Export SBOM reports for cloud workloads from Orca Security

domain: docs.orcasecurity.io · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Authenticate to the Orca API using your API token in the Authorization: Token YOUR_TOKEN header.
  2. Use the Orca API or console to trigger an SBOM export for a specific asset type (container image, virtual machine, or serverless function) by specifying asset filters in the request body.
  3. Retrieve the scheduled or on-demand SBOM report in SPDX, CycloneDX, or JSON format via the reports endpoint; check the report's status field before downloading.
  4. Download the completed SBOM file using the download URL returned in the report metadata response.
  5. Use the SBOM output to feed downstream vulnerability scanning pipelines (e.g., Grype) or compliance tooling that requires a package inventory.
  6. Schedule recurring SBOM exports through Orca's report scheduler and configure delivery to a cloud storage bucket or email destination via the integration settings.

Known gotchas

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans