niche · -0.3

SBOM

Score 19.7 / 100 29 providers 14 APIs Search apis.io →

Providers using this tag (29)

Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.

Strong 3 Solid coverage with minor gaps
Developing 9 Usable, with meaningful gaps to close
Thin 7 Limited public surface area
Emerging 8 Early or largely undocumented
Minimal 2 Almost no public developer surface

APIs with this tag (14)

Ranked by the provider's API Evangelist rating — the Kin Score is scored per provider, not per API, so every API of a provider shares its band. How the rating works →

Strong 1 Solid coverage with minor gaps
Developing 3 Usable, with meaningful gaps to close
Thin 5 Limited public surface area
Emerging 5 Early or largely undocumented

Score breakdown

Frequency
44.9
log-scaled weighted occurrences
Breadth
0.8
spread across providers
Quality lift
41.3
mean composite of providers using it
Cohesion
0.0
strength of nearest seed neighbor

Related tags

Software Composition Analysis 10 co-occurrences Software Supply Chain 7 co-occurrences DevSecOps 13 co-occurrences Container Security 6 co-occurrences Vulnerability Management 15 co-occurrences Vulnerabilities 7 co-occurrences Supply Chain Security 5 co-occurrences Vulnerability Scanning 5 co-occurrences

Where this tag comes from

Provider tag21
Api tag14
Openapi tag4
Openapi op tag22

Cohort brief

Auto-generated

The 29 providers in the APIs.io catalog tagged SBOM, scored on the Kin Score. Every figure below is computed from the catalog — nothing here is written.

Providers
29
all scored
Mean Kin Score
34.3
+13.6 vs catalog 20.7
Mean Agent Readiness
19.7
+10.0 vs catalog 9.7
Spread
5–63.7
median 36.6 · σ 16.4
How the 29 split by band
Exemplar 0Strong 3Developing 9Thin 7Emerging 8Minimal 2
Facet averages, against the whole catalog
FacetThis cohortCatalogDifferenceScored
Developer Ergonomics 35.5 17.9 +17.6 29
Contract Quality 34.3 17.5 +16.8 29
Operational Transparency 25.7 11.3 +14.4 29
Discoverability 71.8 60.4 +11.4 29
Access Clarity 31.4 22.3 +9.1 29
Contract Governance 13.7 6.4 +7.3 29

A facet is averaged over the members that carry it, not over the whole cohort — the “Scored” column is that count. Averaging an absent facet as zero would score our own coverage gaps as the providers’ posture.

What this cohort publishes
ArtifactThis cohortCatalogDifference
MCP server (any) 59% 16% +43
MCP server (first-party) 10% 7% +3
Agent Skills 0% 0% 0
OAuth scopes 10% 9% +1
Security 97% 88% +9
Arazzo workflows 24% 2% +22
Governance rules 31% 13% +18

mcp_pct counts any mcp/ artifact including ones API Evangelist derived from the provider OpenAPI; mcp_first_party_pct counts only servers the provider publishes. Prefer the latter.

Top by Kin Score
  1. 1 Palo Alto Networks 63.7
  2. 2 Kondukto 62.5
  3. 3 Socket 56.5
  4. 4 Sysdig 50.9
  5. 5 Mend 49.9
  6. 6 Fossa 48
  7. 7 Binarly 47.4
  8. 8 Socket 46.5
  9. 9 Harness 46
  10. 10 Root (fka Slim.ai) 45.3
Top by Agent Readiness
  1. 1 Socket 48.6
  2. 2 Socket 41.2
  3. 3 Palo Alto Networks 39.4
  4. 4 Aqua Security 34
  5. 5 Tidelift 32.9
  6. 6 Trivy 32.7
  7. 7 Kondukto 32.6
  8. 8 Snyk 30.6
  9. 9 Harness 29.4
  10. 10 Root (fka Slim.ai) 27.9
All 29 members of this roster resolve to a scored provider in the catalog.Generated from the catalog build of 25 August 2026, across 26891 providers, using the same computation served by the APIs.io cohort API. Briefs are published for rosters of 5 or more scored providers; below that a distribution is not meaningful.

Work with this as data

Every tag here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for tags

7 MCP tools reach this
  • find_tagsBrowse and filter every tag in the catalog.
  • get_cohortThis tag as a scored cohort — every provider carrying it, with scores.
  • cohort_statsPRO — the distribution across this tag: mean, median, band split, adoption rates.
  • cohort_rankingsPRO — the leaderboard, on composite AND agent-readiness axes.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This tag
curl "https://apis.io/api/v1/tags/sbom"
All tags
curl "https://apis.io/api/v1/tags?limit=25"
As a scored cohort
curl "https://apis.io/api/v1/cohorts/tag/sbom"
The distribution (Pro)
curl "https://apis.io/api/v1/cohorts/tag/sbom/stats" \
  -H "X-API-Key: $APIS_IO_KEY"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.