Ratify website screenshot

Ratify

Ratify is a CNCF Sandbox open-source verification framework for container images and other supply chain artifacts in Kubernetes environments. It enables policy-driven artifact ratification by coordinating any number of pluggable verifiers (signatures, SBOMs, scan results, attestations) against a given policy, integrating with Kubernetes admission webhooks via the Gatekeeper policy engine. Ratify is developed by the ratify-project GitHub organization (originally a Microsoft open-source project), written in Go, and distributed as a CLI tool, Go library, and Kubernetes admission webhook server. It supports OCI-compliant artifact stores including Azure Container Registry, Amazon ECR, and Docker Hub. Ratify exposes an internal HTTP verification API (v2alpha1) consumed by its webhook server but does not publish a public-facing REST API or OpenAPI specification.

Ratify is profiled on the APIs.io network. Tagged areas include Artifact Verification, CNCF, Cloud Native, Container Security, and Kubernetes.

Ratify’s developer surface includes documentation, engineering blog, and 5 more developer resources.

9.6/100 minimal ▬ flat Agent 0/100 human only Full breakdown ↓
scored 2026-07-27 · rubric v0.5
0 APIs
Artifact VerificationCNCFCloud NativeContainer SecurityKubernetesOpen SourcePolicy EnforcementSecuritySupply Chain

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 9.6/100 · minimal
Contract Quality 0.0 / 25
Developer Ergonomics 2.2 / 20
Commercial Clarity 0.0 / 20
Operational Transparency 0.7 / 13
Governance 0.0 / 12
Discoverability 6.8 / 10
Agent readiness — 0/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/ratify: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Ratify Domain Security

TLSv1.3 · HSTS

SECURITY

Resources

Documentation 1

Reference material describing how the API behaves

Build 3

SDKs, sample code, and the tooling you integrate with

Access & Security 1

Authentication, authorization, and security posture

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: ratify
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source: []
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/ratify.png
name: Ratify
description: Ratify is a CNCF Sandbox open-source verification framework for container images and other supply chain artifacts
  in Kubernetes environments. It enables policy-driven artifact ratification by coordinating any number of pluggable verifiers
  (signatures, SBOMs, scan results, attestations) against a given policy, integrating with Kubernetes admission webhooks via
  the Gatekeeper policy engine. Ratify is developed by the ratify-project GitHub organization (originally a Microsoft open-source
  project), written in Go, and distributed as a CLI tool, Go library, and Kubernetes admission webhook server. It supports
  OCI-compliant artifact stores including Azure Container Registry, Amazon ECR, and Docker Hub. Ratify exposes an internal
  HTTP verification API (v2alpha1) consumed by its webhook server but does not publish a public-facing REST API or OpenAPI
  specification.
type: Index
position: Consuming
access: 3rd-Party
url: https://raw.githubusercontent.com/api-evangelist/ratify/refs/heads/main/apis.yml
tags:
- Artifact Verification
- CNCF
- Cloud Native
- Container Security
- Kubernetes
- Open Source
- Policy Enforcement
- Security
- Supply Chain
created: '2025-01-01'
modified: '2026-05-02'
specificationVersion: '0.19'
apis: []
common:
- type: DomainSecurity
  url: security/ratify-domain-security.yml
- type: Website
  url: https://ratify.dev
- type: Documentation
  url: https://ratify.dev/docs/what-is-ratify
- type: SourceCode
  url: https://github.com/ratify-project/ratify
- type: GitHubOrg
  url: https://github.com/ratify-project
- type: PackageManager
  url: https://artifacthub.io/packages/helm/ratify/ratify
- url: https://ratify.dev/blog/rss.xml
  type: Blog
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com