jfrog.com
JFrog provides a software supply chain platform for artifact management, security scanning, governance, and AI/ML asset management. Its products include Artifactory, Xray, Curation, runtime security, and AI catalog capabilities across SaaS and self-managed deployments.
JFrog exposes a platform REST API, a Catalog GraphQL API, a hosted MCP server for SaaS, and the `jf` CLI; REST and CLI authentication are documented with access/reference tokens and deprecated API keys, while the GraphQL and MCP docs found did not reveal concrete auth bindings or connection URLs.
- JFrog MCP Server for SaaSdiscovered
- JFrog Platform REST APIsdiscovered
- JFrog Catalog GraphQL APIdiscovered
- JFrog CLIdiscovered
Create a token in the JFrog Platform UI under your user profile token settings as described in Identity Tokens. JFrog recommends using reference tokens instead of legacy API keys, as noted on the API Key page.
If your JFrog instance still allows legacy API keys, generate or view it from your user profile as described on API Key. JFrog states API keys reached end of life and recommends migrating to reference tokens from Identity Tokens.
conventions · 1/7 published
- integrations.json——
- llms.txt✓https://jfrog.com/llms.txt
- API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing