Developers
Automate uploads and integrate TraceGuard into your stack.
TraceGuard exposes a few well-defined surfaces for automation. Everything is bounded by the same scopes and row-level security as the UI — a token can never read or change anything its owner couldn't.
Authentication & tokens
The four token types and how scopes work.
GitHub SBOM Action
Generate and upload SBOMs from CI.
REST API
The HTTP API behind the product (beta).
MCP server
Connect Claude or an IDE to your supply-chain data.
OAuth
Authorize MCP and third-party clients.
On the roadmap
- Webhooks — receive events (new critical finding, scan complete) in your own systems.
- SDKs — typed clients for the REST API (JS, Python).
Need one of these sooner? Tell us which and we'll prioritize it.