{
  "schema": "kallipolis.resource-quality.v1",
  "id": "resource.public-data.nist-nvd-vulnerabilities-api",
  "version": "1.0.0",
  "title": "NIST NVD Vulnerabilities API boundary",
  "summary": "Official-source access, authentication, request-shaping, paging, freshness, legal, and interpretation boundaries for NIST NVD Vulnerabilities API.",
  "content": {
    "kind": "public-data-api-boundary",
    "facts": [
      {
        "id": "fact.nist.nvd-vulnerabilities-api.access",
        "statement": "The NVD Vulnerabilities API 2.0 exposes CVE records and NVD enrichment with identifiers, date windows, keyword, weakness, configuration, and severity filters.",
        "normativeLevel": "informative",
        "sourceIds": [
          "source.nist.nvd-vulnerabilities-api"
        ]
      },
      {
        "id": "fact.nist.nvd-vulnerabilities-api.authentication",
        "statement": "An API key is optional for lower-volume access and is recommended for sustained synchronization; keys are credentials and belong in headers rather than public assets.",
        "normativeLevel": "informative",
        "sourceIds": [
          "source.nist.nvd-vulnerabilities-api"
        ]
      },
      {
        "id": "fact.nist.nvd-vulnerabilities-api.request",
        "statement": "Clients should use modification windows, results-per-page, start index, backoff, and the published rate limits instead of repeatedly downloading the full collection.",
        "normativeLevel": "informative",
        "sourceIds": [
          "source.nist.nvd-vulnerabilities-api"
        ]
      },
      {
        "id": "fact.nist.nvd-vulnerabilities-api.boundary",
        "statement": "NVD enrichment and CVE source data can change or remain incomplete and do not prove exploitability, affected deployment, remediation success, or a complete risk assessment.",
        "normativeLevel": "informative",
        "sourceIds": [
          "source.nist.nvd-vulnerabilities-api"
        ]
      }
    ]
  },
  "language": "en",
  "category": "public-data-api",
  "state": "prepared",
  "canonicalUrl": "https://platoskallipolis.com/resources/public-data-apis/nist-nvd-vulnerabilities-api.json",
  "contentHash": "sha256:5264fe3bcc2b66a22ac66fb9d22be3065a7ec0bb8e4b6c9e60a8efaa2239a47c",
  "owner": {
    "id": "platos-kallipolis",
    "name": "Plato's Kallipolis",
    "type": "organization",
    "accountabilityUrl": "https://platoskallipolis.com/about"
  },
  "access": {
    "mode": "public",
    "url": "https://platoskallipolis.com/resources/public-data-apis/nist-nvd-vulnerabilities-api.json",
    "authentication": "none",
    "robotsAllowed": true
  },
  "provenance": {
    "method": "primary-source",
    "sources": [
      {
        "id": "source.nist.nvd-vulnerabilities-api",
        "url": "https://nvd.nist.gov/developers/vulnerabilities",
        "title": "NVD Vulnerabilities API",
        "publisher": "U.S. National Institute of Standards and Technology",
        "observedAt": "2026-08-27T09:30:00Z"
      }
    ]
  },
  "observedAt": "2026-08-27T09:30:00Z",
  "freshness": {
    "policy": "max-age",
    "state": "current",
    "nextReviewAt": "2026-09-03T09:30:00Z",
    "maxAgeSeconds": 604800
  },
  "license": {
    "id": "source-terms-apply",
    "url": "https://www.nist.gov/disclaimer",
    "redistributionAllowed": false
  },
  "evidence": [
    {
      "id": "evidence.nist.nvd-vulnerabilities-api",
      "type": "source-claim",
      "url": "https://nvd.nist.gov/developers/vulnerabilities",
      "observedAt": "2026-08-27T09:30:00Z"
    }
  ]
}
