Check package compliance

Check whether a package version is allowed by Curation policies and, when it is blocked, return compliant alternatives when they exist.

Requires a user with READ permissions. Curation must be enabled.

Supported package_type values are npm, PyPI, Gems, NuGet, Maven, Gradle, and SBT. Other curated types (for example Docker) return HTTP 400.

CLI and other non-agent callers must send remote_source_url (typically the Artifactory download URL). Agent callers set X-JFrog-Curation-Agentic-Request to true and must send package_version. Gradle and SBT use the same Artifactory path layout as Maven.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params
string
required

Package name. For Maven, Gradle, and SBT, use groupId:artifactId.

string
enum
required

Package types accepted by the Compliance API. Values are case-insensitive and normalized to these PrettyName strings.

Allowed:
string

Package version. Required when X-JFrog-Curation-Agentic-Request is true.

uri

Artifactory or public download URL used to resolve the curated repository. Required for CLI and other non-agent callers. Gradle and SBT URLs use the Maven repository layout.

Headers
string
enum

Set to true when the caller is an LLM agent. Agent requests require package_version and do not require remote_source_url.

Allowed:
Responses

Language
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json