# SiFive > SiFive is a semiconductor intellectual-property company founded by the creators of the > RISC-V instruction set architecture at UC Berkeley. It licenses configurable RISC-V > processor core IP rather than manufacturing chips. SiFive publishes **no public REST > API and no OpenAPI**. Its machine-readable surface is (1) an OAuth 2.0 authorization > server fronting the customer-only SiFive Cloud Services portal, and (2) the open-source > DUH hardware-IP description format and its JSON Schema. Generated by API Evangelist from public sources on 2026-08-05. SiFive does not publish an llms.txt of its own (https://www.sifive.com/llms.txt returns 404). ## What SiFive sells - [Core IP — Essential (E/S/U series)](https://www.sifive.com/cores/essential) - [Core IP — Performance (P500/P600/P800 series)](https://www.sifive.com/cores/performance) - [Core IP — Intelligence (X100/X200/X300/XM series)](https://www.sifive.com/cores/intelligence) - [Core IP — Automotive (E6-A/E7-A/S7-A series)](https://www.sifive.com/cores/automotive) - [System IP — SiFive Insight, IOMMU Gen 2, Shield, WorldGuard](https://www.sifive.com/software/trace-and-debug) - [Development boards — HiFive Premier P550, HiFive Unmatched Rev B](https://www.sifive.com/boards) ## APIs - [SiFive Cloud Services OAuth 2.0](https://www.sifive.com/software/sifive-core-designer): The only callable HTTP surface SiFive exposes publicly. Authorization server at `https://scs.sifive.com/o` with authorization_code + refresh_token grants, PKCE (S256), and the scopes `openid`, `mcp:read`, `mcp:write`. The resources behind it require a SiFive customer account. There is no public REST or GraphQL API. Probes of every candidate spec location on www.sifive.com and scs.sifive.com (`/openapi.json`, `/openapi.yaml`, `/swagger.json`, `/api-docs`, `/graphql`, `/.well-known/api-catalog`) all returned 404. ## Specs and machine-readable artifacts - [DUH JSON Schema (draft-07)](https://www.npmjs.com/package/duh-schema): The document schema for DUH — SiFive's JSON5 format for describing reusable hardware components, designs, bus interfaces, memory maps and registers. Shipped as `dist/schema.json`. - [OAuth 2.0 Authorization Server Metadata (RFC 8414)](https://scs.sifive.com/.well-known/oauth-authorization-server): Served anonymously. Note the published `issuer` is `http://localhost:8000/o`, a misconfiguration — the working endpoints are on `https://scs.sifive.com/o`. ## Developer tools - [Developers hub](https://www.sifive.com/developers) - [Documentation](https://www.sifive.com/documentation) - [SiFive Core Designer](https://www.sifive.com/software/sifive-core-designer): configure a Core Design and generate a Dev Kit of RTL, testbench, software and documentation. - [Freedom SDK for Metal](https://www.sifive.com/software/freedom-sdk-metal) - [Freedom SDK for Linux](https://www.sifive.com/software/freedom-sdk-linux) - [SiFive Freedom Studio](https://www.sifive.com/software/sifive-freedom-studio) - [SiFive Freedom Tools](https://www.sifive.com/software/sifive-freedom-tools) - [SiFive Kernel Library](https://www.sifive.com/software/sifive-kernel-library) - [SiFive Models](https://www.sifive.com/software/sifive-models) ## Packages - [duh (npm)](https://www.npmjs.com/package/duh): the DUH CLI and library, Apache-2.0. - [duh-schema (npm)](https://www.npmjs.com/package/duh-schema) - [duh-bus](https://www.npmjs.com/package/duh-bus) · [duh-core](https://www.npmjs.com/package/duh-core) · [duh-ipxact](https://www.npmjs.com/package/duh-ipxact) · [duh-verilog](https://www.npmjs.com/package/duh-verilog) · [duh-om](https://www.npmjs.com/package/duh-om) · [duh-scala](https://www.npmjs.com/package/duh-scala) - [duhportinf (PyPI)](https://pypi.org/project/duhportinf/) · [pydevicetree (PyPI)](https://pypi.org/project/pydevicetree/) - [github.com/sifive](https://github.com/sifive): ~297 public repositories. ## Security - [PSIRT vulnerability disclosure policy](https://www.sifive.com/psirt-report-vulnerability): Coordinated Vulnerability Disclosure per ISO/IEC 29147 and ISO/IEC 30111, CVSS scoring, CVE nomenclature. Contact `psirt@sifive.com`, PGP key published. No bug bounty. There is no `/.well-known/security.txt` (404). ## Support and community - [Support portal](https://support.sifive.com/) - [Forums](https://forums.sifive.com/) - [Blog](https://www.sifive.com/blog) · [RSS](https://www.sifive.com/blog/rss.xml) - [Press](https://www.sifive.com/press) - [Contact](https://www.sifive.com/contact) ## Legal - [Terms](https://www.sifive.com/terms) - [Privacy](https://www.sifive.com/privacy) ## Not published For agents: SiFive does **not** publish an OpenAPI, an AsyncAPI, a GraphQL SDL, webhooks, an A2A agent card (`/.well-known/agent-card.json` → 404 on every host), a Postman collection, a status page, an SLA, a deprecation policy, a changelog, a rate-limit policy, a sandbox, or a documented MCP endpoint — although the `mcp:read` and `mcp:write` OAuth scopes indicate an MCP server exists behind the customer portal.