{
 "categories": [
  "developer-tools",
  "quality-management"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-03",
   "fact": "homepage",
   "note": "Snyk presents an AI security platform that validates AI-generated code and integrates with IDEs, CI/CD, and coding assistants. The page offers a free account.",
   "source": "https://snyk.io/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "license",
   "note": "Snyk publishes a Free plan at $0 plus paid Team, Ignite, and Enterprise plans. Free includes SCA, SAST, IaC, and Container with stated monthly test limits.",
   "source": "https://snyk.io/plans/",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.api.exists",
   "note": "Snyk documents REST and V1 APIs covering organizations, projects, issues, SBOM, service accounts, and related resources. The overview states the API is mostly available on Enterprise plans.",
   "source": "https://docs.snyk.io/developer-tools/snyk-api",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.api.kinds[0]",
   "note": "The Snyk REST API is HTTPS JSON:API, defined in OpenAPI 3.0.3, with regional bases such as https://api.snyk.io/rest.",
   "source": "https://docs.snyk.io/developer-tools/snyk-api/rest-api/about-the-rest-api",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.api.auth[0]",
   "note": "Direct API calls authenticate with a personal API token in an Authorization: token header. The page states the API requires an Enterprise plan.",
   "source": "https://docs.snyk.io/developer-tools/snyk-api/authentication-for-api",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.api.auth[1]",
   "note": "Snyk Apps APIs authenticate with an OAuth access token in an Authorization: bearer header.",
   "source": "https://docs.snyk.io/developer-tools/snyk-api/authentication-for-api",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.api.coverage",
   "note": "The API index lists REST and V1 resources for projects, issues, orgs, SBOM, exports, and more. Access is gated to Enterprise plans, so coverage is the management API for that edition, not every Snyk UI action.",
   "source": "https://docs.snyk.io/developer-tools/snyk-api",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.mcp.first_party",
   "note": "Snyk documents an official local MCP server invoked as npx -y snyk@latest mcp -t stdio. The same page states Snyk does not offer a hosted remote MCP server.",
   "source": "https://docs.snyk.io/agent-security/agentic-security-with-snyk-studio/getting-started-with-snyk-studio",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.cli.exists",
   "note": "Snyk documents an official CLI installed via Homebrew, npm, Yarn, Scoop, Docker (snyk/snyk), GitHub Actions, or standalone binaries for macOS, Linux, and Windows.",
   "source": "https://docs.snyk.io/developer-tools/snyk-cli/snyk-cli/install-the-snyk-cli",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.extensibility.webhooks",
   "note": "Snyk documents outbound HTTPS webhooks for recurring open-source and container scan events, signed with X-Hub-Signature. The Webhooks API is in beta and limited to US-01, US-02, EU-01, and AU-01.",
   "source": "https://docs.snyk.io/developer-tools/snyk-api/using-specific-snyk-apis/webhooks-apis/about-webhooks",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.data_access.export[0]",
   "note": "REST responses are JSON:API documents with a data array and pagination links.",
   "source": "https://docs.snyk.io/developer-tools/snyk-api/rest-api/about-the-rest-api",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "Snyk publishes https://docs.snyk.io/llms.txt as a documentation index covering the platform, CLI, API, and agent-security pages.",
   "source": "https://docs.snyk.io/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "verdict.scores.api",
   "note": "The REST API is documented and versioned, but vendor docs restrict API access to Enterprise plans. Free and Team tokens are for CLI, IDE, and CI only. That is useful coverage with a material edition gate.",
   "source": "https://docs.snyk.io/developer-tools/snyk-api/authentication-for-api",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "verdict.scores.mcp",
   "note": "The official MCP server exposes SCA, SAST, IaC, container, SBOM, and package-health tools through the CLI. It is local STDIO only, so the path is official and useful rather than a hosted production MCP.",
   "source": "https://docs.snyk.io/agent-security",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "verdict.scores.cli",
   "note": "The official CLI has OAuth, PAT, and token auth, SNYK_TOKEN for CI, regional environment config, and is the process that serves MCP. That is a broad, maintained production path.",
   "source": "https://docs.snyk.io/developer-tools/snyk-cli/snyk-cli/authenticate-to-use-the-cli",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "freshness.watch[0].url",
   "note": "Opened Snyk's agent-security overview. It documents Snyk Studio, a local CLI MCP server, supported ADEs, and the scan tool list.",
   "source": "https://docs.snyk.io/agent-security",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "freshness.watch[1].url",
   "note": "Opened the Snyk Studio getting-started page. It documents hooks-based install, the npx stdio MCP config, Lite/Full/Experimental profiles, and the explicit statement that Snyk does not offer a hosted remote MCP server.",
   "source": "https://docs.snyk.io/agent-security/agentic-security-with-snyk-studio/getting-started-with-snyk-studio",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "freshness.watch[2].url",
   "note": "Opened and verified as the current Snyk API authentication page, including the Enterprise plan gate and token versus bearer schemes.",
   "source": "https://docs.snyk.io/developer-tools/snyk-api/authentication-for-api",
   "tier": "declared"
  },
  {
   "date": "2026-09-03",
   "fact": "freshness.watch[3].url",
   "note": "Opened and verified as the current official Snyk CLI install page for package managers, Docker, GitHub Actions, and standalone binaries.",
   "source": "https://docs.snyk.io/developer-tools/snyk-cli/snyk-cli/install-the-snyk-cli",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-03",
  "volatility": "high",
  "watch": [
   {
    "type": "mcp",
    "url": "https://docs.snyk.io/agent-security"
   },
   {
    "type": "mcp",
    "url": "https://docs.snyk.io/agent-security/agentic-security-with-snyk-studio/getting-started-with-snyk-studio"
   },
   {
    "type": "docs",
    "url": "https://docs.snyk.io/developer-tools/snyk-api/authentication-for-api"
   },
   {
    "type": "docs",
    "url": "https://docs.snyk.io/developer-tools/snyk-cli/snyk-cli/install-the-snyk-cli"
   }
  ]
 },
 "homepage": "https://snyk.io/",
 "id": "snyk",
 "license": "freemium",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "api-token",
    "oauth2-bearer"
   ],
   "coverage": "partial",
   "docs": "https://docs.snyk.io/developer-tools/snyk-api/rest-api/about-the-rest-api",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": true
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "api-json"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": true
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Snyk's official CLI, local MCP server, REST API, and beta webhooks cover practical scan and issue automation without browser control.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Snyk",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "github",
   "gitlab",
   "sentry"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Snyk",
 "verdict": {
  "best_path": "cli",
  "scores": {
   "api": 6,
   "cli": 8,
   "computer_use": null,
   "integrations": null,
   "mcp": 7,
   "overall": 8,
   "rpa": null
  },
  "summary": "Snyk is automatable today through the official Snyk CLI. This record is Snyk code and open-source security, including Snyk Studio and the first-party MCP server. It is not SonarQube, GitHub Advanced Security, or CrowdStrike Falcon. The CLI installs via npm, Homebrew, Scoop, Docker, or standalone binaries and authenticates with OAuth (snyk auth), a personal access token, or an API token. CI uses SNYK_TOKEN or SNYK_OAUTH_TOKEN. The same CLI hosts the official MCP server as `snyk mcp -t stdio` or `npx -y snyk@latest mcp -t stdio`. Snyk states it does not offer a hosted remote MCP server. Documented MCP tools include snyk_code_scan, snyk_sca_scan, snyk_iac_scan, snyk_container_scan, snyk_sbom_scan, snyk_aibom, snyk_package_health_check, and auth/trust helpers. Profiles are Lite, Full (default), and Experimental. Snyk Studio adds hooks-based Secure at Inception for Claude Code, Cursor, Codex CLI, Gemini CLI, and GitHub Copilot. The REST API at https://api.snyk.io/rest is JSON:API over HTTPS with per-endpoint versioning, cursor pagination, and a 1620-request-per-minute limit. Vendor docs state the API is for Enterprise plan customers; Free and Team personal tokens do not have API access. REST auth is Authorization: token for API tokens and Authorization: bearer for Snyk Apps OAuth access tokens. Regional bases include api.snyk.io, api.us.snyk.io, api.eu.snyk.io, and api.au.snyk.io. Outbound webhooks exist and are documented as beta. iPaaS connector catalogs were not opened. Computer-use viability is unassessed. CLI scores 8 and is the best path because it works without the Enterprise API gate and is the process that serves MCP.\n"
 }
}