SPDX website screenshot

SPDX

The Software Package Data Exchange (SPDX) is an open standard under the Linux Foundation for communicating software bill of materials information including components, licenses, copyrights, and security references. It is an ISO/IEC standard (ISO/IEC 5962) used for software supply chain transparency.

SPDX publishes 1 API on the APIs.io network. Tagged areas include Licensing, Linux Foundation, SBOM, and Standards.

SPDX’s developer surface includes documentation, engineering blog, and 2 more developer resources.

19.9/100 emerging ▬ flat Agent 3/100 human only Full breakdown ↓
scored 2026-08-05 · rubric v0.9.1
AccessFreemium
1 APIs
LicensingLinux FoundationSBOMStandards

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-05 · rubric v0.9.1
Composite quality — 19.9/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 2.2 / 20
Commercial Clarity 7.9 / 20
Operational Transparency 4.8 / 13
Governance 0.0 / 12
Discoverability 5.0 / 10
Agent readiness — 3/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 10
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/spdx: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

SPDX API

API for accessing SPDX open standard resources for software bill of materials, license compliance, and software supply chain transparency information.

Pricing Plans 1

Published pricing tiers and plan structures.

Spdx Plans Pricing

3 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Spdx Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Spdx Finops

FINOPS

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Spdx Domain Security

TLSv1.3 · HSTS

SECURITY

Resources

Documentation 1

Reference material describing how the API behaves

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 1

Authentication, authorization, and security posture

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: spdx
name: SPDX
description: The Software Package Data Exchange (SPDX) is an open standard under the Linux Foundation for communicating software
  bill of materials information including components, licenses, copyrights, and security references. It is an ISO/IEC standard
  (ISO/IEC 5962) used for software supply chain transparency.
type: Index
accessModel:
  pricing: freemium
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Freemium
  confidence: medium
  source:
  - plans
  generated: '2026-07-22'
  method: derived
position: Consumer
access: 3rd-Party
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/spdx.png
tags:
- Licensing
- Linux Foundation
- SBOM
- Standards
created: '2026-03-16'
modified: '2026-03-16'
url: https://raw.githubusercontent.com/api-evangelist/spdx/refs/heads/main/apis.yml
specificationVersion: '0.19'
apis:
- aid: spdx:spdx-api
  name: SPDX API
  description: API for accessing SPDX open standard resources for software bill of materials, license compliance, and software
    supply chain transparency information.
  humanURL: https://spdx.dev/learn/overview/
  tags:
  - Licensing
  - SBOM
  properties:
  - type: Documentation
    url: https://spdx.dev/learn/overview/
common:
- type: DomainSecurity
  url: security/spdx-domain-security.yml
- type: Documentation
  name: SPDX Documentation
  description: Official documentation for SPDX.
  url: https://spdx.dev/learn/overview/
- type: GitHubOrg
  name: SPDX GitHub
  description: Source code and repositories for SPDX.
  url: https://github.com/spdx
- url: https://spdx.dev/feed/
  type: Blog
maintainers:
- FN: Kin Lane
  email: info@apievangelist.com