Sourcemap

Sourcemap is an enterprise supply chain transparency and due diligence software company, founded at the MIT Media Lab by Leonardo Bonanni and headquartered in New York. Its platform performs n-tier supply chain mapping, automated sub-supplier discovery, bill-of-materials mapping, transaction-level chain-of-custody traceability, supplier watchlist screening and AI document review, so that brands and manufacturers can meet regulatory obligations including the EU Deforestation Regulation (EUDR), the Uyghur Forced Labor Prevention Act (UFLPA), the Corporate Sustainability Due Diligence Directive (CSDDD), CTPAT, conflict minerals rules and Section 232 tariff and customs enforcement. Sourcemap describes a real-time RESTful API and a data pipeline that moves structured data in both directions with SAP, Salesforce Net Zero Cloud, Databricks and the EU TRACES customs portal, but that API is sold and provisioned as part of an enterprise engagement: there is no public developer portal, no published API reference, no pricing page and no machine-readable contract on any Sourcemap host. Customers include Ferrero, Hershey, Woolworths and AG1.

Sourcemap publishes 1 API on the APIs.io network. Tagged areas include Company, Supply Chain, Traceability, Supply Chain Transparency, and Due Diligence.

Sourcemap’s developer surface includes engineering blog, support, and 12 more developer resources.

18.0/100 emerging ▬ flat Agent 9/100 agent aware saas Full breakdown ↓
scored 2026-09-01 · rubric v0.17.2
1 APIs
CompanySupply ChainTraceabilitySupply Chain TransparencyDue DiligenceRegulatory ComplianceESGSustainabilityRisk ManagementLogisticsManufacturing

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-01 · rubric v0.17.2
Composite quality — 18.0/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 1.4 / 20
Access Clarity 5.8 / 20
Operational Transparency 1.0 / 13
Contract Governance 2.2 / 12
Discoverability 7.6 / 10
Agent readiness — 9/100 · agent aware
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 10
Documented Reversibility 0 / 6
MCP Server 12 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Delegated User Identity 0 / 6
Protected Resource Metadata 0 / 5
Registration Without a Human 0 / 6
Agentic Commerce Surface 0 / 5
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/sourcemap: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

Sourcemap Platform API

Sourcemap describes a secure real-time RESTful API used to integrate the traceability platform with ERP and enterprise data stacks (SAP, Salesforce Net Zero Cloud, Databricks) a...

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Sourcemap Rate Limits

0 limits

RATE LIMITS

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Sourcemap Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Resources

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 2

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Operate 3

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: sourcemap
name: Sourcemap
description: 'Sourcemap is an enterprise supply chain transparency and due diligence software company, founded at the MIT
  Media Lab by Leonardo Bonanni and headquartered in New York. Its platform performs n-tier supply chain mapping, automated
  sub-supplier discovery, bill-of-materials mapping, transaction-level chain-of-custody traceability, supplier watchlist screening
  and AI document review, so that brands and manufacturers can meet regulatory obligations including the EU Deforestation
  Regulation (EUDR), the Uyghur Forced Labor Prevention Act (UFLPA), the Corporate Sustainability Due Diligence Directive
  (CSDDD), CTPAT, conflict minerals rules and Section 232 tariff and customs enforcement. Sourcemap describes a real-time
  RESTful API and a data pipeline that moves structured data in both directions with SAP, Salesforce Net Zero Cloud, Databricks
  and the EU TRACES customs portal, but that API is sold and provisioned as part of an enterprise engagement: there is no
  public developer portal, no published API reference, no pricing page and no machine-readable contract on any Sourcemap host.
  Customers include Ferrero, Hershey, Woolworths and AG1.'
url: https://raw.githubusercontent.com/api-evangelist/sourcemap/refs/heads/main/apis.yml
x-api-posture: no-product-api
x-api-posture-basis: observed
x-type: company
x-source: harvest:secondary-market
deliveryModel:
  model: saas
  open_source: false
  commercial: true
  callable_host: false
  label: Hosted service · you call their endpoint
  confidence: medium
  source:
  - pricing
  generated: '2026-08-28'
  method: derived
specificationVersion: '0.20'
created: '2026-08-28'
modified: '2026-08-28'
image: https://www.sourcemap.com/modules/core/client/img/brand/logo.png
tags:
- Company
- Supply Chain
- Traceability
- Supply Chain Transparency
- Due Diligence
- Regulatory Compliance
- ESG
- Sustainability
- Risk Management
- Logistics
- Manufacturing
apis:
- name: Sourcemap Platform API
  description: 'Sourcemap describes a secure real-time RESTful API used to integrate the traceability platform with ERP and
    enterprise data stacks (SAP, Salesforce Net Zero Cloud, Databricks) and with customs portals such as EU TRACES. The API
    host api.sourcemap.com resolves and answers, but every path is refused to an anonymous caller: the Azure Application Gateway
    edge returns 403 Access Forbidden with x-robots-tag noindex, and the Kong router behind it answers /v1/* with "no Route
    matched with those values". No OpenAPI, Swagger, GraphQL, AsyncAPI or MCP manifest is published on any Sourcemap host,
    and there is no public API reference to read. Access is provisioned through an enterprise engagement.'
  humanURL: https://www.sourcemap.com/technology/erp-integration
  baseURL: https://api.sourcemap.com
  tags:
  - Supply Chain
  - Traceability
  - ERP Integration
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: DomainSecurity
  url: security/sourcemap-domain-security.yml
- type: Website
  url: https://www.sourcemap.com/
- type: Blog
  url: https://www.sourcemap.com/blog
- type: Support
  url: https://info.sourcemap.com/supplier-support
- type: TermsOfService
  url: https://www.sourcemap.com/terms-conditions
- type: PrivacyPolicy
  url: https://www.sourcemap.com/privacy-policy
- type: LLMsTxt
  url: llms/sourcemap-llms.txt
- type: Conformance
  url: conformance/sourcemap-conformance.yml
- type: Compliance
  url: conformance/sourcemap-conformance.yml
- type: Lifecycle
  url: lifecycle/sourcemap-lifecycle.yml
- type: StatusPage
  url: https://status.sourcemap.com/
- type: Plans
  url: plans/sourcemap-plans-pricing.yml
- type: RateLimits
  url: rate-limits/sourcemap-rate-limits.yml
- type: Packages
  url: packages/sourcemap-packages.yml
x-enrichment:
  date: '2026-08-28'
  status: minimal
  artifacts_added: 10
  pass: local-v1
x-coverage:
  state: gated
  reason: sales-gate
  detail: Sourcemap markets "a secure real-time RESTful API" on its integrations page, and api.sourcemap.com does resolve
    to an Azure Application Gateway fronting a Kong router, but every anonymous path is refused with 403 Access Forbidden
    and x-robots-tag "noindex, nofollow, noarchive" while the 379-URL sitemap contains no developer, docs, reference, or pricing
    page at all — the only route to the contract is the Request a Demo form.
  evidence:
  - url: https://api.sourcemap.com/openapi.json
    status: 403
  - url: https://api.sourcemap.com/v1/openapi.json
    status: 404
  - url: https://www.sourcemap.com/pricing
    status: 404
  - url: https://status.sourcemap.com/
    status: 401
  - url: https://www.sourcemap.com/company/request-a-demo
    status: 200
  - url: https://www.sourcemap.com/llms.txt
    status: 200
  checked: '2026-08-28'

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/sourcemap"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/sourcemap/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/sourcemap/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.