Skip to content

API Reference

CBOM provides a REST API for automation, integration with CI/CD pipelines, and programmatic access to your cryptographic inventory.


Interactive API documentation (Swagger/OpenAPI) is available within the platform after authentication:

https://your-cbom-instance/swagger-ui/index.html

The documentation includes all available endpoints, request/response schemas, and a “Try it out” feature for testing directly from the browser.


Two authentication methods are supported:

MethodUse Case
JWT TokenUI users and API automation scripts
API KeySensors pushing scan results

Tokens are obtained via the login endpoint and included as a Bearer token in the Authorization header.


  • Export CycloneDX CBOM — programmatically generate compliance reports
  • Import scan results — feed CI/CD pipeline findings into the platform
  • Query inventory — search and filter assets for custom tooling
  • Trigger scans — force-scan sensors on demand

For pipeline integration, sensors can push results directly:

Terminal window
curl -X POST https://your-cbom-instance/api/v1/import/source-scan \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d @scan-results.json

See Import/Export for accepted formats and offline import options.