E

endorlabs.com

Endor Labs provides application security and software supply chain security tooling, including dependency, vulnerability, secret, and code scanning. Its platform helps teams analyze and manage risk across source code, open source packages, and AI-assisted development workflows.

3 integrations · MCP · REST · CLI

Endor Labs exposes a REST API at `https://api.endorlabs.com/v1`, the `endorctl` CLI, and a local stdio MCP server; all require Endor Labs-issued authentication, primarily an `ENDOR_TOKEN` or API key/secret for CLI-backed flows.

discovered 2mo ago
MCP servers1
REST · OpenAPI1
CLI1
Credentials
Endor Labs API key and secretcompoundGet key ↗

In the Endor Labs UI, go to Manage API keys: User menu → Settings → Access Control → API Keys → Generate API Key. Choose roles and expiry, then copy the generated ENDOR_API_CREDENTIALS_KEY and ENDOR_API_CREDENTIALS_SECRET. You can exchange them for an access token with POST https://api.endorlabs.com/v1/auth/api-key as described in REST API authentication.

Endor Identity Token (ENDOR_TOKEN)bearerGet token ↗

Get an Endor Labs access token by either:

- running endorctl init as shown in Install and configure endorctl, then printing it with endorctl auth --print-access-token; or

- using headless browser auth or exchanging an API key/secret as described in REST API authentication.

Use the resulting token as ENDOR_TOKEN and send it as Authorization: Bearer <token>.

conventions · 1/7 published

Publish these signals → /publishing