Veracode
Veracode is an application security testing (AST) platform offering static analysis (SAST), dynamic analysis (DAST), software composition analysis (SCA), manual penetration testing, and developer security training. The Veracode Platform provides a comprehensive suite of REST APIs enabling organizations to automate security testing, access findings, manage policies, generate reports, and administer users and teams. All REST APIs use HMAC authentication with API ID/key credentials and return JSON responses following OpenAPI standards.
Veracode publishes 11 APIs on the APIs.io network, including API Credentials API, Applications API, Business Units API, and 8 more. Tagged areas include Application Security, SAST, DAST, SCA, and Security Testing.
The Veracode catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
Veracode’s developer surface includes authentication, documentation, getting-started guide, engineering blog, support, and 9 more developer resources.
Kin Score
APIs 11
Individual APIs this provider publishes, each with its own machine-readable definition.
Veracode API Credentials API
API credential lifecycle management
Veracode Applications API
Application profile management
Veracode Business Units API
Business unit management
Veracode Findings API
Application security findings
Veracode Manual Penetration Testing API
Manual penetration test findings
Veracode Policy Evaluations API
Application policy compliance evaluations
Veracode Reports API
Asynchronous report generation and retrieval
Veracode Roles API
Role and permission management
Veracode Sandboxes API
Development sandbox management
Veracode Teams API
Team management
Veracode Users API
User and API service account management
Scroll for all 11
Open Collections 16
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
API Collection
OPEN COLLECTIONVeracode Applications REST API Credentials API
OPEN COLLECTIONVeracode REST API Credentials Applications API
OPEN COLLECTIONVeracode Applications REST API
OPEN COLLECTIONVeracode Applications REST API Credentials Findings API
OPEN COLLECTIONVeracode Findings REST API
OPEN COLLECTIONVeracode Identity REST API
OPEN COLLECTIONVeracode Reporting REST API
OPEN COLLECTIONVeracode Applications REST API Credentials Reports API
OPEN COLLECTIONVeracode Applications REST API Credentials Roles API
OPEN COLLECTIONVeracode Applications REST API Credentials Sandboxes API
OPEN COLLECTIONVeracode Applications REST API Credentials Teams API
OPEN COLLECTIONVeracode Applications REST API Credentials Users API
OPEN COLLECTIONScroll for all 16
GraphQL 1
GraphQL schemas published by this provider.
Veracode GraphQL API
Veracode is an application security testing platform covering static analysis, dynamic analysis, SCA, and manual penetration testing. The API covers scan submissions, results, f...
GRAPHQLPricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Veracode Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Veracode Finops
FINOPSSemantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Veracode Context
JSON-LDSpectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
Veracode API Rules
SPECTRALVeracode API Rules
SPECTRALJSON Schema 1
Standalone JSON Schema definitions for this provider's data models.
Veracode Security Finding
JSON SCHEMAJSON Structure 1
JSON Structure definitions describing this provider's data shapes.
Veracode Finding Structure
JSON STRUCTUREExamples 3
Example request and response payloads for these APIs.
Security Posture 4
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 5
Authentication, authorization, and security posture
Operate 1
Status, limits, changes, and where to get help
Company 3
The organization behind the API
Other 1
Properties that don't map to a standard resource type
Source (apis.yml)
Work with this as data
Every provider here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for providers
9 MCP tools reach this
find_providersBrowse and filter every provider in the catalog.get_provider_artifactsEvery artifact this provider publishes, grouped by type.get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.get_provider_toolsEvery MCP tool they ship, with the operation each wraps.get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.get_provider_ratingPRO — composite, band, trend and facet scores.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/providers/veracode"
curl "https://apis.io/api/v1/providers?limit=25"
curl "https://apis.io/api/v1/providers/veracode/operations?limit=25"
curl "https://apis.io/api/v1/providers/veracode/evidence"
Discovery needs no key. Ratings and market analysis are Pro.