Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC
JFrog website screenshot

JFrog

JFrog provides universal DevOps solutions for software supply chain automation and security, offering a unified platform for managing binaries, securing the software supply chain, and automating DevOps workflows.

agent native

Reference-quality API operations across every facet — a rich contract, published governance, transparent operations, and machine-readable commercial terms.

Kin Score

API Evangelist profiles JFrog the way a machine reads it — 230 machine-readable artifacts across 53 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.

Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — JFrog scores 77.6/100 (exemplar), with a separate agent-readiness read of 70/100 (agent native). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.

Kin Score

This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 77.6/100 · exemplar
Contract Quality 16.7 / 25
Developer Ergonomics 16.1 / 20
Commercial Clarity 16.8 / 20
Operational Transparency 9.9 / 13
Governance 8.8 / 12
Discoverability 9.3 / 10
Agent readiness — 70/100 · agent native
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 6 / 6
Agent Skills 5 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3

How we profile JFrog

Each block below is one kind of artifact we hold for JFrog. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.

APIs 53

Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.

Individual APIs this provider publishes, each with its own machine-readable definition.

JFrog Access Tokens API

Token creation and management

JFrog Artifacts & Storage API

Deploy, retrieve, copy, move, and delete artifacts

JFrog Audit API

Curation audit and activity logs

JFrog Builds API

Build information and promotion

JFrog Commands API

Remote command execution on devices

JFrog Components API

Component details and vulnerability information

JFrog Deployments API

Model deployment and serving

JFrog Device Groups API

Logical grouping of devices

JFrog Devices API

Device management and monitoring

JFrog Distribution API

Distribute release bundles to edge nodes

JFrog Evidence API

Create and manage evidence attestations

JFrog Execution API

Worker testing and execution

JFrog Experiments API

ML experiment tracking

JFrog GraphQL API

GraphQL query interface for package and CVE data

JFrog Groups API

User group management

JFrog Ignore Rules API

Rules for ignoring specific vulnerabilities

JFrog Integrations API

External service integrations

JFrog JPDs API

JFrog Platform Deployment management

JFrog Labels API

Custom label management for packages

JFrog Licenses API

License management across instances

JFrog Model Versions API

Model version management

JFrog Models API

ML model registry and management

JFrog Node Pools API

Build node pool management

JFrog Packages API

Package metadata search and retrieval

JFrog Permissions API

Permission target management

JFrog Pipeline Sources API

Manage pipeline source configurations

JFrog Pipelines API

Pipeline definitions and management

JFrog Policies API

Curation policy management

JFrog Projects API

Project administration

JFrog Promotion API

Promote release bundles through environments

JFrog Properties API

Set, update, and delete artifact properties

JFrog Release Bundles V1 API

Create and manage release bundles (v1)

JFrog Release Bundles V2 API

Create and manage release bundles v2

JFrog Replication API

Push and pull replication configuration

JFrog Reports API

Vulnerability and compliance reports

JFrog Repositories API

Create, read, update, and delete repositories

JFrog Runs API

Pipeline run execution and monitoring

JFrog Scanning API

On-demand scanning operations

JFrog Scripts API

Remote execution scripts

JFrog Searches API

Search for artifacts using various criteria

JFrog Security API

Users, groups, permissions, and access tokens

JFrog Steps API

Pipeline step execution details

JFrog Summary API

Artifact and build vulnerability summaries

JFrog System API

Access service system information

JFrog System & Configuration API

System health, configuration, and version information

JFrog Tokens API

Access token creation, management, and revocation

JFrog Updates API

OTA software update deployments

JFrog Users API

Platform user management

JFrog Verification API

Verify evidence and retrieve verification status

JFrog Violations API

Policy violations management

JFrog Watches API

Watch policies for monitoring artifacts

JFrog Webhooks API

Webhook configuration

JFrog Workers API

Worker lifecycle management

Scroll within the panel for all 53 ·

Postman Collections 14

A runnable collection turns the contract into something a developer can execute in seconds. We profile them because the fastest way to trust an API is to make a real call against it.

Ready-to-run Postman collections for exercising this provider's APIs.

Scroll within the panel for all 14 ·

Open Collections 14

Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Scroll within the panel for all 14 ·

Arazzo Workflows 25

Real integrations are rarely a single call. Arazzo describes the multi-step sequences — auth, then create, then confirm — so both a human and an agent can follow the choreography, not just the endpoints.

Multi-step API workflows described with the Arazzo specification.

JFrog Access Create User With Group

Create a group then a user in that group via the Access service.

ARAZZO

JFrog Access Provision Project

Create a project, add a user to it, and confirm the project.

ARAZZO

JFrog Attach Build Evidence

Create signed evidence for a build then verify its signature.

ARAZZO

JFrog Cleanup Stale Artifacts

Run an AQL search for stale artifacts and delete the first match.

ARAZZO

JFrog Configure Repository Replication

Confirm a repository exists then configure push replication for it.

ARAZZO

JFrog Curation Policy Setup

Create a curation policy then review its audit log.

ARAZZO

JFrog Deploy and Verify Artifact

Deploy an artifact to a repository and confirm its storage metadata.

ARAZZO

JFrog Distribution Release Bundle

Create a release bundle, sign it, distribute it, and poll for status.

ARAZZO

JFrog Grant Repository Permission

Create a permission target granting a group access to a repository.

ARAZZO

JFrog ML Register Model Version

Register an ML model then publish a version of it.

ARAZZO

JFrog Pipelines Trigger and Monitor

Trigger a pipeline run, find the new run, and poll until it finishes.

ARAZZO

JFrog Platform Register Webhook

Create a platform webhook subscription and confirm it.

ARAZZO

JFrog Platform Rotate Access Token

Issue a fresh platform token then revoke a superseded one.

ARAZZO

JFrog Promote Artifact by Checksum

Find an artifact by its checksum and copy it to a release repository.

ARAZZO

JFrog Promote Build

Resolve a build run and promote it to a target repository.

ARAZZO

JFrog Provision Local Repository

Create a local Artifactory repository and confirm its configuration.

ARAZZO

JFrog Release Bundle v2 Promote

Create a v2 release bundle from a build and promote it to an environment.

ARAZZO

JFrog Secure Publish Artifact

Deploy an artifact then immediately scan it with Xray for issues.

ARAZZO

JFrog Worker Deploy and Test

Create a worker, run a test payload, then enable it on success.

ARAZZO

JFrog Xray Component License Check

Look up component details then confirm via the catalog version data.

ARAZZO

JFrog Xray Policy and Watch

Create a security policy then a watch that assigns it to a repository.

ARAZZO

JFrog Xray Scan Artifact

Trigger an Xray scan for an artifact then pull its security summary.

ARAZZO

JFrog Xray Scan Build

Trigger an Xray CI build scan then read the build security summary.

ARAZZO

JFrog Xray Triage Violation

Query Xray violations and create an ignore rule when any are found.

ARAZZO

JFrog Xray Vulnerability Report

Generate a vulnerability report and poll until it completes.

ARAZZO

Scroll within the panel for all 25 ·

MCP Servers 1

Model Context Protocol servers expose these APIs directly to AI agents. We profile them because agent-native access is the fastest-growing way this provider's capabilities actually get used.

Model Context Protocol servers that expose these APIs to AI agents.

MCP Server

MCP SERVER

Agent Skills 2

An agent skill packages the how-to for driving these APIs from an assistant — the prompts, the sequence, the guardrails — so the knowledge to use the API travels with it.

Packaged agent skills for driving this provider's APIs from an AI assistant.

GraphQL 1

Where a provider ships GraphQL, the schema is the contract. We profile it alongside the REST surface so the whole interface is legible in one place.

GraphQL schemas published by this provider.

Pricing Plans 1

Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.

Published pricing tiers and plan structures.

Jfrog Plans Pricing

8 plans

PLANS

Rate Limits 1

Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.

Documented rate limits and quota policies.

Jfrog Rate Limits

3 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.

Cost, billing, and metering signals for API financial operations.

Jfrog Finops

FINOPS

Semantic Vocabularies 1

JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.

JSON-LD contexts and semantic vocabularies used across these APIs.

Jfrog Context

9 classes · 13 properties

JSON-LD

Spectral Rules 1

Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.

JFrog API Rules

6 rules · 4 warnings

SPECTRAL

JSON Schema 110

Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.

Standalone JSON Schema definitions for this provider's data models.

AccessToken

5 properties

JSON SCHEMA

AqlSearchResult

2 properties

JSON SCHEMA

JFrog Artifact

16 properties

JSON SCHEMA

ArtifactSummary

1 properties

JSON SCHEMA

AuditEntry

9 properties

JSON SCHEMA

JFrog Build Info

16 properties

JSON SCHEMA

BuildInfo

1 properties

JSON SCHEMA

BuildPromotion

11 properties

JSON SCHEMA

BuildRuns

2 properties

JSON SCHEMA

BuildsList

1 properties

JSON SCHEMA

BuildSummary

2 properties

JSON SCHEMA

CatalogVulnerability

9 properties

JSON SCHEMA

Checksums

3 properties

JSON SCHEMA

CommandRequest

4 properties

JSON SCHEMA

ComponentDetail

6 properties

JSON SCHEMA

CreateEvidenceRequest

6 properties

JSON SCHEMA

CreateTokenRequest

8 properties

JSON SCHEMA

CreateUserRequest

7 properties

JSON SCHEMA

JFrog Curation Policy

10 properties

JSON SCHEMA

CurationPolicy

10 properties

JSON SCHEMA

CurationPolicyRequest

8 properties

JSON SCHEMA

Deployment

9 properties

JSON SCHEMA

DeploymentRequest

5 properties

JSON SCHEMA

DeployResponse

10 properties

JSON SCHEMA

Device

13 properties

JSON SCHEMA

DeviceGroup

5 properties

JSON SCHEMA

DeviceGroupRequest

3 properties

JSON SCHEMA

DistributeRequest

2 properties

JSON SCHEMA

DistributionRequest

3 properties

JSON SCHEMA

JFrog Evidence

11 properties

JSON SCHEMA

EvidenceRequest

6 properties

JSON SCHEMA

EvidenceSearchRequest

7 properties

JSON SCHEMA

Experiment

10 properties

JSON SCHEMA

ExperimentRequest

4 properties

JSON SCHEMA

FileInfo

13 properties

JSON SCHEMA

FolderInfo

9 properties

JSON SCHEMA

GraphQLRequest

3 properties

JSON SCHEMA

GraphQLResponse

2 properties

JSON SCHEMA

Group

7 properties

JSON SCHEMA

GroupSummary

2 properties

JSON SCHEMA

IgnoreRule

10 properties

JSON SCHEMA

Integration

7 properties

JSON SCHEMA

IntegrationRequest

5 properties

JSON SCHEMA

Issue

9 properties

JSON SCHEMA

ItemProperties

2 properties

JSON SCHEMA

JPD

7 properties

JSON SCHEMA

JPDRequest

4 properties

JSON SCHEMA

Label

6 properties

JSON SCHEMA

LabelRequest

3 properties

JSON SCHEMA

LicenseBucket

6 properties

JSON SCHEMA

LicenseInfo

3 properties

JSON SCHEMA

Model

11 properties

JSON SCHEMA

ModelRequest

5 properties

JSON SCHEMA

ModelVersion

10 properties

JSON SCHEMA

ModelVersionRequest

6 properties

JSON SCHEMA

MoveOrCopyResponse

1 properties

JSON SCHEMA

NodePool

9 properties

JSON SCHEMA

NodePoolRequest

6 properties

JSON SCHEMA

PackageDetail

10 properties

JSON SCHEMA

PackageSearchRequest

7 properties

JSON SCHEMA

PackageSearchResponse

2 properties

JSON SCHEMA

PackageSummary

7 properties

JSON SCHEMA

PackageVersion

7 properties

JSON SCHEMA

JFrog Permission Target

2 properties

JSON SCHEMA

PermissionTarget

3 properties

JSON SCHEMA

PermissionTargetSummary

2 properties

JSON SCHEMA

JFrog Pipeline

9 properties

JSON SCHEMA

PipelineSource

9 properties

JSON SCHEMA

PipelineSourceRequest

6 properties

JSON SCHEMA

PlatformGroup

7 properties

JSON SCHEMA

PlatformUser

8 properties

JSON SCHEMA

Policy

4 properties

JSON SCHEMA

Project

8 properties

JSON SCHEMA

ProjectRequest

5 properties

JSON SCHEMA

PromotionRequest

5 properties

JSON SCHEMA

PromotionStatus

4 properties

JSON SCHEMA

JFrog Release Bundle

13 properties

JSON SCHEMA

ReleaseBundle

8 properties

JSON SCHEMA

ReleaseBundleRequest

7 properties

JSON SCHEMA

ReleaseBundleV2

9 properties

JSON SCHEMA

ReleaseBundleV2Request

5 properties

JSON SCHEMA

ReleaseBundleV2Summary

6 properties

JSON SCHEMA

ReplicationConfig

12 properties

JSON SCHEMA

JFrog Repository

20 properties

JSON SCHEMA

RepositoryConfiguration

15 properties

JSON SCHEMA

RepositoryListItem

5 properties

JSON SCHEMA

Run

10 properties

JSON SCHEMA

Script

5 properties

JSON SCHEMA

ScriptRequest

3 properties

JSON SCHEMA

SearchResult

1 properties

JSON SCHEMA

JFrog Security Vulnerability

16 properties

JSON SCHEMA

Step

9 properties

JSON SCHEMA

StorageSummary

3 properties

JSON SCHEMA

SystemHealth

2 properties

JSON SCHEMA

SystemVersion

4 properties

JSON SCHEMA

TokenInfo

9 properties

JSON SCHEMA

TokenResponse

7 properties

JSON SCHEMA

Update

10 properties

JSON SCHEMA

UpdateRequest

12 properties

JSON SCHEMA

UpdateUserRequest

7 properties

JSON SCHEMA

JFrog Platform User

11 properties

JSON SCHEMA

UserSummary

4 properties

JSON SCHEMA

VerificationResult

6 properties

JSON SCHEMA

ViolationsResponse

2 properties

JSON SCHEMA

Vulnerability

9 properties

JSON SCHEMA

Watch

3 properties

JSON SCHEMA

Webhook

7 properties

JSON SCHEMA

WebhookRequest

7 properties

JSON SCHEMA

JFrog Worker

9 properties

JSON SCHEMA

WorkerRequest

7 properties

JSON SCHEMA

Scroll within the panel for all 110 ·

JSON Structure 1

JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.

JSON Structure definitions describing this provider's data shapes.

Jfrog Structure

0 properties

JSON STRUCTURE

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Jfrog Authentication

apiKey/http · 4 schemes

SECURITY

Jfrog Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Jfrog Vulnerability Disclosure

security.txt · contact published

SECURITY

Agentic Access 1

An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.

Recommended x-agentic-access execution contracts for AI agents.

Jfrog Agentic Access

260 operations · 137 acting · 3 human-in-the-loop

260 operations · 137 acting

AGENTIC

Resources

Every other property we hold for JFrog — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.

Get Started 4

Portal, sign-up, and the first successful call

Agent Surfaces 4

MCP servers, agent skills, and machine-readable catalogs

Learn 2

Tutorials, courses, talks, and written guidance

Commercial 3

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 1

Properties that don't map to a standard resource type

← All providers · Data indexed from github.com/api-evangelist/jfrog · machine-readable index on apis.io