endorlabs.com
Endor Labs provides application security and software supply chain security tooling, including dependency, vulnerability, secret, and code scanning. Its platform helps teams analyze and manage risk across source code, open source packages, and AI-assisted development workflows.
Endor Labs exposes a REST API at `https://api.endorlabs.com/v1`, the `endorctl` CLI, and a local stdio MCP server; all require Endor Labs-issued authentication, primarily an `ENDOR_TOKEN` or API key/secret for CLI-backed flows.
- Endor Labs MCP serverdiscovered
- Endor Labs REST APIdiscovered
- endorctldiscovered
In the Endor Labs UI, go to Manage API keys: User menu → Settings → Access Control → API Keys → Generate API Key. Choose roles and expiry, then copy the generated ENDOR_API_CREDENTIALS_KEY and ENDOR_API_CREDENTIALS_SECRET. You can exchange them for an access token with POST https://api.endorlabs.com/v1/auth/api-key as described in REST API authentication.
Get an Endor Labs access token by either:
- running endorctl init as shown in Install and configure endorctl, then printing it with endorctl auth --print-access-token; or
- using headless browser auth or exchanging an API key/secret as described in REST API authentication.
Use the resulting token as ENDOR_TOKEN and send it as Authorization: Bearer <token>.
conventions · 1/7 published
- integrations.json——
- llms.txt✓https://endorlabs.com/llms.txt
- API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing