{
 "categories": [
  "developer-tools"
 ],
 "deployment": "hybrid",
 "evidence": [
  {
   "date": "2026-09-30",
   "fact": "homepage",
   "note": "nuget.org describes NuGet as the package manager for .NET and the NuGet Gallery as the central package repository.",
   "source": "https://www.nuget.org/",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "license",
   "note": "The gallery presents package search and publishing without a priced plan. License is free. An OSI license file for the client was not opened.",
   "source": "https://www.nuget.org/",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "deployment",
   "note": "nuget.org is a hosted feed. The MCP server runs locally with dnx. Deployment is hybrid.",
   "source": "https://learn.microsoft.com/en-us/nuget/concepts/nuget-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "platforms",
   "note": "nuget.exe is documented for Windows, and for macOS and Linux through Mono. Selected commands are also on the dotnet CLI. The gallery is on the web.",
   "source": "https://learn.microsoft.com/en-us/nuget/reference/nuget-exe-cli-reference",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "modalities.rpa.ui_stack[0]",
   "note": "The NuGet Gallery is a browser site. UI stack is web-dom. Drivability was not probed.",
   "source": "https://www.nuget.org/",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "modalities.api.exists",
   "note": "Microsoft documents the NuGet Server API as HTTP endpoints for download, metadata, and publish. The nuget.org service index is https://api.nuget.org/v3/index.json.",
   "source": "https://learn.microsoft.com/en-us/nuget/api/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "modalities.api.kinds[0]",
   "note": "V3 resources return JSON over HTTP. The older V2 OData protocol is not the documented API.",
   "source": "https://learn.microsoft.com/en-us/nuget/api/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "modalities.api.auth[0]",
   "note": "Push, delete or unlist, and relist require the X-NuGet-ApiKey header. The overview says that on nuget.org only PackagePublish requires authentication.",
   "source": "https://learn.microsoft.com/en-us/nuget/api/package-publish-resource",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "modalities.api.coverage",
   "note": "Required resources include package content, metadata, search, and publish. Other resources are optional. Private-feed authentication is left to the source. Coverage is partial.",
   "source": "https://learn.microsoft.com/en-us/nuget/api/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "modalities.api.docs",
   "note": "Opened as the current NuGet Server API overview.",
   "source": "https://learn.microsoft.com/en-us/nuget/api/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "modalities.data_access.export[0]",
   "note": "PackageBaseAddress gets package content as a .nupkg.",
   "source": "https://learn.microsoft.com/en-us/nuget/api/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "modalities.data_access.import[0]",
   "note": "Push sends the raw bytes of a .nupkg to the PackagePublish resource.",
   "source": "https://learn.microsoft.com/en-us/nuget/api/package-publish-resource",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "modalities.mcp.first_party",
   "note": "Microsoft Learn documents the NuGet MCP server run from NuGet.Mcp.Server on nuget.org with dnx.",
   "source": "https://learn.microsoft.com/en-us/nuget/concepts/nuget-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "modalities.mcp.verdict",
   "note": "NuGet.Mcp.Server 1.4.16, updated 2026-06-30, lists six package tools and a stdio dnx config. The package prefix is reserved. Verdict is official.",
   "source": "https://www.nuget.org/packages/NuGet.Mcp.Server",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "modalities.cli.exists",
   "note": "nuget.exe documents pack, push, restore, search, and other non-interactive commands. A subset is also on the dotnet CLI for macOS and Linux.",
   "source": "https://learn.microsoft.com/en-us/nuget/reference/nuget-exe-cli-reference",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "verdict.scores.api",
   "note": "The V3 protocol is the path official clients use to search, download, and publish. nuget.org push needs an API key, and private-source auth is implementation-defined. Score 8.",
   "source": "https://learn.microsoft.com/en-us/nuget/api/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "verdict.scores.mcp",
   "note": "Official local MCP for vulnerability fixes, upgrades, and package lookup. It requires the .NET 10 SDK and is not a hosted gallery admin API. Score 7.",
   "source": "https://learn.microsoft.com/en-us/nuget/concepts/nuget-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "verdict.scores.cli",
   "note": "Official nuget.exe covers install, pack, push, restore, and search. Mono and the narrower dotnet CLI subset on macOS and Linux keep the score at 7.",
   "source": "https://learn.microsoft.com/en-us/nuget/reference/nuget-exe-cli-reference",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "freshness.watch[0].url",
   "note": "Opened and verified as the NuGet MCP server article.",
   "source": "https://learn.microsoft.com/en-us/nuget/concepts/nuget-mcp-server",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "freshness.watch[1].url",
   "note": "Opened and verified as the NuGet.Mcp.Server 1.4.16 package page.",
   "source": "https://www.nuget.org/packages/NuGet.Mcp.Server",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "freshness.watch[2].url",
   "note": "Opened and verified as the NuGet Server API overview.",
   "source": "https://learn.microsoft.com/en-us/nuget/api/overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-30",
   "fact": "freshness.watch[3].url",
   "note": "Opened and verified as the nuget.exe CLI reference.",
   "source": "https://learn.microsoft.com/en-us/nuget/reference/nuget-exe-cli-reference",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-30",
  "volatility": "medium",
  "watch": [
   {
    "type": "docs",
    "url": "https://learn.microsoft.com/en-us/nuget/concepts/nuget-mcp-server"
   },
   {
    "type": "docs",
    "url": "https://www.nuget.org/packages/NuGet.Mcp.Server"
   },
   {
    "type": "docs",
    "url": "https://learn.microsoft.com/en-us/nuget/api/overview"
   },
   {
    "type": "docs",
    "url": "https://learn.microsoft.com/en-us/nuget/reference/nuget-exe-cli-reference"
   }
  ]
 },
 "homepage": "https://www.nuget.org/",
 "id": "nuget",
 "license": "free",
 "modalities": {
  "agent_docs": {
   "llms_txt": "unknown"
  },
  "api": {
   "auth": [
    "api-key"
   ],
   "coverage": "partial",
   "docs": "https://learn.microsoft.com/en-us/nuget/api/overview",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": true
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "nupkg"
   ],
   "import": [
    "nupkg"
   ]
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. The NuGet V3 API, nuget.exe, the dotnet CLI, and the local NuGet MCP server cover package lookup and publish without browser control of nuget.org.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "NuGet",
 "platforms": [
  "windows",
  "macos",
  "linux",
  "web"
 ],
 "related": {
  "alternatives": [
   "jfrog-artifactory"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Microsoft",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 8,
   "cli": 7,
   "computer_use": null,
   "integrations": null,
   "mcp": 7,
   "overall": 8,
   "rpa": null
  },
  "summary": "NuGet is automatable today through the NuGet V3 HTTP API. This record is NuGet package feeds and the NuGet MCP server shipped as NuGet.Mcp.Server. It is not JFrog Artifactory, GitHub Packages, or npm. The nuget.org service index is https://api.nuget.org/v3/index.json. Microsoft Learn documents resources for package content, metadata, search, and publish. On nuget.org, only the PackagePublish resource requires authentication, and it uses the X-NuGet-ApiKey header for push, unlist, and relist. Reads of public packages do not use that header. nuget.exe installs, creates, publishes, and manages packages. The pack, restore, delete, locals, and push commands are also available on macOS and Linux through the dotnet CLI. Some nuget.exe commands are limited under Mono. The MCP server is local stdio through dnx. Microsoft Learn requires the .NET 10 SDK or later. NuGet.Mcp.Server 1.4.16 lists fix_vulnerable_packages, upgrade_packages_to_latest, get_latest_package_version, get_package_context, update_package_version, and review_supply_chain_security. Visual Studio 2026 includes the server and it must be enabled. Visual Studio 2022 17.14 or later uses a manual stdio config aimed at the nuget.org service index. The package page for 1.4.16 still says .NET 10 Preview 6 or later. Webhooks and an llms.txt index were not established. iPaaS catalogs were not opened. Computer-use viability is unassessed. The API scores 8, the CLI scores 7, and MCP scores 7. API is the best path because an HTTP client can search, download, and publish without the .NET 10 SDK.\n"
 }
}