Tidelift
Tidelift provides open-source software supply-chain management for enterprises. Its platform combines package intelligence (maintenance, quality, end-of-life, and vulnerability signals) with catalogs of approved dependencies, policy and license standards enforcement, SBOM import/export, and "alignment" of projects against an organization's standards. Tidelift is distinctive for paying the open-source maintainers ("lifters") behind the packages enterprises rely on. The Tidelift External API (OpenAPI 3.0, Bearer API-key auth) exposes catalogs, violations, projects, groups, packages, releases, vulnerabilities, licenses, and reporting. Tidelift was acquired by Sonar in 2025; the API and developer surface remain active.
Tidelift publishes 15 APIs on the APIs.io network, including Alignments API, Attestations API, Authentication API, and 12 more. Tagged areas include Company, Open Source, Software Supply Chain, Dependency Management, and Application Security.
The Tidelift catalog on APIs.io includes 1 event-driven AsyncAPI specification.
Tidelift’s developer surface includes documentation, API reference, getting-started guide, support, pricing, authentication, CLI, and 22 more developer resources.
Kin Score
APIs 15
Individual APIs this provider publishes, each with its own machine-readable definition.
Tidelift Alignments API
The Alignments API from Tidelift — 4 operation(s) for alignments.
Tidelift Attestations API
The Attestations API from Tidelift — 2 operation(s) for attestations.
Tidelift Authentication API
A [Tidelift API key](https://docs.tidelift.com/article/79-api-authentication) is required for all endpoints. If a particular type of API key is required it will be noted on the ...
Tidelift Basic Examples API
* curl ``` curl -H "Accept: application/json" \ -H "Authorization: bearer
Tidelift Catalog Releases API
The Catalog Releases API from Tidelift — 7 operation(s) for catalog releases.
Tidelift Catalogs API
The Catalogs API from Tidelift — 9 operation(s) for catalogs.
Tidelift CatalogStandards API
The CatalogStandards API from Tidelift — 3 operation(s) for catalogstandards.
Tidelift Groups API
The Groups API from Tidelift — 5 operation(s) for groups.
Tidelift Licenses API
The Licenses API from Tidelift — 5 operation(s) for licenses.
Tidelift Packages API
The Packages API from Tidelift — 6 operation(s) for packages.
Tidelift Projects API
The Projects API from Tidelift — 6 operation(s) for projects.
Tidelift Releases API
The Releases API from Tidelift — 5 operation(s) for releases.
Tidelift Reports API
The Reports API from Tidelift — 3 operation(s) for reports.
Tidelift Users API
The Users API from Tidelift — 1 operation(s) for users.
Tidelift Vulnerabilities API
The Vulnerabilities API from Tidelift — 2 operation(s) for vulnerabilities.
Scroll for all 15
Arazzo Workflows 2
Multi-step API workflows described with the Arazzo specification.
_Index
ARAZZOTidelift — package vulnerability check
Validate the API key, look up a package and a release, and pull the release's vulnerabilities.
ARAZZOMCP Servers 1
Model Context Protocol servers that expose these APIs to AI agents.
tidelift-mcp.yml
MCP SERVEREvent Specifications 1
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Tidelift Webhooks
ASYNCAPISecurity Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 2
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 5
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 7
Pagination, idempotency, versioning, errors, and events
Scroll for all 7
Build 5
SDKs, sample code, and the tooling you integrate with
Access & Security 5
Authentication, authorization, and security posture
Operate 2
Status, limits, changes, and where to get help
Commercial 1
Pricing, plans, and the legal terms of use