documentation
Attestd Docs
Attestd returns a structured, deterministic security assessment for a software product and version. These docs cover how to call the API, what every field means, and how to integrate into CI/CD pipelines and AI agents.
Why Attestd
Technical architecture deep-dive: sensor vs. gate philosophy, NVD limitations, three-signal design, confidence semantics, and the determinism guarantee.
Quickstart
Make your first API call in under two minutes.
Response Field Reference
Exact semantics for every field in a /v1/check response, including multi-range aggregation rules.
Schema Stability Guarantee
risk_state values, risk_factors vocabulary, and field semantics are frozen for the lifetime of v1. Versioning policy and JSON Schema artifact.
Detection Ledger
Public commit record of supply chain compromises registered by Attestd. Packages, versions, detection source, and OSV citations.
API Reference
Base URL, authentication, request parameters, error codes, and rate limits.
SDK Reference
Python and JavaScript SDK clients with typed response models, error handling, and testing utilities.
Account & Portal Guide
API key management, key rotation, route scoping, billing tiers, and portal settings.
Attestd for Developers
Set up Attestd in Claude Code, Cursor, or Windsurf via MCP. Per-client config blocks and system prompt.
AI Agent Integration
LangChain tool definition, function calling, and correct handling of outside-coverage products.
CI/CD Integration
GitHub Actions and GitLab CI recipes for blocking deployments on high-risk dependencies.
Integrations
Framework-specific integrations: LangChain StructuredTool, agent executor, and async patterns.
Products
356 API products (77 with detailed docs), API slugs, notable CVEs, and NVD data source details.
Supply chain integrity
Monitored PyPI (27459) and npm (237601) packages, OSV MAL- and registry sources, and how supply_chain relates to risk_state.
FAQ
Common questions about data freshness, coverage, confidence scores, and supply chain monitoring.