Sigstore
Sigstore is a set of free-to-use open source tools for signing, verifying, and protecting software supply chain artifacts. It provides a transparent and auditable signing infrastructure that eliminates the need for managing signing keys, making software supply chain security more accessible. The Sigstore ecosystem includes Cosign for artifact signing, Fulcio as the certificate authority, and Rekor as the cryptographically secure transparency log.
Sigstore publishes 5 APIs on the APIs.io network, including CA API, entries API, index API, and 2 more. Tagged areas include Certificate Authority, Code Signing, Containers, Cryptography, and Open Source.
The Sigstore catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
Sigstore’s developer surface includes documentation, getting-started guide, engineering blog, and 9 more developer resources.
Kin Score
APIs 6
Individual APIs this provider publishes, each with its own machine-readable definition.
Cosign
Cosign is the Sigstore tool for signing and verifying container images and other OCI artifacts. It enables keyless signing using OIDC identity, hardware token signing, and polic...
Sigstore CA API
The CA API from Sigstore — 3 operation(s) for ca.
Sigstore entries API
The entries API from Sigstore — 3 operation(s) for entries.
Sigstore index API
The index API from Sigstore — 1 operation(s) for index.
Sigstore pubkey API
The pubkey API from Sigstore — 1 operation(s) for pubkey.
Sigstore tlog API
The tlog API from Sigstore — 2 operation(s) for tlog.
Open Collections 1
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Fulcio
OPEN COLLECTIONPricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Sigstore Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Sigstore Finops
FINOPSSemantic Vocabularies 1
JSON-LD contexts and semantic vocabularies used across these APIs.
Sigstore Context
JSON-LDSpectral Rules 2
Spectral governance rulesets for linting and validating these APIs.
Sigstore API Rules
SPECTRALSigstore API Rules
SPECTRALJSON Schema 2
Standalone JSON Schema definitions for this provider's data models.
Sigstore Fulcio Signing Certificate
JSON SCHEMASigstore Rekor Log Entry
JSON SCHEMAJSON Structure 1
JSON Structure definitions describing this provider's data shapes.
Sigstore Log Entry Structure
JSON STRUCTUREExamples 3
Example request and response payloads for these APIs.
Security Posture 1
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 1
Pagination, idempotency, versioning, errors, and events
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 2
Authentication, authorization, and security posture
Operate 1
Status, limits, changes, and where to get help
Company 3
The organization behind the API
Other 1
Properties that don't map to a standard resource type