In-Toto
in-toto is a CNCF graduated framework for securing the integrity of software supply chains. It provides a specification for generating and verifying metadata about each step in a software supply chain, from source code to deployment. in-toto ensures that each step is performed by the authorized party and that materials and products are not tampered with between steps.
In-Toto publishes 4 APIs on the APIs.io network. Tagged areas include Cloud Native, Graduated, Security, Software Integrity, and Supply Chain Security.
The In-Toto catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
In-Toto’s developer surface includes documentation, getting-started guide, engineering blog, FAQ, and 9 more developer resources.
Kin Score
APIs 4
Individual APIs this provider publishes, each with its own machine-readable definition.
in-toto Attestation Specification
The in-toto specification defines the metadata format for recording software supply chain steps. It includes layout metadata that defines the expected steps and their authorized...
in-toto Attestation Framework
The in-toto Attestation Framework provides a specification for generating verifiable claims about any aspect of how a piece of software is produced. It defines a fixed lightweig...
in-toto Python Reference Implementation
The Python reference implementation of in-toto provides tools and libraries for creating and verifying in-toto metadata. It includes the in-toto-run command for wrapping supply ...
in-toto Go Implementation
A Go implementation of the in-toto specification that enables supply chain integrity verification in Go-based build and deployment pipelines. It provides the same core functiona...
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
In Toto Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
In Toto Finops
FINOPSSemantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
In Toto Context
JSON-LDSpectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
In-Toto API Rules
SPECTRALIn-Toto API Rules
SPECTRALJSON Schema 3
Standalone JSON Schema definitions for this provider's data models.
Security Posture 1
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 4
Reference material describing how the API behaves
Design & Contract 2
Pagination, idempotency, versioning, errors, and events
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 1
Authentication, authorization, and security posture
Operate 2
Status, limits, changes, and where to get help
Company 2
The organization behind the API