API (1.0)
Download the OpenAPI specification
OSV API
Want a quick example?
Please see the quickstart.
How does the API work?
There are six different types of requests that can be made of the API.
- Query vulnerabilities for a particular project at a given commit hash or version.
- Batched query vulnerabilities for given package versions and commit hashes.
- Return a
Vulnerabilityobject for a given OSV ID. - Return a list of probable versions of a specified C/C++ project. (Experimental)
- Retrieve records failing import-time quality checks, by record source (Experimental)
- Map Ubuntu binary package names to their corresponding source package names. (Experimental)
Is the API rate limited?
Currently there are no limits on the API.
Are there any response size limits?
The API has a response size limit of 32MiB when using HTTP/1.1. There is no limit when using HTTP/2.
We recommend using HTTP/2 for queries that may result in large responses (e.g. big OSV Linux queries).