S

semgrep.dev

Semgrep provides static application security testing, software composition analysis, secrets scanning, and related triage workflows for codebases. It offers a hosted AppSec Platform alongside an open-source CLI for local and CI scanning.

2 integrations · REST · CLI

Semgrep exposes one documented HTTP API for its AppSec Platform and a Semgrep CLI; docs also reference an official MCP server, but its public connect endpoint and auth mechanics were not confirmed from Semgrep-hosted docs.

discovered 2mo ago
REST · OpenAPI1
CLI1
Credentials
Semgrep Web API tokenapi_keyGet key ↗

In the Semgrep AppSec Platform, open Settings > Tokens and create an API token with the Web API permission. The API docs state the token must have Web API permission and no limited scopes.

Semgrep CLI login sessionoauth2$ semgrep login

Acquired by the CLI — running semgrep login opens the auth flow and stores the credential.

conventions · 1/8 published

Publish these signals → /publishing