SBOM
Providers using this tag (29)
Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.
Strong 3 Solid coverage with minor gaps
Developing 9 Usable, with meaningful gaps to close
Thin 7 Limited public surface area
Emerging 8 Early or largely undocumented
Minimal 2 Almost no public developer surface
APIs with this tag (14)
Ranked by the provider's API Evangelist rating — the Kin Score is scored per provider, not per API, so every API of a provider shares its band. How the rating works →
Strong 1 Solid coverage with minor gaps
Developing 3 Usable, with meaningful gaps to close
Thin 5 Limited public surface area
Emerging 5 Early or largely undocumented
Score breakdown
Related tags
Where this tag comes from
Cohort brief
Auto-generatedThe 29 providers in the APIs.io catalog tagged SBOM, scored on the Kin Score. Every figure below is computed from the catalog — nothing here is written.
| Facet | This cohort | Catalog | Difference | Scored |
|---|---|---|---|---|
| Developer Ergonomics | 35.5 | 17.9 | +17.6 | 29 |
| Contract Quality | 34.3 | 17.5 | +16.8 | 29 |
| Operational Transparency | 25.7 | 11.3 | +14.4 | 29 |
| Discoverability | 71.8 | 60.4 | +11.4 | 29 |
| Access Clarity | 31.4 | 22.3 | +9.1 | 29 |
| Contract Governance | 13.7 | 6.4 | +7.3 | 29 |
A facet is averaged over the members that carry it, not over the whole cohort — the “Scored” column is that count. Averaging an absent facet as zero would score our own coverage gaps as the providers’ posture.
| Artifact | This cohort | Catalog | Difference |
|---|---|---|---|
| MCP server (any) | 59% | 16% | +43 |
| MCP server (first-party) | 10% | 7% | +3 |
| Agent Skills | 0% | 0% | 0 |
| OAuth scopes | 10% | 9% | +1 |
| Security | 97% | 88% | +9 |
| Arazzo workflows | 24% | 2% | +22 |
| Governance rules | 31% | 13% | +18 |
mcp_pct counts any mcp/ artifact including ones API Evangelist derived from the provider OpenAPI; mcp_first_party_pct counts only servers the provider publishes. Prefer the latter.
- 1 Palo Alto Networks 63.7
- 2 Kondukto 62.5
- 3 Socket 56.5
- 4 Sysdig 50.9
- 5 Mend 49.9
- 6 Fossa 48
- 7 Binarly 47.4
- 8 Socket 46.5
- 9 Harness 46
- 10 Root (fka Slim.ai) 45.3
- 1 Socket 48.6
- 2 Socket 41.2
- 3 Palo Alto Networks 39.4
- 4 Aqua Security 34
- 5 Tidelift 32.9
- 6 Trivy 32.7
- 7 Kondukto 32.6
- 8 Snyk 30.6
- 9 Harness 29.4
- 10 Root (fka Slim.ai) 27.9
Work with this as data
Every tag here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for tags
7 MCP tools reach this
find_tagsBrowse and filter every tag in the catalog.get_cohortThis tag as a scored cohort — every provider carrying it, with scores.cohort_statsPRO — the distribution across this tag: mean, median, band split, adoption rates.cohort_rankingsPRO — the leaderboard, on composite AND agent-readiness axes.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/tags/sbom"
curl "https://apis.io/api/v1/tags?limit=25"
curl "https://apis.io/api/v1/cohorts/tag/sbom"
curl "https://apis.io/api/v1/cohorts/tag/sbom/stats" \
-H "X-API-Key: $APIS_IO_KEY"
Discovery needs no key. Ratings and market analysis are Pro.