Packagist website screenshot

Packagist

Packagist is the default package repository for Composer, the PHP dependency manager. It indexes over 454,000 open-source PHP packages — versions, dependencies, maintainers, download statistics, security advisories — and exposes them through a free public HTTP API plus a high-throughput static Composer v2 metadata mirror at repo.packagist.org. Packagist is MIT-licensed open source (composer/packagist on GitHub) and is operated by the Composer team, with funding from Private Packagist (the commercial hosted/self-hosted sibling product at packagist.com) and infrastructure sponsorships from Bunny.net and Aikido. Together with the Composer CLI, the SemVer library, the SPDX licenses helper, and the Satis static repository generator, Packagist anchors PHP's modern software supply chain.

Packagist publishes 5 APIs on the APIs.io network, including Metadata API, Packages API, Search API, and 2 more. Tagged areas include Composer, PHP, Package Registry, Dependency Management, and Open Source.

The Packagist catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Packagist’s developer surface includes authentication, developer portal, documentation, tooling, signup flow, sandbox, engineering blog, and 33 more developer resources.

53.2/100 developing ▬ flat Agent 31/100 agent aware Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessPaidSelf serve
5 APIs 12 Features
ComposerPHPPackage RegistryDependency ManagementOpen SourceDeveloper ToolsSoftware Supply ChainSecurity Advisories

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 53.2/100 · developing
Contract Quality 17.5 / 25
Developer Ergonomics 7.4 / 20
Commercial Clarity 13.2 / 20
Operational Transparency 0.7 / 13
Governance 7.0 / 12
Discoverability 7.4 / 10
Agent readiness — 31/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/packagist: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 5

Individual APIs this provider publishes, each with its own machine-readable definition.

Packagist Metadata API

Composer v2 static metadata and change tracking.

Packagist Packages API

Discover and manage Composer packages.

Packagist Search API

Search the Packagist registry.

Packagist Security API

PHP security advisory database.

Packagist Statistics API

Download and registry statistics.

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Packagist API

OPEN COLLECTION

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Packagist Rate Limits

0 limits

RATE LIMITS

Features 12

Notable capabilities this provider offers.

454,128 packages, 5.58 million versions, 181 billion+ installs since April 2012
Default Composer package repository for the PHP ecosystem
Static Composer v2 metadata mirror at repo.packagist.org with long-lived caching
Bearer token auth with SAFE (read/update) and MAIN (create/edit) token classes
24-hour rolling change feed for mirror operators and dependency scanners
Security advisories API aggregating FriendsOfPHP, GitHub Advisory Database, and PSA sources
Webhook-driven auto-updates from GitHub, Bitbucket, GitLab, and Gitea
Algolia-powered package search across name, tags, and type
Per-package and per-version download statistics
Commercial sibling Private Packagist for private/hosted/self-hosted Composer repositories
MIT-licensed open source codebase (composer/packagist) — operated, not designed for reuse
Funded by Private Packagist subscriptions plus Bunny.net (CDN) and Aikido (security) sponsorships

Scroll for all 12

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Packagist Context

35 classes · 4 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Packagist API Rules

5 rules · 3 warnings 2 info

SPECTRAL

Packagist API Rules

5 rules · 1 errors 3 warnings 1 info

SPECTRAL

JSON Schema 2

Standalone JSON Schema definitions for this provider's data models.

Packagist Package

20 properties

JSON SCHEMA

Packagist Security Advisory

11 properties

JSON SCHEMA

JSON Structure 1

JSON Structure definitions describing this provider's data shapes.

Packagist Package Structure

0 properties

JSON STRUCTURE

Examples 3

Example request and response payloads for these APIs.

Packagist Search Example

2 fields

EXAMPLE

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Packagist Authentication

http · 1 scheme

SECURITY

Packagist Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Packagist Agentic Access

13 operations · 3 acting

13 operations · 3 acting

AGENTIC

Resources

Get Started 4

Portal, sign-up, and the first successful call

Documentation 6

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Build 12

SDKs, sample code, and the tooling you integrate with

Scroll for all 12

Access & Security 6

Authentication, authorization, and security posture

Operate 3

Status, limits, changes, and where to get help

Commercial 4

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 2

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: packagist
url: https://raw.githubusercontent.com/api-evangelist/packagist/refs/heads/main/apis.yml
apis:
- aid: packagist:packagist-metadata-api
  name: Packagist Metadata API
  description: Composer v2 static metadata and change tracking.
  humanURL: https://packagist.org/apidoc
  baseURL: https://packagist.org
  tags:
  - Metadata
  properties:
  - type: OpenAPI
    url: openapi/packagist-metadata-api-openapi.yml
  - type: Documentation
    url: https://packagist.org/apidoc
  - type: BaseURL
    url: https://repo.packagist.org/
  - type: JSONSchema
    url: json-schema/packagist-package-schema.json
  - type: JSONSchema
    url: json-schema/packagist-security-advisory-schema.json
  - type: JSONStructure
    url: json-structure/packagist-package-structure.json
  - type: JSONLD
    url: json-ld/packagist-context.jsonld
  - type: SpectralRules
    url: rules/packagist-rules.yml
  - type: Vocabulary
    url: vocabulary/packagist-vocabulary.yml
  - type: Examples
    url: examples/packagist-search-example.json
  - type: Examples
    url: examples/packagist-get-package-example.json
  - type: Examples
    url: examples/packagist-security-advisories-example.json
- aid: packagist:packagist-packages-api
  name: Packagist Packages API
  description: Discover and manage Composer packages.
  humanURL: https://packagist.org/apidoc
  baseURL: https://packagist.org
  tags:
  - Packages
  properties:
  - type: OpenAPI
    url: openapi/packagist-packages-api-openapi.yml
  - type: Documentation
    url: https://packagist.org/apidoc
  - type: BaseURL
    url: https://repo.packagist.org/
  - type: JSONSchema
    url: json-schema/packagist-package-schema.json
  - type: JSONSchema
    url: json-schema/packagist-security-advisory-schema.json
  - type: JSONStructure
    url: json-structure/packagist-package-structure.json
  - type: JSONLD
    url: json-ld/packagist-context.jsonld
  - type: SpectralRules
    url: rules/packagist-rules.yml
  - type: Vocabulary
    url: vocabulary/packagist-vocabulary.yml
  - type: Examples
    url: examples/packagist-search-example.json
  - type: Examples
    url: examples/packagist-get-package-example.json
  - type: Examples
    url: examples/packagist-security-advisories-example.json
- aid: packagist:packagist-search-api
  name: Packagist Search API
  description: Search the Packagist registry.
  humanURL: https://packagist.org/apidoc
  baseURL: https://packagist.org
  tags:
  - Search
  properties:
  - type: OpenAPI
    url: openapi/packagist-search-api-openapi.yml
  - type: Documentation
    url: https://packagist.org/apidoc
  - type: BaseURL
    url: https://repo.packagist.org/
  - type: JSONSchema
    url: json-schema/packagist-package-schema.json
  - type: JSONSchema
    url: json-schema/packagist-security-advisory-schema.json
  - type: JSONStructure
    url: json-structure/packagist-package-structure.json
  - type: JSONLD
    url: json-ld/packagist-context.jsonld
  - type: SpectralRules
    url: rules/packagist-rules.yml
  - type: Vocabulary
    url: vocabulary/packagist-vocabulary.yml
  - type: Examples
    url: examples/packagist-search-example.json
  - type: Examples
    url: examples/packagist-get-package-example.json
  - type: Examples
    url: examples/packagist-security-advisories-example.json
- aid: packagist:packagist-security-api
  name: Packagist Security API
  description: PHP security advisory database.
  humanURL: https://packagist.org/apidoc
  baseURL: https://packagist.org
  tags:
  - Security
  properties:
  - type: OpenAPI
    url: openapi/packagist-security-api-openapi.yml
  - type: Documentation
    url: https://packagist.org/apidoc
  - type: BaseURL
    url: https://repo.packagist.org/
  - type: JSONSchema
    url: json-schema/packagist-package-schema.json
  - type: JSONSchema
    url: json-schema/packagist-security-advisory-schema.json
  - type: JSONStructure
    url: json-structure/packagist-package-structure.json
  - type: JSONLD
    url: json-ld/packagist-context.jsonld
  - type: SpectralRules
    url: rules/packagist-rules.yml
  - type: Vocabulary
    url: vocabulary/packagist-vocabulary.yml
  - type: Examples
    url: examples/packagist-search-example.json
  - type: Examples
    url: examples/packagist-get-package-example.json
  - type: Examples
    url: examples/packagist-security-advisories-example.json
- aid: packagist:packagist-statistics-api
  name: Packagist Statistics API
  description: Download and registry statistics.
  humanURL: https://packagist.org/apidoc
  baseURL: https://packagist.org
  tags:
  - Statistics
  properties:
  - type: OpenAPI
    url: openapi/packagist-statistics-api-openapi.yml
  - type: Documentation
    url: https://packagist.org/apidoc
  - type: BaseURL
    url: https://repo.packagist.org/
  - type: JSONSchema
    url: json-schema/packagist-package-schema.json
  - type: JSONSchema
    url: json-schema/packagist-security-advisory-schema.json
  - type: JSONStructure
    url: json-structure/packagist-package-structure.json
  - type: JSONLD
    url: json-ld/packagist-context.jsonld
  - type: SpectralRules
    url: rules/packagist-rules.yml
  - type: Vocabulary
    url: vocabulary/packagist-vocabulary.yml
  - type: Examples
    url: examples/packagist-search-example.json
  - type: Examples
    url: examples/packagist-get-package-example.json
  - type: Examples
    url: examples/packagist-security-advisories-example.json
name: Packagist
tags:
- Composer
- PHP
- Package Registry
- Dependency Management
- Open Source
- Developer Tools
- Software Supply Chain
- Security Advisories
kind: registry
accessModel:
  pricing: paid
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Paid · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/packagist.png
access: 3rd-Party
common:
- type: AgenticAccess
  url: agentic-access/packagist-agentic-access.yml
- type: DomainSecurity
  url: security/packagist-domain-security.yml
- type: Authentication
  url: authentication/packagist-authentication.yml
- type: Portal
  url: https://packagist.org
- type: Documentation
  url: https://packagist.org/apidoc
- type: Documentation
  url: https://getcomposer.org/doc/
  name: Composer Documentation
- type: About
  url: https://packagist.org/about
- type: Statistics
  url: https://packagist.org/statistics
- type: GitHubOrganization
  url: https://github.com/composer
- type: GitHubRepository
  url: https://github.com/composer/packagist
  name: composer/packagist (source)
- type: GitHubRepository
  url: https://github.com/composer/composer
  name: composer/composer (CLI / resolver)
- type: GitHubRepository
  url: https://github.com/composer/satis
  name: composer/satis (static repo generator)
- type: GitHubRepository
  url: https://github.com/composer/semver
  name: composer/semver
- type: GitHubRepository
  url: https://github.com/composer/spdx-licenses
  name: composer/spdx-licenses
- type: GitHubRepository
  url: https://github.com/composer/class-map-generator
  name: composer/class-map-generator
- type: GitHubRepository
  url: https://github.com/composer/ca-bundle
  name: composer/ca-bundle
- type: GitHubRepository
  url: https://github.com/composer/api-surface-check
  name: composer/api-surface-check
- type: GitHubRepository
  url: https://github.com/composer/docker
  name: composer/docker
- type: Tools
  url: https://getcomposer.org/
  name: Composer (PHP Dependency Manager)
- type: Tools
  url: https://github.com/composer/satis
  name: Satis (static Composer repo generator)
- type: Documentation
  url: https://getcomposer.org/doc/01-basic-usage.md
  name: Composer Basic Usage
- type: Documentation
  url: https://getcomposer.org/doc/04-schema.md
  name: composer.json Schema
- type: Documentation
  url: https://getcomposer.org/doc/articles/versions.md
  name: Composer Version Constraints
- type: Documentation
  url: https://packagist.org/about#how-to-update-packages
  name: Updating Packages
- type: Authentication
  url: https://packagist.org/apidoc#authentication
  name: API Authentication
- type: Signup
  url: https://packagist.org/register/
- type: Login
  url: https://packagist.org/login/
- type: APIKeys
  url: https://packagist.org/profile/
  name: User Profile (API Tokens)
- type: SecurityAdvisories
  url: https://packagist.org/apidoc#list-security-advisories
- type: SecurityAdvisories
  url: https://github.com/FriendsOfPHP/security-advisories
  name: FriendsOfPHP/security-advisories
- type: Mirror
  url: https://packagist.org/mirrors
  name: Packagist Mirrors
- type: Sandbox
  url: https://packagist.com
  name: Private Packagist (commercial sibling)
- type: PrivacyPolicy
  url: https://packagist.com/privacy
- type: TermsOfService
  url: https://packagist.com/terms-of-service
- type: License
  url: https://github.com/composer/packagist/blob/main/LICENSE
  name: MIT License
- type: Blog
  url: https://blog.packagist.com/
- type: Forums
  url: https://github.com/composer/packagist/discussions
- type: Issues
  url: https://github.com/composer/packagist/issues
- type: Plans
  url: plans/packagist-plans-pricing.yml
- type: RateLimits
  url: rate-limits/packagist-rate-limits.yml
- type: Features
  data:
  - 454,128 packages, 5.58 million versions, 181 billion+ installs since April 2012
  - Default Composer package repository for the PHP ecosystem
  - Static Composer v2 metadata mirror at repo.packagist.org with long-lived caching
  - Bearer token auth with SAFE (read/update) and MAIN (create/edit) token classes
  - 24-hour rolling change feed for mirror operators and dependency scanners
  - Security advisories API aggregating FriendsOfPHP, GitHub Advisory Database, and PSA sources
  - Webhook-driven auto-updates from GitHub, Bitbucket, GitLab, and Gitea
  - Algolia-powered package search across name, tags, and type
  - Per-package and per-version download statistics
  - Commercial sibling Private Packagist for private/hosted/self-hosted Composer repositories
  - MIT-licensed open source codebase (composer/packagist) — operated, not designed for reuse
  - Funded by Private Packagist subscriptions plus Bunny.net (CDN) and Aikido (security) sponsorships
  sources:
  - https://packagist.org/apidoc
  - https://packagist.org/about
  - https://packagist.org/statistics
  - https://github.com/composer/packagist
  - https://packagist.com/pricing
  updated: '2026-05-25'
created: '2026-05-25T00:00:00.000Z'
modified: '2026-05-25'
position: Providing
description: 'Packagist is the default package repository for Composer, the PHP dependency manager. It indexes

  over 454,000 open-source PHP packages — versions, dependencies, maintainers, download statistics,

  security advisories — and exposes them through a free public HTTP API plus a high-throughput static

  Composer v2 metadata mirror at repo.packagist.org. Packagist is MIT-licensed open source (composer/packagist

  on GitHub) and is operated by the Composer team, with funding from Private Packagist (the commercial

  hosted/self-hosted sibling product at packagist.com) and infrastructure sponsorships from Bunny.net

  and Aikido. Together with the Composer CLI, the SemVer library, the SPDX licenses helper, and the

  Satis static repository generator, Packagist anchors PHP''s modern software supply chain.

  '
maintainers:
- FN: Kin Lane
  email: info@apievangelist.com
  X: apievangelist
  url: https://apievangelist.com
specificationVersion: '0.16'