# in-toto Attestation Specification

**Canonical:** https://apis.io/apis/in-toto/in-toto-spec/  
**Provider:** In-Toto — https://apis.io/providers/in-toto/  
**Documentation:** https://in-toto.io/docs/specs/

in-toto Attestation Specification is one of 4 APIs that [In-Toto](https://apis.io/providers/in-toto/) publishes on the [APIs.io](https://apis.io/) network. This API exposes 3 JSON Schema definitions. Tagged areas include Attestation, Specification, and Supply Chain. The published artifact set on APIs.io includes API documentation, an API reference, a JSON-LD context, and 3 JSON Schemas.

The in-toto specification defines the metadata format for recording software supply chain steps. It includes layout metadata that defines the expected steps and their authorized functionaries, and link metadata that records what actually happened at each step including materials consumed and products produced. Verification compares layouts against links to detect tampering.

## Machine-readable artifacts (7)

- **Documentation** — https://in-toto.io/docs/specs/
- **Reference** — https://github.com/in-toto/docs/blob/master/in-toto-spec.md
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/in-toto/refs/heads/main/json-schema/in-toto-layout-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/in-toto/refs/heads/main/json-schema/in-toto-link-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/in-toto/refs/heads/main/json-schema/in-toto-attestation-schema.json
- **JSONLD** — https://raw.githubusercontent.com/api-evangelist/in-toto/refs/heads/main/json-ld/in-toto-context.jsonld
- **APIsJSON** — https://raw.githubusercontent.com/api-evangelist/in-toto/refs/heads/main/apis.yml

## Other In-Toto APIs (3)

- [in-toto Attestation Framework](https://apis.io/apis/in-toto/in-toto-attestation-framework/)
- [in-toto Python Reference Implementation](https://apis.io/apis/in-toto/in-toto-python/)
- [in-toto Go Implementation](https://apis.io/apis/in-toto/in-toto-golang/)

## Tags

Attestation, Specification, Supply Chain

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/in-toto/in-toto-spec/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/in-toto/.
