# Root (fka Slim.ai)

**Canonical:** https://apis.io/providers/root-fka-slimai/  
**Website:** https://www.root.io/  
**APIs profiled:** 20

Root (formerly Slim.ai) is a container and dependency security company backed by Insight Partners. Its "secure supply" platform delivers end-to-end, autonomous vulnerability remediation for container images and application packages: a fleet of AI agents (Agentic Vulnerability Remediation, AVR) researches, patches, tests, and ships Root Patches within minutes of CVE publication, without base-image changes or forced version upgrades. Root operates the Root Image Catalog (cr.root.io), Library Catalog, and OS-package registry (pkg.root.io), and exposes a REST API (api.root.io) for querying patch status, security findings, subscriptions, and pulling SBOM, VEX, and provenance artifacts, plus Standard-Webhooks notifications and a first-party CLI (rootio_patcher).

## Kin Score — 51.7 / 100 (developing)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 51.7).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 58.7 |
| Governance | 20.8 |
| Operational Transparency | 39.5 |
| Developer Ergonomics | 56.0 |
| Commercial Clarity | 50.0 |

## Agent readiness — 43.5 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | derived |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (20)

- **Root (fka Slim.ai) Accounts API** — The Accounts API from Root (fka Slim.ai) — 3 operation(s) for accounts.
- **Root (fka Slim.ai) API Keys API** — The API Keys API from Root (fka Slim.ai) — 2 operation(s) for api keys.
- **Root (fka Slim.ai) Authentication API** — The Authentication API from Root (fka Slim.ai) — 1 operation(s) for authentication.
- **Root (fka Slim.ai) AVR API** — The AVR API from Root (fka Slim.ai) — 6 operation(s) for avr.
- **Root (fka Slim.ai) Billing API** — The Billing API from Root (fka Slim.ai) — 1 operation(s) for billing.
- **Root (fka Slim.ai) Core - Discovered Packages V3 API** — The Core - Discovered Packages V3 API from Root (fka Slim.ai) — 1 operation(s) for core - discovered packages v3.
- **Root (fka Slim.ai) CveFeed API** — The CveFeed API from Root (fka Slim.ai) — 1 operation(s) for cvefeed.
- **Root (fka Slim.ai) Discovery API** — The Discovery API from Root (fka Slim.ai) — 2 operation(s) for discovery.
- **Root (fka Slim.ai) Invitations API** — The Invitations API from Root (fka Slim.ai) — 3 operation(s) for invitations.
- **Root (fka Slim.ai) Notifications API** — The Notifications API from Root (fka Slim.ai) — 4 operation(s) for notifications.
- **Root (fka Slim.ai) Organizations API** — The Organizations API from Root (fka Slim.ai) — 1 operation(s) for organizations.
- **Root (fka Slim.ai) OSVFeed API** — The OSVFeed API from Root (fka Slim.ai) — 3 operation(s) for osvfeed.
- **Root (fka Slim.ai) Package API** — The Package API from Root (fka Slim.ai) — 4 operation(s) for package.
- **Root (fka Slim.ai) Patches API** — The Patches API from Root (fka Slim.ai) — 3 operation(s) for patches.
- **Root (fka Slim.ai) PatchFeed API** — The PatchFeed API from Root (fka Slim.ai) — 1 operation(s) for patchfeed.
- **Root (fka Slim.ai) Remediation API** — The Remediation API from Root (fka Slim.ai) — 10 operation(s) for remediation.
- **Root (fka Slim.ai) Security Findings API** — The Security Findings API from Root (fka Slim.ai) — 4 operation(s) for security findings.
- **Root (fka Slim.ai) Subscriptions API** — The Subscriptions API from Root (fka Slim.ai) — 2 operation(s) for subscriptions.
- **Root (fka Slim.ai) System Matrix API** — The System Matrix API from Root (fka Slim.ai) — 2 operation(s) for system matrix.
- **Root (fka Slim.ai) Webhooks API** — The Webhooks API from Root (fka Slim.ai) — 3 operation(s) for webhooks.

## MCP servers (1)

- **root-fka-slimai-mcp.yml**

## Agentic access (1)

- **Root Fka Slimai Agentic Access** — 69 operations · 31 acting

## Security (4)

- **Root Fka Slimai Authentication** — http · 2 schemes
- **Root Fka Slimai Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Root Fka Slimai Vulnerability Disclosure** — contact published
- **Root Fka Slimai Trust Center** — SOC 2 Type II, Cyber Essentials, SLSA, FIPS 140-3, STIG

## Tags

Company, Security, Vulnerability Management, Container Security, DevSecOps, Software Supply Chain, CVE, SBOM, Open Source, Patching

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/root-fka-slimai/). Scores are computed from the provider's own public artifacts under a published rubric.
