Veracode
Veracode is an application security testing (AST) platform offering static analysis (SAST), dynamic analysis (DAST), software composition analysis (SCA), manual penetration testing, and developer security training. The Veracode Platform provides a comprehensive suite of REST APIs enabling organizations to automate security testing, access findings, manage policies, generate reports, and administer users and teams. All REST APIs use HMAC authentication with API ID/key credentials and return JSON responses following OpenAPI standards.
Veracode publishes 12 APIs on the APIs.io network, including API Credentials API, Applications API, Business Units API, and 9 more. Tagged areas include Application Security, SAST, DAST, SCA, and Security Testing.
The Veracode catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
Veracode’s developer surface includes sandbox, authentication, documentation, getting-started guide, engineering blog, support, and 37 more developer resources.
What this lets a business do 1
Business capabilities this provider's published APIs can perform, derived from its own contracts. Browse all capabilities →
Kin Score
APIs 12
Individual APIs this provider publishes, each with its own machine-readable definition.
Veracode API Credentials API
API credential lifecycle management
Veracode Applications API
Application profile management
Veracode Business Units API
Business unit management
Veracode Findings API
Application security findings
Veracode Manual Penetration Testing API
Manual penetration test findings
Veracode Policy Evaluations API
Application policy compliance evaluations
Veracode Reports API
Asynchronous report generation and retrieval
Veracode Roles API
Role and permission management
Veracode Sandboxes API
Development sandbox management
Veracode Teams API
Team management
Veracode Users API
User and API service account management
Veracode API Credentials API
API credential lifecycle management
Scroll for all 12
Open Collections 16
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
API Collection
OPEN COLLECTIONVeracode Applications REST API Credentials API
OPEN COLLECTIONVeracode REST API Credentials Applications API
OPEN COLLECTIONVeracode Applications REST API
OPEN COLLECTIONVeracode Applications REST API Credentials Findings API
OPEN COLLECTIONVeracode Findings REST API
OPEN COLLECTIONVeracode Identity REST API
OPEN COLLECTIONVeracode Reporting REST API
OPEN COLLECTIONVeracode Applications REST API Credentials Reports API
OPEN COLLECTIONVeracode Applications REST API Credentials Roles API
OPEN COLLECTIONVeracode Applications REST API Credentials Sandboxes API
OPEN COLLECTIONVeracode Applications REST API Credentials Teams API
OPEN COLLECTIONVeracode Applications REST API Credentials Users API
OPEN COLLECTIONScroll for all 16
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Veracode Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Veracode Finops
FINOPSSemantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Veracode Context
JSON-LDSpectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
Veracode API Rules
SPECTRALVeracode API Rules
SPECTRALJSON Schema 25
Standalone JSON Schema definitions for this provider's data models.
ApplicationProfile
JSON SCHEMAApplication
JSON SCHEMAApplicationsPage
JSON SCHEMABusinessUnitProfile
JSON SCHEMABusinessUnit
JSON SCHEMABusinessUnitsPage
JSON SCHEMADynamicFlawInfo
JSON SCHEMAVeracode Security Finding
JSON SCHEMAFindingsPage
JSON SCHEMAMptScansPage
JSON SCHEMAPolicyCompliance
JSON SCHEMAReportInitiated
JSON SCHEMAReportRequest
JSON SCHEMAReportResults
JSON SCHEMARolesPage
JSON SCHEMASandboxProfile
JSON SCHEMASandbox
JSON SCHEMASandboxesPage
JSON SCHEMAStaticFlawInfo
JSON SCHEMATeamProfile
JSON SCHEMATeam
JSON SCHEMATeamsPage
JSON SCHEMAUserProfile
JSON SCHEMAUser
JSON SCHEMAUsersPage
JSON SCHEMAScroll for all 25
JSON Structure 1
JSON Structure definitions describing this provider's data shapes.
Veracode Finding Structure
JSON STRUCTUREExamples 3
Example request and response payloads for these APIs.
Security Posture 4
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 4
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 4
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 8
Pagination, idempotency, versioning, errors, and events
Scroll for all 8
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 8
Authentication, authorization, and security posture
Scroll for all 8
Operate 3
Status, limits, changes, and where to get help
Commercial 3
Pricing, plans, and the legal terms of use
Company 4
The organization behind the API
Other 5
Properties that don't map to a standard resource type
Source (apis.yml)
Work with this as data
Every provider here is available over the APIs.io API and to AI agents over MCP.