Cosign
Cosign is the command-line client of the Sigstore project for signing, verifying, and storing container images, OCI artifacts, blobs, and in-toto attestations. Cosign supports keyless signing using OpenID Connect identity providers (Google, GitHub, Microsoft) by obtaining short-lived certificates from the Fulcio certificate authority and recording signing events in the Rekor transparency log. Signatures and attestations are stored alongside the signed artifact in any OCI-compliant registry, and cosign integrates with policy controllers, KMS providers, hardware tokens, and SBOM workflows for software supply chain security.
Cosign publishes 1 API on the APIs.io network: Sigstore Rekor API (consumed). Tagged areas include Apache 2.0, Attestations, CLI, Code Signing, and Containers.
Cosign’s developer surface includes documentation, getting-started guide, release notes, engineering blog, and 11 more developer resources.
Kin Score
APIs 3
Individual APIs this provider publishes, each with its own machine-readable definition.
Cosign CLI
Cosign is a command-line tool for signing, verifying, and storing container images and OCI artifacts. It supports keyless signing, hardware-backed keys, KMS providers, in-toto a...
Sigstore Rekor API (consumed)
Rekor is the Sigstore transparency log that cosign writes to and reads from when recording and verifying signing events. The public Rekor service exposes a REST API at rekor.sig...
Sigstore Fulcio API (consumed)
Fulcio is the Sigstore certificate authority that issues short-lived X.509 code-signing certificates bound to OIDC identities. Cosign calls the Fulcio public CA at fulcio.sigsto...
Pricing Plans 1
Published pricing tiers and plan structures.
Cosign Plans Pricing
PLANSRate Limits 1
Documented rate limits and quota policies.
Cosign Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Cosign Finops
FINOPSSecurity Posture 1
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Build 2
SDKs, sample code, and the tooling you integrate with
Access & Security 2
Authentication, authorization, and security posture
Operate 4
Status, limits, changes, and where to get help
Commercial 1
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Other 1
Properties that don't map to a standard resource type