API Reference
CBOM provides a REST API for automation, integration with CI/CD pipelines, and programmatic access to your cryptographic inventory.
Accessing the API Documentation
Section titled “Accessing the API Documentation”Interactive API documentation (Swagger/OpenAPI) is available within the platform after authentication:
https://your-cbom-instance/swagger-ui/index.htmlThe documentation includes all available endpoints, request/response schemas, and a “Try it out” feature for testing directly from the browser.
Authentication
Section titled “Authentication”Two authentication methods are supported:
| Method | Use Case |
|---|---|
| JWT Token | UI users and API automation scripts |
| API Key | Sensors pushing scan results |
Tokens are obtained via the login endpoint and included as a Bearer token in the Authorization header.
Common Use Cases
Section titled “Common Use Cases”- Export CycloneDX CBOM — programmatically generate compliance reports
- Import scan results — feed CI/CD pipeline findings into the platform
- Query inventory — search and filter assets for custom tooling
- Trigger scans — force-scan sensors on demand
CI/CD Integration
Section titled “CI/CD Integration”For pipeline integration, sensors can push results directly:
curl -X POST https://your-cbom-instance/api/v1/import/source-scan \ -H "Authorization: Bearer YOUR_TOKEN" \ -H "Content-Type: application/json" \ -d @scan-results.jsonSee Import/Export for accepted formats and offline import options.
Related
Section titled “Related”- Import/Export — UI for import/export operations
- Sensors — Sensor management and scan triggers
- Deployment — Platform setup