# Chainguard

**Canonical:** https://apis.io/providers/chainguard/  
**Website:** https://www.chainguard.dev/  
**APIs profiled:** 6

Chainguard builds, secures, and maintains a catalog of hardened, minimal container images and software supply chain security tools. Its flagship Chainguard Images rebuild open source software from source daily on a zero-known-CVE promise, signed with Sigstore, and distributed through the cgr.dev registry. The Chainguard platform exposes REST APIs, a command- line tool (chainctl), a Terraform provider, and an SDK for managing organizations, IAM, image repositories, registries, vulnerabilities, and event subscriptions. Chainguard Libraries extends the model to language ecosystems (Java, Python, Go, Node.js).

## Kin Score — 21.8 / 100 (emerging)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 21.8).

| Facet | Score |
|---|---|
| Discoverability | 64.8 |
| Contract Quality | 0.0 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 13.2 |
| Developer Ergonomics | 28.6 |
| Commercial Clarity | 39.5 |
| Access Clarity | 39.5 |

## Agent readiness — 7.3 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | yes |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium — onboarding: unknown, pricing: freemium, trial: no (confidence: medium).

## APIs (6)

- **Chainguard API v2** — Chainguard API v2 is the current REST API for the Chainguard platform. Endpoints cover Identity and Access Management (IAM), image registry operations, and vulnerability data un...
- **Chainguard API v1** — Chainguard API v1 is the legacy REST API for the Chainguard platform, covering the same broad surface as v2 (IAM, registry, vulnerabilities) and remaining available for existing...
- **Chainguard Unified API Spec** — The unified Chainguard API specification combines API v1 and v2 definitions in a single reference, useful for tool builders and readers who need a consolidated view of the platf...
- **Chainguard chainctl CLI** — chainctl is the official command-line interface for the Chainguard platform. It provides commands for authentication, IAM, image management, registry operations, event subscript...
- **Chainguard Terraform Provider** — The chainguard-dev/chainguard Terraform provider lets platform engineers provision and manage Chainguard resources (organizations, groups, identities, roles, subscriptions, and ...
- **Chainguard Images Registry (cgr.dev)** — cgr.dev is the OCI-compliant distribution endpoint for Chainguard Images. Standard OCI and Docker tooling (docker pull, cosign verify, oras, crane, etc.) can authenticate with a...

## Security (1)

- **Chainguard Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC

## Plans (1)

- **Chainguard Plans Pricing**

## Use cases (11)

- **Software Supply Chain Security**
- **Container Hardening**
- **CVE Remediation**
- **Compliance (FedRAMP, FIPS, PCI, HIPAA)**
- **Open Source Dependency Security**
- **Secure Base Images**
- **Air-Gapped Distribution**
- **Kubernetes Workload Security**
- **CI/CD Integration**
- **Image Signing and Verification**
- **Vulnerability Scanning Reduction**

## Tags

Cloud-Native, Container Images, Containers, DevSecOps, Kubernetes, Registry, Security, Software Supply Chain, Vulnerability Management

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/chainguard/). Scores are computed from the provider's own public artifacts under a published rubric.
