# OpenSSF

**Canonical:** https://apis.io/providers/openssf/  
**Website:** https://openssf.org/  
**APIs profiled:** 7

The Open Source Security Foundation (OpenSSF) is a collaborative initiative under the Linux Foundation dedicated to improving the security of open source software. It brings together industry leaders, developers, and security experts to address vulnerabilities, enhance supply chain security, and develop security tools and best practices. OpenSSF stewards a number of projects with public REST APIs, including the OSV (Open Source Vulnerabilities) database, the Scorecard automated security health-check service, and Sigstore signing infrastructure.

## Kin Score — 33.9 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 33.9).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 62.0 |
| Governance | 9.8 |
| Contract Governance | 9.8 |
| Operational Transparency | 10.5 |
| Developer Ergonomics | 26.2 |
| Commercial Clarity | 15.8 |
| Access Clarity | 15.8 |

## Agent readiness — 20.5 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium — onboarding: unknown, pricing: freemium, trial: no (confidence: medium).

## APIs (7)

- **Sigstore Public Good APIs** — Sigstore is an OpenSSF-hosted standard and service for signing, verifying, and protecting software. The public-good Sigstore instance exposes Fulcio (code-signing certificate au...
- **GUAC (Graph for Understanding Artifact Composition)** — GUAC aggregates software supply-chain security metadata (SBOMs, attestations, vulnerabilities, signatures) into a queryable graph. GUAC exposes a GraphQL API for supply-chain qu...
- **OpenSSF Projects API** — The Projects API from OpenSSF — 1 operation(s) for projects.
- **OpenSSF Query API** — The Query API from OpenSSF — 1 operation(s) for query.
- **OpenSSF Querybatch API** — The Querybatch API from OpenSSF — 1 operation(s) for querybatch.
- **OpenSSF V1experimental API** — The V1experimental API from OpenSSF — 2 operation(s) for v1experimental.
- **OpenSSF Vulns API** — The Vulns API from OpenSSF — 1 operation(s) for vulns.

## Agentic access (1)

- **Openssf Agentic Access** — 6 operations · 3 acting

## Security (1)

- **Openssf Domain Security** — TLSv1.3 · HSTS · DMARC

## Plans (1)

- **Openssf Plans Pricing**

## Tags

Linux Foundation, Open-Source, Security, Supply Chain, Vulnerabilities

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/openssf/). Scores are computed from the provider's own public artifacts under a published rubric.
