# Socket

**Canonical:** https://apis.io/providers/socket/  
**Website:** https://socket.dev  
**APIs profiled:** 20

Socket is a developer-first software supply chain security platform that protects applications from supply chain attacks by deeply inspecting open source dependencies across npm, PyPI, Maven, Go, NuGet, RubyGems, Cargo and more. Socket detects malware, hidden code, typosquats, install scripts, protestware, and risky capabilities in packages, scores their quality and risk, and enforces security and license policies across repositories through a REST API, CLI, GitHub App, MCP server, and static reachability analysis. Founded by Feross Aboukhadijeh and backed by a16z, Socket is used by engineering teams at organizations including Vercel, Replit, and Brave.

## Kin Score — 54.4 / 100 (developing)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 54.4).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 67.2 |
| Governance | 11.5 |
| Operational Transparency | 63.2 |
| Developer Ergonomics | 75.5 |
| Commercial Clarity | 23.7 |

## Agent readiness — 57.4 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | yes |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | verified |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (20)

- **Socket alerts API** — The alerts API from Socket — 6 operation(s) for alerts.
- **Socket api-tokens API** — The api-tokens API from Socket — 6 operation(s) for api-tokens.
- **Socket audit-log API** — The audit-log API from Socket — 1 operation(s) for audit-log.
- **Socket dependencies API** — The dependencies API from Socket — 2 operation(s) for dependencies.
- **Socket deprecated API** — The deprecated API from Socket — 17 operation(s) for deprecated.
- **Socket diff-scans API** — The diff-scans API from Socket — 7 operation(s) for diff-scans.
- **Socket fixes API** — The fixes API from Socket — 1 operation(s) for fixes.
- **Socket full-scans API** — The full-scans API from Socket — 13 operation(s) for full-scans.
- **Socket license-policy API** — The license-policy API from Socket — 4 operation(s) for license-policy.
- **Socket metadata API** — The metadata API from Socket — 5 operation(s) for metadata.
- **Socket org-settings API** — The org-settings API from Socket — 2 operation(s) for org-settings.
- **Socket org-snapshots API** — The org-snapshots API from Socket — 1 operation(s) for org-snapshots.
- **Socket packages API** — The packages API from Socket — 2 operation(s) for packages.
- **Socket repo-labels API** — The repo-labels API from Socket — 5 operation(s) for repo-labels.
- **Socket repos API** — The repos API from Socket — 2 operation(s) for repos.
- **Socket security-policy API** — The security-policy API from Socket — 1 operation(s) for security-policy.
- **Socket telemetry API** — The telemetry API from Socket — 1 operation(s) for telemetry.
- **Socket threat-feed API** — The threat-feed API from Socket — 1 operation(s) for threat-feed.
- **Socket triage API** — The triage API from Socket — 2 operation(s) for triage.
- **Socket webhooks API** — The webhooks API from Socket — 2 operation(s) for webhooks.

## MCP servers (1)

- **Socket MCP Server** — Socket's official MCP server exposes the depscore tool so AI assistants can query dependency scores from the Socket API; hosted at https://mcp.socket.dev/ or run locally.

## Agentic access (1)

- **Socket Agentic Access** — 96 operations · 44 acting · 1 human-in-the-loop

## Security (3)

- **Socket Authentication** — http · 2 schemes
- **Socket Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Socket Vulnerability Disclosure** — security.txt · contact published

## Tags

Company, Security, Software Supply Chain Security, Dependency Scanning, Software Composition Analysis, Vulnerability Management, Open Source Security, DevSecOps, SBOM, Package Analysis

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/socket/). Scores are computed from the provider's own public artifacts under a published rubric.
