API overview
Base URL: /api/v1. Authenticate with a scoped token (Settings → API): Authorization: Bearer vlc_…. Tokens have a name, creator, expiry, scopes, last-used tracking and can be revoked; the secret is shown once and stored as a hash.
Scopes
products:read, products:write, sboms:read, sboms:write, components:read, vulnerabilities:read, vulnerabilities:write, incidents:read, incidents:write, cra:read, tasks:read, tasks:write, evidence:read, reports:read, webhooks:manage.
Pagination
List endpoints return { data, next_cursor, has_more }. Pass cursor to fetch the next page (limit ≤ 200).
Rate limits
600 read and 120 write requests per minute per token, 200 SBOM uploads per hour. Limits are returned in X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset and Retry-After.
Errors
{ "error": { "code": "validation" | "unauthenticated" | "forbidden" | "not_found" | "conflict" | "rate_limited" | "internal", "message": "…", "details": {…} } }
The complete specification is served at /api/v1/openapi.json.
Last updated . This page describes the current release.