# Cosign

**Canonical:** https://apis.io/providers/cosign/  
**Website:** https://www.sigstore.dev/  
**APIs profiled:** 3

Cosign is the command-line client of the Sigstore project for signing, verifying, and storing container images, OCI artifacts, blobs, and in-toto attestations. Cosign supports keyless signing using OpenID Connect identity providers (Google, GitHub, Microsoft) by obtaining short-lived certificates from the Fulcio certificate authority and recording signing events in the Rekor transparency log. Signatures and attestations are stored alongside the signed artifact in any OCI-compliant registry, and cosign integrates with policy controllers, KMS providers, hardware tokens, and SBOM workflows for software supply chain security.

## Kin Score — 26.7 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 26.7).

| Facet | Score |
|---|---|
| Discoverability | 64.8 |
| Contract Quality | 28.2 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 36.8 |
| Developer Ergonomics | 26.2 |
| Commercial Clarity | 15.8 |
| Access Clarity | 15.8 |

## Agent readiness — 18.4 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium — onboarding: unknown, pricing: freemium, trial: no (confidence: medium).

## APIs (3)

- **Cosign CLI** — Cosign is a command-line tool for signing, verifying, and storing container images and OCI artifacts. It supports keyless signing, hardware-backed keys, KMS providers, in-toto a...
- **Sigstore Rekor API (consumed)** — Rekor is the Sigstore transparency log that cosign writes to and reads from when recording and verifying signing events. The public Rekor service exposes a REST API at rekor.sig...
- **Sigstore Fulcio API (consumed)** — Fulcio is the Sigstore certificate authority that issues short-lived X.509 code-signing certificates bound to OIDC identities. Cosign calls the Fulcio public CA at fulcio.sigsto...

## Security (1)

- **Cosign Domain Security** — TLSv1.3 · HSTS · DMARC

## Plans (1)

- **Cosign Plans Pricing**

## Tags

Apache 2.0, Attestations, CLI, Code Signing, Containers, Fulcio, Go, Keyless, OCI, OIDC, Open-Source, Rekor, Sigstore, Supply Chain, Transparency Log, Verification

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/cosign/). Scores are computed from the provider's own public artifacts under a published rubric.
