How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Crowd.dev Packages API

Package detail — requires read:packages and read:stewardships (see TODO above).

Crowd.dev Packages API is one of 16 APIs that Crowd.dev publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Packages. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 14 operations across 14 paths, and defines 35 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against 2 base URLs: https://cm.lfx.dev/api/v1, https://lf-staging.crowd.dev/api/v1.

14 operations 14 paths 35 schemas 12 GET2 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://cm.lfx.dev/api/v1
Authentication
OAuth 2.0, HTTP Bearer
Resource Areas
1

Authentication & Security 2

Crowd.dev Packages API declares 2 security schemes for authenticating requests. It supports OAuth 2.0 (M2MBearer) using the clientCredentials flow, exposing 3 scopes. It accepts HTTP bearer tokens (JWT) (BearerAuth).

  • M2MBearer — Auth0 machine-to-machine client-credentials flow. Akrites exchanges its client ID/secret with Auth0 for a JWT and sends it as Authorization: Bearer ; CDP only…

Paths & Operations 14

Across 14 paths, the API surfaces 14 operations — 12 GET, 2 POST. Each is listed below with its method, path, parameters, and response codes.

Packages 14

Package detail — requires read:packages and read:stewardships (see TODO above).

GET
/akrites-external/packages/detail
Get package detail by PURL
getPackageDetail 1 param → 200400401403404
POST
/akrites-external/packages/detail:batch
Bulk package detail lookup
getPackageDetailBatch body → 200400401403
GET
/akrites/packages
List packages with stewardship data
listAkritesPackages 13 params → 200400401
GET
/akrites/packages/scatter
Get risk matrix scatter data
getAkritesPackagesScatter → 200401
GET
/akrites/packages/metrics
Get package count metrics
getAkritesPackagesMetrics → 200401
GET
/akrites/packages/detail
Get package detail
getAkritesPackageDetail 1 param → 200400401404
GET
/akrites/packages/advisories
Get advisories for a package
getAkritesPackageAdvisories 6 params → 200400401404
GET
/akrites/packages/history
Get stewardship history for a package
getAkritesPackageHistory 1 param → 200400401404
POST
/akrites/packages:batch-stewardship
Batch stewardship lookup by PURL
batchGetStewardship body → 200400401
GET
/ossprey/packages
Filtered paginated package list
listOsspreyPackages 13 params → 200400401
GET
/ossprey/packages/scatter
Scatter plot data for the Risk Matrix tab
getOsspreyPackagesScatter → 200401
GET
/packages
List packages
listPackages 9 params → 200400401403
GET
/packages/metrics
Overview metrics for the list page header
getPackagesMetrics → 200401403
GET
/packages/detail
Get full package detail
getPackage 1 param → 200404401403

Schemas 35

The contract defines 35 schemas that model the data the API accepts and returns. The most detailed are PackageRow (16 properties), PackageListRow (14 properties), PackageDetail (11 properties), PackageListItem (11 properties). Each schema is shown below with its type and property counts.

HealthBand
string
Health band on the internal scale (best→worst), returned verbatim — no external crosswalk.
Error
object
1 property 1 required
PackageDetailBulkEntry
object
3 properties 3 required
PackageDetail
object
11 properties 11 required
Ecosystem
string
StewardEntry
object
7 properties 5 required
HealthBand_2
string
Derived from scorecardScore: null or < 3.0 → critical · < 5.0 → concerning · < 7.0 → fair · ≥ 7.0 → healthy
StewardshipStatus
string
SecurityContactConfidence
string
PackageMetrics
object
1 property 1 required
Advisory
object
4 properties 4 required
Error_2
object
1 property 1 required
StatusCounts
object
Count of packages per stewardship status (used to drive filter pill badges).
9 properties 9 required
PackageHistoryEvent
object
7 properties 4 required
SecurityContact
object
5 properties 5 required
Steward
object
3 properties 3 required
PackageStewardshipSummary
object
Slim stewardship summary returned per-purl by the batch endpoint.
10 properties 2 required
PaginationMeta
object
3 properties 3 required
PackageListRow
object
14 properties 7 required
PackageDetail_2
object
10 properties 9 required
ScatterPoint
object
9 properties 7 required
EscalationResolutionPath
string
Error_3
object
1 property 1 required
StatusCounts_2
object
Per-status package counts for the tab bar. Computed without the active status filter.
9 properties 9 required
HealthBand_3
string
Tinybird band when enriched (excellent ≥85, healthy 70–84, fair 50–69, concerning 30–49, critical <30). Falls back to scorecard thresholds: null or < 3.0 → cri…
PackageRow
object
16 properties 7 required
ScatterPoint_2
object
9 properties 7 required
Error_4
object
1 property 1 required
Advisory_2
object
3 properties 2 required
SecurityContact_2
object
2 properties 1 required
OpenVulns
object
Open vulnerability counts by severity from advisorypackages + advisories.
4 properties 4 required
Steward_2
object
5 properties 3 required
PackageDetail_3
object
10 properties 8 required
PackageListItem
object
11 properties 3 required
PackagesMetrics
object
2 properties 2 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

crowddev-packages-api-openapi.yml Raw ↑

Other APIs Crowd.dev publishes across the network.

Crowd.dev Advisories API
Crowd.dev Affiliations API
Crowd.dev Contacts API
Crowd.dev Dashboard API
Crowd.dev Maintainer Roles API
Crowd.dev Member Affiliations API API
Crowd.dev Member Identities API
Crowd.dev Member Organizations API API
Crowd.dev Members API
Crowd.dev Organizations API
Crowd.dev Project Affiliations API
Crowd.dev Stewardship Actions API
Where this information came from

This is an independent, third-party profile of Crowd.dev Packages API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.