# SBOM Inventory

Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment.

Extract names, versions, PURLs, declared licenses and hashes from CycloneDX JSON 1.5/1.6 or SPDX JSON 2.3. Includes nested CycloneDX components and metadata.component; excludes services, external BOMs, relationships and unconsumed fields. No full document, license, PURL or hash validation.

Release: 0.29.0. Built: 2026-10-06T15:38:00Z.

## Choose for
- Build a small auditable component inventory from caller-supplied SBOM JSON
- Retain source JSON pointers and distinguish declared/concluded license fields

## Outside this profile
- Full SBOM conformance checks, dependency resolution or vulnerability scanning
- XML/tag-value inputs, external document traversal or artifact verification

Proposed nominal USD 0.005 per successful call; payer fees excluded. No verified runtime availability.

- [Exact release contract](/reference/services/sbom-inventory.json)
- [Input schema](/reference/schemas/sbom-inventory.input.json)
- [Output schema](/reference/schemas/sbom-inventory.output.json)
- [Fixed example](/reference/examples/sbom-inventory.json)
- [Complete HTML reference](/discover/tools/sbom-inventory)
