semgrep.dev
Semgrep provides static application security testing, software composition analysis, secrets scanning, and related triage workflows for codebases. It offers a hosted AppSec Platform alongside an open-source CLI for local and CI scanning.
Semgrep exposes one documented HTTP API for its AppSec Platform and a Semgrep CLI; docs also reference an official MCP server, but its public connect endpoint and auth mechanics were not confirmed from Semgrep-hosted docs.
- Semgrep API v1discovered
- Semgrep CLIdiscovered
In the Semgrep AppSec Platform, open Settings > Tokens and create an API token with the Web API permission. The API docs state the token must have Web API permission and no limited scopes.
$ semgrep loginAcquired by the CLI — running semgrep login opens the auth flow and stores the credential.
conventions · 1/8 published
- integrations.json✗
/.well-known/integrations.json - llms.txt✓https://semgrep.dev/llms.txt
- API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing