# Tidelift

**Canonical:** https://apis.io/providers/tidelift/  
**Website:** https://api.tidelift.com/docs/  
**APIs profiled:** 15

Tidelift provides open-source software supply-chain management for enterprises. Its platform combines package intelligence (maintenance, quality, end-of-life, and vulnerability signals) with catalogs of approved dependencies, policy and license standards enforcement, SBOM import/export, and "alignment" of projects against an organization's standards. Tidelift is distinctive for paying the open-source maintainers ("lifters") behind the packages enterprises rely on. The Tidelift External API (OpenAPI 3.0, Bearer API-key auth) exposes catalogs, violations, projects, groups, packages, releases, vulnerabilities, licenses, and reporting. Tidelift was acquired by Sonar in 2025; the API and developer surface remain active.

## Kin Score — 43.0 / 100 (developing)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+1.1 from 41.9).

| Facet | Score |
|---|---|
| Discoverability | 92.6 |
| Contract Quality | 60.8 |
| Governance | 16.7 |
| Contract Governance | 16.7 |
| Operational Transparency | 36.8 |
| Developer Ergonomics | 58.9 |
| Commercial Clarity | 0.0 |
| Access Clarity | 0.0 |

## Agent readiness — 44.7 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (15)

- **Tidelift Alignments API** — The Alignments API from Tidelift — 4 operation(s) for alignments.
- **Tidelift Attestations API** — The Attestations API from Tidelift — 2 operation(s) for attestations.
- **Tidelift Authentication API** — A [Tidelift API key](https://docs.tidelift.com/article/79-api-authentication) is required for all endpoints. If a particular type of API key is required it will be noted on the ...
- **Tidelift Basic Examples API** — * curl ``` curl -H "Accept: application/json" \ -H "Authorization: bearer <your Tidelift API key>" \ https://api.tidelift.com/external-api/v1/packages/pypi/urllib3 ``` More deta...
- **Tidelift Catalog Releases API** — The Catalog Releases API from Tidelift — 7 operation(s) for catalog releases.
- **Tidelift Catalogs API** — The Catalogs API from Tidelift — 9 operation(s) for catalogs.
- **Tidelift CatalogStandards API** — The CatalogStandards API from Tidelift — 3 operation(s) for catalogstandards.
- **Tidelift Groups API** — The Groups API from Tidelift — 5 operation(s) for groups.
- **Tidelift Licenses API** — The Licenses API from Tidelift — 5 operation(s) for licenses.
- **Tidelift Packages API** — The Packages API from Tidelift — 6 operation(s) for packages.
- **Tidelift Projects API** — The Projects API from Tidelift — 6 operation(s) for projects.
- **Tidelift Releases API** — The Releases API from Tidelift — 5 operation(s) for releases.
- **Tidelift Reports API** — The Reports API from Tidelift — 3 operation(s) for reports.
- **Tidelift Users API** — The Users API from Tidelift — 1 operation(s) for users.
- **Tidelift Vulnerabilities API** — The Vulnerabilities API from Tidelift — 2 operation(s) for vulnerabilities.

## MCP servers (1)

- **Tidelift MCP Server**

## Agentic access (1)

- **Tidelift Agentic Access** — 66 operations · 33 acting · 2 human-in-the-loop

## Security (3)

- **Tidelift Authentication** — http · 1 scheme
- **Tidelift Domain Security** — TLSv1.2 · HSTS · DMARC
- **Tidelift Vulnerability Disclosure** — security.txt · contact published

## Tags

Company, Open-Source, Software Supply Chain, Dependency Management, Application Security, SBOM, License Compliance, Vulnerability Management, Developer Tools

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/tidelift/). Scores are computed from the provider's own public artifacts under a published rubric.
