# in-toto Go Implementation

**Canonical:** https://apis.io/apis/in-toto/in-toto-golang/  
**Provider:** In-Toto — https://apis.io/providers/in-toto/  
**Documentation:** https://github.com/in-toto/in-toto-golang

in-toto Go Implementation is one of 4 APIs that [In-Toto](https://apis.io/providers/in-toto/) publishes on the [APIs.io](https://apis.io/) network. Tagged areas include Go, Implementation, SDK, and Supply Chain. The published artifact set on APIs.io includes API documentation and a GitHub repository.

A Go implementation of the in-toto specification that enables supply chain integrity verification in Go-based build and deployment pipelines. It provides the same core functionality as the Python reference implementation including generating link metadata, creating layouts, and verifying supply chains. It supports ITE-7 for X.509-based signing via SPIFFE/SPIRE integration.

## Machine-readable artifacts (2)

- **Documentation** — https://pkg.go.dev/github.com/in-toto/in-toto-golang
- **GitHubRepository** — https://github.com/in-toto/in-toto-golang

## Other In-Toto APIs (3)

- [in-toto Attestation Specification](https://apis.io/apis/in-toto/in-toto-spec/)
- [in-toto Attestation Framework](https://apis.io/apis/in-toto/in-toto-attestation-framework/)
- [in-toto Python Reference Implementation](https://apis.io/apis/in-toto/in-toto-python/)

## Tags

Go, Implementation, SDK, Supply Chain

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/in-toto/in-toto-golang/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/in-toto/.
