# Sigstore

**Canonical:** https://apis.io/providers/sigstore/  
**Website:** https://www.sigstore.dev/  
**APIs profiled:** 6

Sigstore is a set of free-to-use open source tools for signing, verifying, and protecting software supply chain artifacts. It provides a transparent and auditable signing infrastructure that eliminates the need for managing signing keys, making software supply chain security more accessible. The Sigstore ecosystem includes Cosign for artifact signing, Fulcio as the certificate authority, and Rekor as the cryptographically secure transparency log.

## Kin Score — 32.6 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 32.6).

| Facet | Score |
|---|---|
| Discoverability | 64.8 |
| Contract Quality | 51.2 |
| Governance | 25.0 |
| Contract Governance | 25.0 |
| Operational Transparency | 18.4 |
| Developer Ergonomics | 26.2 |
| Commercial Clarity | 13.2 |
| Access Clarity | 13.2 |

## Agent readiness — 20.5 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Paid — onboarding: unknown, pricing: paid, trial: no (confidence: medium).

## APIs (6)

- **Cosign** — Cosign is the Sigstore tool for signing and verifying container images and other OCI artifacts. It enables keyless signing using OIDC identity, hardware token signing, and polic...
- **Sigstore CA API** — The CA API from Sigstore — 3 operation(s) for ca.
- **Sigstore entries API** — The entries API from Sigstore — 3 operation(s) for entries.
- **Sigstore index API** — The index API from Sigstore — 1 operation(s) for index.
- **Sigstore pubkey API** — The pubkey API from Sigstore — 1 operation(s) for pubkey.
- **Sigstore tlog API** — The tlog API from Sigstore — 2 operation(s) for tlog.

## Agentic access (1)

- **Sigstore Agentic Access** — 11 operations · 4 acting

## Security (1)

- **Sigstore Domain Security** — TLSv1.3 · HSTS · DMARC

## Plans (1)

- **Sigstore Plans Pricing**

## Tags

Certificate Authority, Code Signing, Containers, Cryptography, Open-Source, PKI, Security, Software Supply Chain, Transparency Log

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/sigstore/). Scores are computed from the provider's own public artifacts under a published rubric.
