veracode.com
Veracode provides application security products for scanning code, open-source dependencies, containers, IaC, and web applications, plus risk-management capabilities. Its platform is used to automate security testing and review findings across software development workflows.
Veracode exposes region-specific REST APIs, XML APIs, a Veracode Risk Manager GraphQL API, and a Veracode CLI; authentication is required via HMAC credentials across APIs, OAuth client credentials for REST APIs, and interactive OAuth or HMAC for the CLI.
- Veracode REST APIsdiscovered
- Veracode XML APIsdiscovered
- Veracode Risk Manager GraphQL APIdiscovered
- Veracode CLIdiscovered
$ veracode configureAcquired by the CLI — running veracode configure opens the auth flow and stores the credential.
In the Veracode Platform, open API Credentials from the user account menu, choose Create API Credentials, select OAuth Client, set the name, expiration, and roles, then generate and copy the Client ID and Client Secret as documented on OAuth Client Credentials. Use them to obtain short-lived access tokens for REST APIs.
$ veracode auth loginAcquired by the CLI — running veracode auth login opens the auth flow and stores the credential.
conventions · 1/8 published
- integrations.json✗
/.well-known/integrations.json - llms.txt✓https://veracode.com/llms.txt
- API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing