API overview

Base URL: /api/v1. Authenticate with a scoped token (Settings → API): Authorization: Bearer vlc_…. Tokens have a name, creator, expiry, scopes, last-used tracking and can be revoked; the secret is shown once and stored as a hash.

Scopes

products:read, products:write, sboms:read, sboms:write, components:read, vulnerabilities:read, vulnerabilities:write, incidents:read, incidents:write, cra:read, tasks:read, tasks:write, evidence:read, reports:read, webhooks:manage.

Pagination

List endpoints return { data, next_cursor, has_more }. Pass cursor to fetch the next page (limit ≤ 200).

Rate limits

600 read and 120 write requests per minute per token, 200 SBOM uploads per hour. Limits are returned in X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset and Retry-After.

Errors

{ "error": { "code": "validation" | "unauthenticated" | "forbidden" | "not_found" | "conflict" | "rate_limited" | "internal", "message": "…", "details": {…} } }

The complete specification is served at /api/v1/openapi.json.

Last updated . This page describes the current release.