# in-toto Attestation Framework

**Canonical:** https://apis.io/apis/in-toto/in-toto-attestation-framework/  
**Provider:** In-Toto — https://apis.io/providers/in-toto/  
**Documentation:** https://github.com/in-toto/attestation

in-toto Attestation Framework is one of 4 APIs that [In-Toto](https://apis.io/providers/in-toto/) publishes on the [APIs.io](https://apis.io/) network. This API exposes 1 JSON Schema definition. Tagged areas include Attestation, SLSA, Specification, and Supply Chain. The published artifact set on APIs.io includes API documentation, an API reference, a GitHub repository, a JSON-LD context, and 1 JSON Schema.

The in-toto Attestation Framework provides a specification for generating verifiable claims about any aspect of how a piece of software is produced. It defines a fixed lightweight Statement structure with a subject and predicate, and a set of standard predicate types covering common use cases such as SLSA provenance. A future version of the in-toto specification will incorporate this framework as the primary mechanism to express supply chain claims.

## Machine-readable artifacts (5)

- **Documentation** — https://github.com/in-toto/attestation/blob/main/README.md
- **Reference** — https://github.com/in-toto/attestation/tree/main/spec/v1
- **GitHubRepository** — https://github.com/in-toto/attestation
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/in-toto/refs/heads/main/json-schema/in-toto-attestation-schema.json
- **JSONLD** — https://raw.githubusercontent.com/api-evangelist/in-toto/refs/heads/main/json-ld/in-toto-context.jsonld

## Other In-Toto APIs (3)

- [in-toto Attestation Specification](https://apis.io/apis/in-toto/in-toto-spec/)
- [in-toto Python Reference Implementation](https://apis.io/apis/in-toto/in-toto-python/)
- [in-toto Go Implementation](https://apis.io/apis/in-toto/in-toto-golang/)

## Tags

Attestation, SLSA, Specification, Supply Chain

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/in-toto/in-toto-attestation-framework/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/in-toto/.
