Foundation, Open Source, Security, Supply Chain, and Vulnerabilities.
The OpenSSF catalog on APIs.io includes 1 JSON-LD context and 1 Spectral governance ruleset.
OpenSSF’s developer surface includes documentation, developer portal, engineering blog, and 11 more developer resources.
Kin Score
APIs 7
Individual APIs this provider publishes, each with its own machine-readable definition.
Sigstore Public Good APIs
Sigstore is an OpenSSF-hosted standard and service for signing, verifying, and protecting software. The public-good Sigstore instance exposes Fulcio (code-signing certificate au...
GUAC (Graph for Understanding Artifact Composition)
GUAC aggregates software supply-chain security metadata (SBOMs, attestations, vulnerabilities, signatures) into a queryable graph. GUAC exposes a GraphQL API for supply-chain qu...
OpenSSF Projects API
The Projects API from OpenSSF — 1 operation(s) for projects.
OpenSSF Query API
The Query API from OpenSSF — 1 operation(s) for query.
OpenSSF Querybatch API
The Querybatch API from OpenSSF — 1 operation(s) for querybatch.
OpenSSF V1experimental API
The V1experimental API from OpenSSF — 2 operation(s) for v1experimental.
OpenSSF Vulns API
The Vulns API from OpenSSF — 1 operation(s) for vulns.
Scroll for all 7
Open Collections 2
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
OSV (Open Source Vulnerabilities) API
OPEN COLLECTIONOpenSSF Scorecard API
OPEN COLLECTIONGraphQL 1
GraphQL schemas published by this provider.
OpenSSF GraphQL API
GUAC aggregates software supply-chain security metadata (SBOMs, attestations, vulnerabilities, signatures) into a queryable graph. GUAC exposes a GraphQL API for supply-chain qu...
GRAPHQLPricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Openssf Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Openssf Finops
FINOPSSemantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Openssf Context
JSON-LDSpectral Rules 1
Spectral governance rulesets for linting and validating these APIs.
OpenSSF API Rules
SPECTRALJSON Schema 1
Standalone JSON Schema definitions for this provider's data models.
OSV Vulnerability
JSON SCHEMASecurity Posture 1
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 1
Authentication, authorization, and security posture
Operate 2
Status, limits, changes, and where to get help
Commercial 1
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API