Trivy
Trivy is a comprehensive and versatile open-source security scanner from Aqua Security that finds vulnerabilities, misconfigurations, secrets, and SBOM in containers, Kubernetes, code repositories, clouds, and more. Trivy runs as a CLI tool, in client/server mode with an HTTP API, and as a Kubernetes Operator (trivy-operator) that continuously scans clusters and generates security reports as native Kubernetes Custom Resources.
Trivy publishes 2 APIs on the APIs.io network: Health API and Server API. Tagged areas include Containers, Kubernetes, SBOM, Security, and Vulnerability Scanning.
The Trivy catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
Trivy’s developer surface includes authentication, documentation, getting-started guide, release notes, and 19 more developer resources.
Kin Score
APIs 4
Individual APIs this provider publishes, each with its own machine-readable definition.
Trivy Operator
The Trivy Operator is a Kubernetes-native security toolkit that automatically scans clusters and generates security reports as Kubernetes Custom Resources. It defines 12 CRDs co...
Trivy CLI
The primary interface for Trivy is its command-line tool, which scans container images, filesystems, Git repositories, Kubernetes clusters, virtual machine images, and SBOMs. Su...
Trivy Health API
Server health and liveness checks
Trivy Server API
Server metadata and version information
Open Collections 1
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Trivy Server API
OPEN COLLECTIONMCP Servers 1
Model Context Protocol servers that expose these APIs to AI agents.
MCP Server
MCP SERVERPricing Plans 1
Published pricing tiers and plan structures.
Trivy Plans Pricing
PLANSRate Limits 1
Documented rate limits and quota policies.
Trivy Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Trivy Finops
FINOPSSemantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Trivy Context
JSON-LDSpectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
Trivy API Rules
SPECTRALTrivy API Rules
SPECTRALJSON Schema 2
Standalone JSON Schema definitions for this provider's data models.
Trivy Scan Result
JSON SCHEMATrivy Vulnerability Report
JSON SCHEMAJSON Structure 1
JSON Structure definitions describing this provider's data shapes.
Trivy Scan Structure
JSON STRUCTUREExamples 2
Example request and response payloads for these APIs.
Trivy Health Check Example
EXAMPLESecurity Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Kubernetes CRDs 12
Kubernetes Custom Resource Definitions published by this provider.
aquasecurity.github.io clustercompliancereports
CRDaquasecurity.github.io clusterconfigauditreports
CRDaquasecurity.github.io clusterinfraassessmentreports
CRDaquasecurity.github.io clusterrbacassessmentreports
CRDaquasecurity.github.io clustersbomreports
CRDaquasecurity.github.io clustervulnerabilityreports
CRDaquasecurity.github.io configauditreports
CRDaquasecurity.github.io exposedsecretreports
CRDaquasecurity.github.io infraassessmentreports
CRDaquasecurity.github.io rbacassessmentreports
CRDaquasecurity.github.io sbomreports
CRDaquasecurity.github.io vulnerabilityreports
CRDScroll for all 12
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 4
Reference material describing how the API behaves
Agent Surfaces 2
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 4
Pagination, idempotency, versioning, errors, and events
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 2
Authentication, authorization, and security posture
Operate 1
Status, limits, changes, and where to get help
Company 1
The organization behind the API
Other 4
Properties that don't map to a standard resource type