Skip to content

OWASP ASVS API

How do I query OWASP ASVS data over an API?

Point a GET request at api.theartofservice.com/api/agent/frameworks/OWASP ASVS, or add the MCP server to Claude Desktop or Cursor with the config below. You get 14 controls, 14 domains and every cross-framework mapping this standard carries. The free tier is 10 calls a day and needs no signup or API key.

14
Controls
14
Domains
174+
Mappings
Free
API Price

Add OWASP ASVS to Claude Desktop or Cursor in one config block

Copy this config into your MCP client to start querying OWASP ASVS data with AI:

{
  "mcpServers": {
    "compliance": {
      "url": "https://api.theartofservice.com/mcp"
    }
  }
}

No API key required for up to 10 calls/day. Works with Claude Desktop, Cursor, Windsurf, and any MCP-compatible client.

Three curl calls that return OWASP ASVS data

Get OWASP ASVS details

curl https://api.theartofservice.com/api/agent/frameworks/OWASP%20ASVS

List all OWASP ASVS controls

curl https://api.theartofservice.com/api/agent/frameworks/OWASP%20ASVS/controls

Map OWASP ASVS to another framework

curl "https://api.theartofservice.com/api/agent/cross-map?source=OWASP%20ASVS&target=SOC%202"

Install the Python or npm client

Python (Langchain)

pip install theartofservice-compliance

npm (MCP Server)

npx @theartofservice/compliance-mcp

Questions developers ask about the OWASP ASVS API

Is there an API for OWASP ASVS?
Yes. The Art of Service provides a REST API and MCP server with full OWASP ASVS data: 14 controls across 14 domains, plus cross-framework mappings to 686 other compliance frameworks. Free tier includes 10 calls/day with no signup.
How do I access OWASP ASVS controls programmatically?
Use the Compliance Intelligence API at api.theartofservice.com. Call GET /api/agent/frameworks/OWASP%20ASVS/controls to retrieve all 14 controls with codes, titles, and descriptions. Supports filtering by domain.
Can I map OWASP ASVS controls to other frameworks?
Yes. The API provides cross-framework mapping with 311K+ verified control-to-control mappings. Call GET /api/agent/cross-map?source=OWASP%20ASVS&target=TARGET to map OWASP ASVS controls to any of 686 frameworks.
Does the OWASP ASVS API work with Claude, ChatGPT, or Cursor?
Yes. The API is available as an MCP (Model Context Protocol) server. Add it to Claude Desktop, Cursor, or any MCP-compatible client with a single JSON config snippet. AI agents can then query OWASP ASVS data directly.
How much does the OWASP ASVS API cost?
Anonymous access is free (10 calls/day). Free accounts get 100 calls/month. Professional plans start at $149/month with 10,000 calls included. No credit card required for free tier.

What OWASP ASVS actually requires

The API returns the data. If you want the standard explained first, with its controls, domains and the frameworks it overlaps with, that is on the OWASP ASVS framework page.

OWASP ASVS controls, domains and mappings →
Written and maintained by Gerard Blokdyk, The Art of Service.Last updated .

Start using the OWASP ASVS API today

No signup required for 10 free API calls per day. Create a free account for 100 calls/month.