fossa.com
FOSSA provides software supply chain security tools for open source license compliance, vulnerability management, and SBOM workflows. Its platform helps organizations analyze codebases, containers, and software artifacts to identify dependencies and related risk.
FOSSA exposes a REST API on app.fossa.com authenticated by API token, a `fossa` CLI using the same token via `FOSSA_API_KEY`, and a public unauthenticated content API under `/api/llms` described in llms.txt.
- FOSSA REST APIdiscovered
- FOSSA Content APIdiscovered
- FOSSA CLIdiscovered
In the FOSSA web app, open API & Custom Integrations or Authentication, then go to your account or organization settings and create an API token at API token settings. The docs state the FOSSA API uses API keys, and the CLI docs say to get an API key before running fossa analyze.
conventions · 1/7 published
- integrations.json——
- llms.txt✓https://fossa.com/llms.txt
- API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing