Amazon Signer website screenshot

Amazon Signer

AWS Signer is a fully managed code-signing service to ensure the trust and integrity of your code. It manages the code-signing certificate public and private keys and enables central management and deployment of code signing certificates for Lambda functions and IoT devices.

Amazon Signer publishes 5 APIs on the APIs.io network, including Revocations#signatureTimestamp&platformId&profileVersionArn&jobArn&certificateHashes API, Signing Jobs API, Signing Platforms API, and 2 more. Tagged areas include Code Signing, IoT, Lambda, and Security.

The Amazon Signer catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Amazon Signer’s developer surface includes authentication, developer portal, documentation, support, engineering blog, developer console, signup flow, and 13 more developer resources.

64.9/100 strong ▬ flat Agent 44/100 agent ready Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
5 APIs 6 Features 4 Use Cases
Code SigningIoTLambdaSecurity

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 64.9/100 · strong
Contract Quality 17.9 / 25
Developer Ergonomics 9.1 / 20
Commercial Clarity 16.3 / 20
Operational Transparency 6.8 / 13
Governance 8.3 / 12
Discoverability 6.5 / 10
Agent readiness — 44/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/amazon-signer: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 5

Individual APIs this provider publishes, each with its own machine-readable definition.

Amazon Signer Revocations#signatureTimestamp&platformId&profileVersionArn&jobArn&certificateHashes API

The Revocations#signatureTimestamp&platformId&profileVersionArn&jobArn&certificateHashes API from Amazon Signer — 1 operation(s) for revocations#signaturetimestamp&platformid&pr...

Amazon Signer Signing Jobs API

The Signing Jobs API from Amazon Signer — 4 operation(s) for signing jobs.

Amazon Signer Signing Platforms API

The Signing Platforms API from Amazon Signer — 2 operation(s) for signing platforms.

Amazon Signer Signing Profiles API

The Signing Profiles API from Amazon Signer — 5 operation(s) for signing profiles.

Amazon Signer Tags API

The Tags API from Amazon Signer — 2 operation(s) for tags.

Postman Collections 5

Ready-to-run Postman collections for exercising this provider's APIs.

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Amazon Signer Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 6

Notable capabilities this provider offers.

Centralized Code Signing

Security administrators define signing policies and which IAM roles can sign code.

Certificate Management

Automatically manages code-signing certificate public and private keys.

Lifecycle Management

Central management and deployment of code-signing certificates.

Compliance Tracking

Integration with AWS CloudTrail tracks who generates signatures for compliance.

Fully Managed

No infrastructure to maintain — fully managed code signing service.

Signature Revocation

Revoke signing profiles and individual signatures with effective timestamps.

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Amazon Signer Context

60 classes · 69 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Amazon Signer API Rules

5 rules · 3 warnings 2 info

SPECTRAL

Amazon Signer API Rules

30 rules · 11 errors 14 warnings 5 info

SPECTRAL

JSON Schema 65

Standalone JSON Schema definitions for this provider's data models.

AddProfilePermissionRequest

5 properties

JSON SCHEMA

AddProfilePermissionResponse

1 properties

JSON SCHEMA

CancelSigningProfileRequest

0 properties

JSON SCHEMA

Category

0 properties

JSON SCHEMA

DescribeSigningJobRequest

0 properties

JSON SCHEMA

DescribeSigningJobResponse

19 properties

JSON SCHEMA

Destination

1 properties

JSON SCHEMA

EncryptionAlgorithmOptions

2 properties

JSON SCHEMA

EncryptionAlgorithm

0 properties

JSON SCHEMA

GetRevocationStatusRequest

0 properties

JSON SCHEMA

GetRevocationStatusResponse

1 properties

JSON SCHEMA

GetSigningPlatformRequest

0 properties

JSON SCHEMA

GetSigningPlatformResponse

9 properties

JSON SCHEMA

GetSigningProfileRequest

0 properties

JSON SCHEMA

GetSigningProfileResponse

14 properties

JSON SCHEMA

HashAlgorithmOptions

2 properties

JSON SCHEMA

HashAlgorithm

0 properties

JSON SCHEMA

ImageFormat

0 properties

JSON SCHEMA

ListProfilePermissionsRequest

0 properties

JSON SCHEMA

ListProfilePermissionsResponse

4 properties

JSON SCHEMA

ListSigningJobsRequest

0 properties

JSON SCHEMA

ListSigningJobsResponse

2 properties

JSON SCHEMA

ListSigningPlatformsRequest

0 properties

JSON SCHEMA

ListSigningPlatformsResponse

2 properties

JSON SCHEMA

ListSigningProfilesRequest

0 properties

JSON SCHEMA

ListSigningProfilesResponse

2 properties

JSON SCHEMA

ListTagsForResourceRequest

0 properties

JSON SCHEMA

ListTagsForResourceResponse

1 properties

JSON SCHEMA

Metadata

0 properties

JSON SCHEMA

Permission

4 properties

JSON SCHEMA

PutSigningProfileRequest

6 properties

JSON SCHEMA

PutSigningProfileResponse

3 properties

JSON SCHEMA

RemoveProfilePermissionRequest

0 properties

JSON SCHEMA

RemoveProfilePermissionResponse

1 properties

JSON SCHEMA

RevokeSignatureRequest

2 properties

JSON SCHEMA

RevokeSigningProfileRequest

3 properties

JSON SCHEMA

S3Destination

2 properties

JSON SCHEMA

S3SignedObject

2 properties

JSON SCHEMA

S3Source

3 properties

JSON SCHEMA

SignPayloadRequest

4 properties

JSON SCHEMA

SignPayloadResponse

4 properties

JSON SCHEMA

SignatureValidityPeriod

2 properties

JSON SCHEMA

SignedObject

1 properties

JSON SCHEMA

SigningConfigurationOverrides

2 properties

JSON SCHEMA

SigningConfiguration

2 properties

JSON SCHEMA

SigningImageFormat

2 properties

JSON SCHEMA

SigningJobRevocationRecord

3 properties

JSON SCHEMA

SigningJob

14 properties

JSON SCHEMA

SigningMaterial

1 properties

JSON SCHEMA

SigningParameters

0 properties

JSON SCHEMA

SigningPlatformOverrides

2 properties

JSON SCHEMA

SigningPlatform

9 properties

JSON SCHEMA

SigningProfileRevocationRecord

3 properties

JSON SCHEMA

SigningProfile

11 properties

JSON SCHEMA

SigningProfileStatus

0 properties

JSON SCHEMA

SigningStatus

0 properties

JSON SCHEMA

Source

1 properties

JSON SCHEMA

StartSigningJobRequest

5 properties

JSON SCHEMA

StartSigningJobResponse

2 properties

JSON SCHEMA

TagMap

0 properties

JSON SCHEMA

TagResourceRequest

1 properties

JSON SCHEMA

TagResourceResponse

0 properties

JSON SCHEMA

UntagResourceRequest

0 properties

JSON SCHEMA

UntagResourceResponse

0 properties

JSON SCHEMA

ValidityType

0 properties

JSON SCHEMA

Scroll for all 65

JSON Structure 65

JSON Structure definitions describing this provider's data shapes.

Amazon Signer Category Structure

0 properties

JSON STRUCTURE

Amazon Signer Destination Structure

1 properties

JSON STRUCTURE

Amazon Signer Hash Algorithm Structure

0 properties

JSON STRUCTURE

Amazon Signer Image Format Structure

0 properties

JSON STRUCTURE

Amazon Signer Metadata Structure

0 properties

JSON STRUCTURE

Amazon Signer Permission Structure

4 properties

JSON STRUCTURE

Amazon Signer S3 Destination Structure

2 properties

JSON STRUCTURE

Amazon Signer S3 Signed Object Structure

2 properties

JSON STRUCTURE

Amazon Signer S3 Source Structure

3 properties

JSON STRUCTURE

Amazon Signer Signed Object Structure

1 properties

JSON STRUCTURE

Amazon Signer Signing Job Structure

14 properties

JSON STRUCTURE

Amazon Signer Signing Material Structure

1 properties

JSON STRUCTURE

Amazon Signer Signing Parameters Structure

0 properties

JSON STRUCTURE

Amazon Signer Signing Platform Structure

9 properties

JSON STRUCTURE

Amazon Signer Signing Profile Structure

11 properties

JSON STRUCTURE

Amazon Signer Signing Status Structure

0 properties

JSON STRUCTURE

Amazon Signer Source Structure

1 properties

JSON STRUCTURE

Amazon Signer Tag Map Structure

0 properties

JSON STRUCTURE

Amazon Signer Validity Type Structure

0 properties

JSON STRUCTURE

Scroll for all 65

Examples 58

Example request and response payloads for these APIs.

Scroll for all 58

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Amazon Signer Authentication

apiKey · 1 scheme

SECURITY

Amazon Signer Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Amazon Signer Vulnerability Disclosure

security.txt · contact published

SECURITY

Amazon Signer Trust Center

PCI DSS, HIPAA, FedRAMP, GDPR, FIPS 140

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Amazon Signer Agentic Access

19 operations · 10 acting · 2 human-in-the-loop

19 operations · 10 acting

AGENTIC

Use Cases 4

What developers build with this provider.

Lambda Code Signing

Sign Lambda deployment packages to ensure only trusted code is deployed.

IoT Firmware Signing

Sign firmware images for microcontrollers and over-the-air (OTA) updates via Amazon FreeRTOS.

Container Image Signing

Sign container images using Notation CLI with Amazon ECR and verify at EKS deployment.

Audit and Compliance

Track all signing operations via CloudTrail for audit and compliance requirements.

Resources

Get Started 4

Portal, sign-up, and the first successful call

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 2

Pagination, idempotency, versioning, errors, and events

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 3

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: amazon-signer
name: Amazon Signer
description: AWS Signer is a fully managed code-signing service to ensure the trust and integrity of your code. It manages
  the code-signing certificate public and private keys and enables central management and deployment of code signing certificates
  for Lambda functions and IoT devices.
type: Index
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/amazon-signer.png
tags:
- AWS
- Code Signing
- IoT
- Lambda
- Security
url: https://raw.githubusercontent.com/api-evangelist/amazon-signer/refs/heads/main/apis.yml
created: '2026-03-16'
modified: '2026-05-19'
specificationVersion: '0.19'
apis:
- aid: amazon-signer:amazon-signer-revocations-signaturetimestamp-platformid-profileversionarn-jobarn-certificatehashes-api
  name: Amazon Signer Revocations#signatureTimestamp&platformId&profileVersionArn&jobArn&certificateHashes API
  description: The Revocations#signatureTimestamp&platformId&profileVersionArn&jobArn&certificateHashes API from Amazon Signer
    — 1 operation(s) for revocations#signaturetimestamp&platformid&profileversionarn&jobarn&certificatehashes.
  humanURL: https://aws.amazon.com/signer/
  baseURL: https://signer.amazonaws.com
  tags:
  - Revocations#signatureTimestamp&platformId&profileVersionArn&jobArn&certificateHashes
  properties:
  - type: OpenAPI
    url: openapi/amazon-signer-revocations-signaturetimestamp-platformid-profileversionarn-jobarn-certificatehashes-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/signer/latest/api/Welcome.html
  - type: GettingStarted
    url: https://aws.amazon.com/signer/getting-started/
  - type: Pricing
    url: https://aws.amazon.com/signer/pricing/
  - type: FAQ
    url: https://aws.amazon.com/signer/faqs/
- aid: amazon-signer:amazon-signer-signing-jobs-api
  name: Amazon Signer Signing Jobs API
  description: The Signing Jobs API from Amazon Signer — 4 operation(s) for signing jobs.
  humanURL: https://aws.amazon.com/signer/
  baseURL: https://signer.amazonaws.com
  tags:
  - Signing Jobs
  properties:
  - type: OpenAPI
    url: openapi/amazon-signer-signing-jobs-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/signer/latest/api/Welcome.html
  - type: GettingStarted
    url: https://aws.amazon.com/signer/getting-started/
  - type: Pricing
    url: https://aws.amazon.com/signer/pricing/
  - type: FAQ
    url: https://aws.amazon.com/signer/faqs/
- aid: amazon-signer:amazon-signer-signing-platforms-api
  name: Amazon Signer Signing Platforms API
  description: The Signing Platforms API from Amazon Signer — 2 operation(s) for signing platforms.
  humanURL: https://aws.amazon.com/signer/
  baseURL: https://signer.amazonaws.com
  tags:
  - Signing Platforms
  properties:
  - type: OpenAPI
    url: openapi/amazon-signer-signing-platforms-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/signer/latest/api/Welcome.html
  - type: GettingStarted
    url: https://aws.amazon.com/signer/getting-started/
  - type: Pricing
    url: https://aws.amazon.com/signer/pricing/
  - type: FAQ
    url: https://aws.amazon.com/signer/faqs/
- aid: amazon-signer:amazon-signer-signing-profiles-api
  name: Amazon Signer Signing Profiles API
  description: The Signing Profiles API from Amazon Signer — 5 operation(s) for signing profiles.
  humanURL: https://aws.amazon.com/signer/
  baseURL: https://signer.amazonaws.com
  tags:
  - Signing Profiles
  properties:
  - type: OpenAPI
    url: openapi/amazon-signer-signing-profiles-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/signer/latest/api/Welcome.html
  - type: GettingStarted
    url: https://aws.amazon.com/signer/getting-started/
  - type: Pricing
    url: https://aws.amazon.com/signer/pricing/
  - type: FAQ
    url: https://aws.amazon.com/signer/faqs/
- aid: amazon-signer:amazon-signer-tags-api
  name: Amazon Signer Tags API
  description: The Tags API from Amazon Signer — 2 operation(s) for tags.
  humanURL: https://aws.amazon.com/signer/
  baseURL: https://signer.amazonaws.com
  tags:
  - Tags
  properties:
  - type: OpenAPI
    url: openapi/amazon-signer-tags-api-openapi.yml
  - type: Documentation
    url: https://docs.aws.amazon.com/signer/latest/api/Welcome.html
  - type: GettingStarted
    url: https://aws.amazon.com/signer/getting-started/
  - type: Pricing
    url: https://aws.amazon.com/signer/pricing/
  - type: FAQ
    url: https://aws.amazon.com/signer/faqs/
common:
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/amazon-signer/overview
- type: AgenticAccess
  url: agentic-access/amazon-signer-agentic-access.yml
- type: TrustCenter
  url: security/amazon-signer-trust-center.yml
- type: VulnerabilityDisclosure
  url: security/amazon-signer-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/amazon-signer-domain-security.yml
- type: Authentication
  url: authentication/amazon-signer-authentication.yml
- type: Portal
  url: https://aws.amazon.com/signer/
- type: Documentation
  url: https://docs.aws.amazon.com/signer/
- type: TermsOfService
  url: https://aws.amazon.com/service-terms/
- type: PrivacyPolicy
  url: https://aws.amazon.com/privacy/
- type: Support
  url: https://aws.amazon.com/premiumsupport/
- type: Blog
  url: https://aws.amazon.com/blogs/compute/tag/aws-signer/
- type: GitHubOrganization
  url: https://github.com/aws
- type: Console
  url: https://console.aws.amazon.com/signer/
- type: Signup
  url: https://portal.aws.amazon.com/billing/signup
- type: Login
  url: https://signin.aws.amazon.com/
- type: StatusPage
  url: https://health.aws.amazon.com/health/status
- type: Contact
  url: https://aws.amazon.com/contact-us/
- type: SpectralRules
  url: rules/amazon-signer-spectral-rules.yml
- type: Vocabulary
  url: vocabulary/amazon-signer-vocabulary.yaml
- type: Features
  data:
  - name: Centralized Code Signing
    description: Security administrators define signing policies and which IAM roles can sign code.
  - name: Certificate Management
    description: Automatically manages code-signing certificate public and private keys.
  - name: Lifecycle Management
    description: Central management and deployment of code-signing certificates.
  - name: Compliance Tracking
    description: Integration with AWS CloudTrail tracks who generates signatures for compliance.
  - name: Fully Managed
    description: No infrastructure to maintain — fully managed code signing service.
  - name: Signature Revocation
    description: Revoke signing profiles and individual signatures with effective timestamps.
- type: UseCases
  data:
  - name: Lambda Code Signing
    description: Sign Lambda deployment packages to ensure only trusted code is deployed.
  - name: IoT Firmware Signing
    description: Sign firmware images for microcontrollers and over-the-air (OTA) updates via Amazon FreeRTOS.
  - name: Container Image Signing
    description: Sign container images using Notation CLI with Amazon ECR and verify at EKS deployment.
  - name: Audit and Compliance
    description: Track all signing operations via CloudTrail for audit and compliance requirements.
- type: Integrations
  data:
  - name: AWS Lambda
    description: Sign Lambda deployment packages; Lambda verifies signatures at deployment.
  - name: Amazon FreeRTOS
    description: Sign firmware images for IoT microcontrollers and OTA updates.
  - name: Amazon ECR
    description: Sign container images using Notation CLI stored in ECR registry.
  - name: Amazon EKS
    description: Verify image ownership and integrity at Kubernetes deployment time.
  - name: AWS Certificate Manager
    description: Create or import SSL/TLS certificates used for code signing.
  - name: AWS CloudTrail
    description: Record and audit all API calls to AWS Signer for compliance.
  - name: AWS IoT Device Management
    description: Sign code for IoT devices managed by AWS IoT Device Management.
- type: Integrations
  url: https://aws.amazon.com/partners/
integrations:
- name: Partner Programs
- name: Resources
- name: Success Stories
- name: Work with an AWS Partner
- name: AWS Marketplace
- name: AWS Partner Central
- name: Partner Paths
- name: co-sell with AWS
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
kind: company