# Socket

**Canonical:** https://apis.io/providers/socket-dev/  
**Website:** https://socket.dev/  
**APIs profiled:** 19

Socket is a developer-first supply-chain security platform that protects applications from malicious dependencies, vulnerable packages, license risk, and software-supply-chain attacks across npm, PyPI, Go, Maven, Cargo, NuGet, RubyGems, and other open-source ecosystems. Socket ships a hosted API, CLI, MCP server, Firewall package-installer proxy (sfw), GitHub App, IDE extensions, SDKs, and reusable integrations for Jira, Slack, GitHub, GitLab, Bitbucket, Azure DevOps, and Microsoft Teams. The Socket API exposes 70+ alert categories — malware, typo- squats, install scripts, telemetry, native code, crypto wallets, suspicious network activity, license issues — plus full-scan reports with SBOM export (CycloneDX, SPDX, OpenVEX), diff scans for pull requests, a triage workflow, webhooks, and a real-time threat feed of newly discovered malicious packages.

## Kin Score — 56.5 / 100 (strong)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 56.5).

| Facet | Score |
|---|---|
| Discoverability | 77.8 |
| Contract Quality | 67.6 |
| Governance | 26.5 |
| Contract Governance | 26.5 |
| Operational Transparency | 50.0 |
| Developer Ergonomics | 47.6 |
| Commercial Clarity | 63.2 |
| Access Clarity | 63.2 |

## Agent readiness — 48.3 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | verified |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | verified |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (19)

- **Socket alerts API** — The alerts API from Socket — 4 operation(s) for alerts.
- **Socket api-tokens API** — The api-tokens API from Socket — 6 operation(s) for api-tokens.
- **Socket audit-log API** — The audit-log API from Socket — 1 operation(s) for audit-log.
- **Socket dependencies API** — The dependencies API from Socket — 2 operation(s) for dependencies.
- **Socket diff-scans API** — The diff-scans API from Socket — 7 operation(s) for diff-scans.
- **Socket fixes API** — The fixes API from Socket — 1 operation(s) for fixes.
- **Socket full-scans API** — The full-scans API from Socket — 13 operation(s) for full-scans.
- **Socket license-policy API** — The license-policy API from Socket — 4 operation(s) for license-policy.
- **Socket metadata API** — The metadata API from Socket — 5 operation(s) for metadata.
- **Socket org-settings API** — The org-settings API from Socket — 2 operation(s) for org-settings.
- **Socket org-snapshots API** — The org-snapshots API from Socket — 1 operation(s) for org-snapshots.
- **Socket packages API** — The packages API from Socket — 2 operation(s) for packages.
- **Socket repo-labels API** — The repo-labels API from Socket — 5 operation(s) for repo-labels.
- **Socket repos API** — The repos API from Socket — 2 operation(s) for repos.
- **Socket security-policy API** — The security-policy API from Socket — 1 operation(s) for security-policy.
- **Socket telemetry API** — The telemetry API from Socket — 1 operation(s) for telemetry.
- **Socket threat-feed API** — The threat-feed API from Socket — 1 operation(s) for threat-feed.
- **Socket triage API** — The triage API from Socket — 2 operation(s) for triage.
- **Socket webhooks API** — The webhooks API from Socket — 2 operation(s) for webhooks.

## MCP servers (1)

- **Socket MCP Server** — Socket operates an official Model Context Protocol server. A public hosted server runs at https://mcp.socket.dev/ over HTTP with OAuth sign-in; a self-hosted stdio/HTTP build sh...

## Agentic access (1)

- **Socket Dev Agentic Access** — 81 operations · 41 acting · 1 human-in-the-loop

## Security (4)

- **Socket Dev Authentication** — http/oauth2 · 3 schemes
- **Socket Dev Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Socket Dev Vulnerability Disclosure** — security.txt · contact published
- **Socket Dev Trust Center** — SOC 2 Type I

## Plans (1)

- **Socket Dev Plans Pricing**

## Tags

Supply Chain Security, Open Source Security, Software Composition Analysis, SCA, Malware Detection, Dependency Scanning, SBOM, npm, PyPI, Go, Maven, Cargo, NuGet, RubyGems, Developer Security

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/socket-dev/). Scores are computed from the provider's own public artifacts under a published rubric.
