Use in your browser

Validate your SBOM

Validate a publicly fetchable CycloneDX or SPDX SBOM, or compare two builds for conformance drift. JSON gets full versioned-schema validation; XML and tag-value get structural, PURL, and SPDX license ID checks.

Guest includes 50 lifetime app requests. Create a free account for 100 app requests each calendar month. One allowance across every app, in your browser and your agent.One allowance across every app, in your browser and your agent. Manage usage

SBOM Check

Connect agent

Guest access is available after setup. Full account linking verified by PowMCP: Claude only.

SBOM Check

Validate one public SBOM with PURL and SPDX-license-id checks, plus full versioned-schema validation for JSON documents.

Usually finishes within 30 seconds.

Choose input source

Only the active source is sent. You can switch without losing what you entered.

135 of 2048

Allowed range: 1–1000 · whole numbers

Add SBOM Check to your agent

Connect this app on its own. Add other PowMCP apps whenever your agent needs another job done.

Open the apps workspace A glowing app tile clicking into a slot on a dark agent device, with the PowMCP app box behind it

Connect directly

Choose your agent. Each button opens a new tab with only this app's endpoint ready to add.

Use another agent

Copy one ready-to-send prompt for any agent that supports remote MCP connections.

Manual endpoint, JSON, and terminal commands

For clients that require manual configuration, use this app-only endpoint, its JSON entry, or one terminal command.

ChatGPT: enable Developer mode in Settings → Security and login, then add this MCP endpoint from the Plugins page. Availability depends on your account and workspace policy. PowMCP has not yet verified ChatGPT account linking. OpenAI setup guide

https://powmcp.com/sbom-preflight/mcp
{
  "mcpServers": {
    "powmcp-sbom-preflight": {
      "type": "http",
      "url": "https://powmcp.com/sbom-preflight/mcp"
    }
  }
}

Terminal agents add this app with one command:

Claude Code
claude mcp add --transport http powmcp-sbom-preflight https://powmcp.com/sbom-preflight/mcp
Codex CLI
codex mcp add powmcp-sbom-preflight --url https://powmcp.com/sbom-preflight/mcp
Gemini CLI
gemini mcp add --transport http powmcp-sbom-preflight https://powmcp.com/sbom-preflight/mcp

Manage, disable, or remove this connection in your agent's own MCP settings. PowMCP does not label an external connection as installed without confirmation from that client.

Proof

What it does

Check an SBOM document before you ship it

Validate one CycloneDX or SPDX SBOM (a public URL or a file attached in the conversation) with full versioned-schema validation for JSON documents; CycloneDX XML and SPDX tag-value are parsed and structurally checked, not schema-validated. PURL-syntax and SPDX-license-id checks and document-located defects run on every format, or compare two builds under identical limits, validating document conformance only.

Category
Developer Tools

Request cost1 completed result

Guests get 50 lifetime app requests. Free accounts get 100 each calendar month.

Tools in this app

01

SBOM Check

sbom_check

Validate one CycloneDX or SPDX software bill of materials before you deliver it or gate a build. Give a publicly fetchable HTTP(S) SBOM URL or attach the SBOM file directly in the conversation (CycloneDX JSON or XML, or SPDX JSON or tag-value) and it downloads the document under an SSRF-guarded, 10 MB-capped fetch, detects the format and spec version from content, validates CycloneDX/SPDX JSON against the correct bundled official versioned JSON schema (CycloneDX XML and SPDX tag-value are parsed and structurally checked instead, never schema-validated, so they always report pass false), and checks every package-url for purl-spec syntax and every declared license against the full SPDX license-id list, returning pass/fail, document-located schema defects, PURL and license-id findings, and a required-field summary. It validates document conformance only: it does not score supply-chain risk, scan for CVEs or vulnerabilities, or confirm the SBOM lists every real component. Fetching and validating a live document can take up to 60 seconds.

02

SBOM Compare

sbom_compare

Compare exactly two CycloneDX or SPDX SBOM builds under identical limits to see what drifted release over release. Give two distinct SBOM builds (publicly fetchable HTTP(S) URLs or files attached in the conversation) and it runs the same bounded validation as sbom_check on each: schema conformance for JSON documents (CycloneDX XML and SPDX tag-value are parsed and structurally checked instead), PURL syntax, SPDX license ids, then reports per-build pass and defect counts, which schema/PURL/license findings were introduced or resolved, the added, removed, and version-changed components and licenses, and ranks the builds by pass state then fewer conformance defects (only when the measured findings support a distinction). Use sbom_check for a single document. It ranks automated conformance only and never infers that fewer defects means lower supply-chain risk, better security, or more complete coverage. Fetching and validating two live documents can take up to 60 seconds.

SBOM Check questions

Scope and boundaries for SBOM Check.

01What can I check with SBOM Check?

Validate the public CycloneDX JSON SBOM for Proton Bridge 1.6.3 with maxDefects set to 300, or attach one CycloneDX or SPDX file instead of supplying a URL.

02How should I read the result?

Read pass together with schema.applied first: pass means a supported CycloneDX or SPDX JSON document passed the bundled schema plus the scanned PURL and SPDX license checks. XML and tag-value inputs cannot pass because no JSON schema is applied, so read schema.reason before treating failure as a defect. Fix schema, PURL, license, and required-field findings, and treat any truncation marker as incomplete evidence.

03What are its limits?

Full versioned-schema validation applies only to CycloneDX and SPDX JSON; CycloneDX XML and SPDX tag-value receive structural checks and do not return pass true. Sources are capped at 10 MB, and validation does not find CVEs, assess supply-chain risk, or confirm the SBOM is complete.