Socket

Socket is a developer-first software supply chain security platform that protects applications from supply chain attacks by deeply inspecting open source dependencies across npm, PyPI, Maven, Go, NuGet, RubyGems, Cargo and more. Socket detects malware, hidden code, typosquats, install scripts, protestware, and risky capabilities in packages, scores their quality and risk, and enforces security and license policies across repositories through a REST API, CLI, GitHub App, MCP server, and static reachability analysis. Founded by Feross Aboukhadijeh and backed by a16z, Socket is used by engineering teams at organizations including Vercel, Replit, and Brave.

Socket publishes 20 APIs on the APIs.io network, including alerts API, api-tokens API, audit-log API, and 17 more. Tagged areas include Company, Security, Software Supply Chain Security, Dependency Scanning, and Software Composition Analysis.

The Socket catalog on APIs.io includes 1 event-driven AsyncAPI specification.

Socket’s developer surface includes documentation, getting-started guide, API reference, support, authentication, changelog, CLI, and 27 more developer resources.

55.0/100 developing ▬ flat Agent 85/100 agent native Full breakdown ↓
scored 2026-07-27 · rubric v0.5
AccessSelf serve
20 APIs 1 MCP Servers
CompanySecuritySoftware Supply Chain SecurityDependency ScanningSoftware Composition AnalysisVulnerability ManagementOpen Source SecurityDevSecOpsSBOMPackage Analysis

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 55.0/100 · developing
Contract Quality 15.9 / 25
Developer Ergonomics 16.1 / 20
Commercial Clarity 4.7 / 20
Operational Transparency 8.2 / 13
Governance 0.0 / 12
Discoverability 10.0 / 10
Agent readiness — 85/100 · agent native
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 6 / 6
Agent Skills 5 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 3 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/socket: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 20

Individual APIs this provider publishes, each with its own machine-readable definition.

Socket alerts API

The alerts API from Socket — 6 operation(s) for alerts.

Socket api-tokens API

The api-tokens API from Socket — 6 operation(s) for api-tokens.

Socket audit-log API

The audit-log API from Socket — 1 operation(s) for audit-log.

Socket dependencies API

The dependencies API from Socket — 2 operation(s) for dependencies.

Socket deprecated API

The deprecated API from Socket — 17 operation(s) for deprecated.

Socket diff-scans API

The diff-scans API from Socket — 7 operation(s) for diff-scans.

Socket fixes API

The fixes API from Socket — 1 operation(s) for fixes.

Socket full-scans API

The full-scans API from Socket — 13 operation(s) for full-scans.

Socket license-policy API

The license-policy API from Socket — 4 operation(s) for license-policy.

Socket metadata API

The metadata API from Socket — 5 operation(s) for metadata.

Socket org-settings API

The org-settings API from Socket — 2 operation(s) for org-settings.

Socket org-snapshots API

The org-snapshots API from Socket — 1 operation(s) for org-snapshots.

Socket packages API

The packages API from Socket — 2 operation(s) for packages.

Socket repo-labels API

The repo-labels API from Socket — 5 operation(s) for repo-labels.

Socket repos API

The repos API from Socket — 2 operation(s) for repos.

Socket security-policy API

The security-policy API from Socket — 1 operation(s) for security-policy.

Socket telemetry API

The telemetry API from Socket — 1 operation(s) for telemetry.

Socket threat-feed API

The threat-feed API from Socket — 1 operation(s) for threat-feed.

Socket triage API

The triage API from Socket — 2 operation(s) for triage.

Socket webhooks API

The webhooks API from Socket — 2 operation(s) for webhooks.

Scroll for all 20

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

Socket MCP Server

Socket's official MCP server exposes the depscore tool so AI assistants can query dependency scores from the Socket API; hosted at https://mcp.socket.dev/ or run locally.

MCP SERVER

Rate Limits 1

Documented rate limits and quota policies.

Socket Rate Limits

0 limits

RATE LIMITS

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Socket Webhooks

ASYNCAPI

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Socket Authentication

http · 2 schemes

SECURITY

Socket Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Socket Vulnerability Disclosure

security.txt · contact published

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Socket Scopes

34 scopes

34 scopes

SCOPES

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Socket Agentic Access

96 operations · 44 acting · 1 human-in-the-loop

96 operations · 44 acting

AGENTIC

Resources

Get Started 3

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 5

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 6

Pagination, idempotency, versioning, errors, and events

Build 4

SDKs, sample code, and the tooling you integrate with

Access & Security 6

Authentication, authorization, and security posture

Operate 5

Status, limits, changes, and where to get help

Commercial 1

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: socket
name: Socket
description: Socket is a developer-first software supply chain security platform that protects applications from supply chain
  attacks by deeply inspecting open source dependencies across npm, PyPI, Maven, Go, NuGet, RubyGems, Cargo and more. Socket
  detects malware, hidden code, typosquats, install scripts, protestware, and risky capabilities in packages, scores their
  quality and risk, and enforces security and license policies across repositories through a REST API, CLI, GitHub App, MCP
  server, and static reachability analysis. Founded by Feross Aboukhadijeh and backed by a16z, Socket is used by engineering
  teams at organizations including Vercel, Replit, and Brave.
accessModel:
  pricing: unknown
  onboarding: self-serve
  trial: false
  try_now: false
  public: false
  label: Self-serve signup
  confidence: medium
  source:
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://socket.dev/favicon.ico
url: https://raw.githubusercontent.com/api-evangelist/socket/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- a16z
x-tier: stub
x-tier-reason: portfolio-lead
x-enrichment:
  date: '2026-07-21'
  status: enriched
  artifacts_added: 26
  pass: local-v1
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-21'
tags:
- Company
- Security
- Software Supply Chain Security
- Dependency Scanning
- Software Composition Analysis
- Vulnerability Management
- Open Source Security
- DevSecOps
- SBOM
- Package Analysis
apis:
- aid: socket:socket-alerts-api
  name: Socket alerts API
  description: The alerts API from Socket — 6 operation(s) for alerts.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - alerts
  properties:
  - type: OpenAPI
    url: openapi/socket-alerts-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-api-tokens-api
  name: Socket api-tokens API
  description: The api-tokens API from Socket — 6 operation(s) for api-tokens.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - api-tokens
  properties:
  - type: OpenAPI
    url: openapi/socket-api-tokens-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-audit-log-api
  name: Socket audit-log API
  description: The audit-log API from Socket — 1 operation(s) for audit-log.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - audit-log
  properties:
  - type: OpenAPI
    url: openapi/socket-audit-log-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-dependencies-api
  name: Socket dependencies API
  description: The dependencies API from Socket — 2 operation(s) for dependencies.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - dependencies
  properties:
  - type: OpenAPI
    url: openapi/socket-dependencies-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-deprecated-api
  name: Socket deprecated API
  description: The deprecated API from Socket — 17 operation(s) for deprecated.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - deprecated
  properties:
  - type: OpenAPI
    url: openapi/socket-deprecated-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-diff-scans-api
  name: Socket diff-scans API
  description: The diff-scans API from Socket — 7 operation(s) for diff-scans.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - diff-scans
  properties:
  - type: OpenAPI
    url: openapi/socket-diff-scans-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-fixes-api
  name: Socket fixes API
  description: The fixes API from Socket — 1 operation(s) for fixes.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - fixes
  properties:
  - type: OpenAPI
    url: openapi/socket-fixes-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-full-scans-api
  name: Socket full-scans API
  description: The full-scans API from Socket — 13 operation(s) for full-scans.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - full-scans
  properties:
  - type: OpenAPI
    url: openapi/socket-full-scans-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-license-policy-api
  name: Socket license-policy API
  description: The license-policy API from Socket — 4 operation(s) for license-policy.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - license-policy
  properties:
  - type: OpenAPI
    url: openapi/socket-license-policy-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-metadata-api
  name: Socket metadata API
  description: The metadata API from Socket — 5 operation(s) for metadata.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - metadata
  properties:
  - type: OpenAPI
    url: openapi/socket-metadata-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-org-settings-api
  name: Socket org-settings API
  description: The org-settings API from Socket — 2 operation(s) for org-settings.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - org-settings
  properties:
  - type: OpenAPI
    url: openapi/socket-org-settings-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-org-snapshots-api
  name: Socket org-snapshots API
  description: The org-snapshots API from Socket — 1 operation(s) for org-snapshots.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - org-snapshots
  properties:
  - type: OpenAPI
    url: openapi/socket-org-snapshots-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-packages-api
  name: Socket packages API
  description: The packages API from Socket — 2 operation(s) for packages.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - packages
  properties:
  - type: OpenAPI
    url: openapi/socket-packages-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-repo-labels-api
  name: Socket repo-labels API
  description: The repo-labels API from Socket — 5 operation(s) for repo-labels.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - repo-labels
  properties:
  - type: OpenAPI
    url: openapi/socket-repo-labels-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-repos-api
  name: Socket repos API
  description: The repos API from Socket — 2 operation(s) for repos.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - repos
  properties:
  - type: OpenAPI
    url: openapi/socket-repos-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-security-policy-api
  name: Socket security-policy API
  description: The security-policy API from Socket — 1 operation(s) for security-policy.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - security-policy
  properties:
  - type: OpenAPI
    url: openapi/socket-security-policy-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-telemetry-api
  name: Socket telemetry API
  description: The telemetry API from Socket — 1 operation(s) for telemetry.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - telemetry
  properties:
  - type: OpenAPI
    url: openapi/socket-telemetry-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-threat-feed-api
  name: Socket threat-feed API
  description: The threat-feed API from Socket — 1 operation(s) for threat-feed.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - threat-feed
  properties:
  - type: OpenAPI
    url: openapi/socket-threat-feed-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-triage-api
  name: Socket triage API
  description: The triage API from Socket — 2 operation(s) for triage.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - triage
  properties:
  - type: OpenAPI
    url: openapi/socket-triage-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
- aid: socket:socket-webhooks-api
  name: Socket webhooks API
  description: The webhooks API from Socket — 2 operation(s) for webhooks.
  humanURL: https://docs.socket.dev
  baseURL: https://api.socket.dev/v0
  tags:
  - webhooks
  properties:
  - type: OpenAPI
    url: openapi/socket-webhooks-api-openapi.yml
  - type: Documentation
    url: https://docs.socket.dev/docs/getting-started
  - type: APIReference
    url: https://docs.socket.dev/reference/authentication
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: VulnerabilityDisclosure
  url: security/socket-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/socket-domain-security.yml
- type: AgenticAccess
  url: agentic-access/socket-agentic-access.yml
- type: Website
  url: https://socket.dev
- type: DeveloperPortal
  url: https://docs.socket.dev
- type: Documentation
  url: https://docs.socket.dev/docs/getting-started
- type: GettingStarted
  url: https://docs.socket.dev/docs/getting-started
- type: APIReference
  url: https://docs.socket.dev/reference/authentication
- type: Support
  url: https://docs.socket.dev/docs/contact-support
- type: GitHubOrganization
  url: https://github.com/SocketDev
- type: LLMsTxt
  url: llms/socket-llms.txt
- type: Authentication
  url: authentication/socket-authentication.yml
- type: OAuthScopes
  url: scopes/socket-scopes.yml
- type: Conventions
  url: conventions/socket-conventions.yml
- type: RateLimits
  url: rate-limits/socket-rate-limits.yml
- type: ErrorCatalog
  url: errors/socket-problem-types.yml
- type: DataModel
  url: data-model/socket-data-model.yml
- type: Conformance
  url: conformance/socket-conformance.yml
- type: Lifecycle
  url: lifecycle/socket-lifecycle.yml
- type: Deprecation
  url: https://docs.socket.dev/reference/api-lifecycle-and-deprecation-process
- type: StatusPage
  url: https://status.socket.dev
- type: ChangeLog
  url: changelog/socket-changelog.yml
- type: CLI
  url: cli/socket-cli.yml
- type: Packages
  url: packages/socket-packages.yml
- type: SDKs
  url: packages/socket-packages.yml
- type: MCPServer
  url: https://mcp.socket.dev/
  name: Socket MCP Server
  description: Socket's official MCP server exposes the depscore tool so AI assistants can query dependency scores from the
    Socket API; hosted at https://mcp.socket.dev/ or run locally.
- type: Webhooks
  url: asyncapi/socket-webhooks.yml
- type: AgentSkill
  url: skills/_index.yml
- type: SecurityTxt
  url: well-known/socket-security.txt
- type: WellKnown
  url: well-known/socket-well-known.yml
- type: Security
  url: https://socket.dev/security/disclosure
- type: Blog
  url: https://socket.dev/blog
- type: Pricing
  url: https://socket.dev/pricing
- type: Login
  url: https://socket.dev/login