Skip to content

OpenSSF Scorecard API

How do I query OpenSSF Scorecard data over an API?

Point a GET request at api.theartofservice.com/api/agent/frameworks/OpenSSF Scorecard, or add the MCP server to Claude Desktop or Cursor with the config below. You get 8 controls, 8 domains and every cross-framework mapping this standard carries. The free tier is 10 calls a day and needs no signup or API key.

8
Controls
8
Domains
147+
Mappings
Free
API Price

Add OpenSSF Scorecard to Claude Desktop or Cursor in one config block

Copy this config into your MCP client to start querying OpenSSF Scorecard data with AI:

{
  "mcpServers": {
    "compliance": {
      "url": "https://api.theartofservice.com/mcp"
    }
  }
}

No API key required for up to 10 calls/day. Works with Claude Desktop, Cursor, Windsurf, and any MCP-compatible client.

Three curl calls that return OpenSSF Scorecard data

Get OpenSSF Scorecard details

curl https://api.theartofservice.com/api/agent/frameworks/OpenSSF%20Scorecard

List all OpenSSF Scorecard controls

curl https://api.theartofservice.com/api/agent/frameworks/OpenSSF%20Scorecard/controls

Map OpenSSF Scorecard to another framework

curl "https://api.theartofservice.com/api/agent/cross-map?source=OpenSSF%20Scorecard&target=SOC%202"

Install the Python or npm client

Python (Langchain)

pip install theartofservice-compliance

npm (MCP Server)

npx @theartofservice/compliance-mcp

Questions developers ask about the OpenSSF Scorecard API

Is there an API for OpenSSF Scorecard?
Yes. The Art of Service provides a REST API and MCP server with full OpenSSF Scorecard data: 8 controls across 8 domains, plus cross-framework mappings to 686 other compliance frameworks. Free tier includes 10 calls/day with no signup.
How do I access OpenSSF Scorecard controls programmatically?
Use the Compliance Intelligence API at api.theartofservice.com. Call GET /api/agent/frameworks/OpenSSF%20Scorecard/controls to retrieve all 8 controls with codes, titles, and descriptions. Supports filtering by domain.
Can I map OpenSSF Scorecard controls to other frameworks?
Yes. The API provides cross-framework mapping with 311K+ verified control-to-control mappings. Call GET /api/agent/cross-map?source=OpenSSF%20Scorecard&target=TARGET to map OpenSSF Scorecard controls to any of 686 frameworks.
Does the OpenSSF Scorecard API work with Claude, ChatGPT, or Cursor?
Yes. The API is available as an MCP (Model Context Protocol) server. Add it to Claude Desktop, Cursor, or any MCP-compatible client with a single JSON config snippet. AI agents can then query OpenSSF Scorecard data directly.
How much does the OpenSSF Scorecard API cost?
Anonymous access is free (10 calls/day). Free accounts get 100 calls/month. Professional plans start at $149/month with 10,000 calls included. No credit card required for free tier.

What OpenSSF Scorecard actually requires

The API returns the data. If you want the standard explained first, with its controls, domains and the frameworks it overlaps with, that is on the OpenSSF Scorecard framework page.

OpenSSF Scorecard controls, domains and mappings →
Written and maintained by Gerard Blokdyk, The Art of Service.Last updated .

Start using the OpenSSF Scorecard API today

No signup required for 10 free API calls per day. Create a free account for 100 calls/month.