Cosign · Rate Limits
Cosign Rate Limits
Cosign itself is a local binary and has no rate limit. The question that matters is what the Sigstore public-good services it calls will accept, and the honest answer is that no request-rate limit is published and no rate-limit headers are returned. What IS published is an availability SLO and a payload size limit. This file replaces a 2026-05-04 bulk-sweep scaffold that carried invented limits.
Cosign Rate Limits is the machine-readable rate-limit profile for Cosign on the APIs.io network, conforming to the API Commons Rate Limits specification.
Tagged areas include Apache 2.0, Attestations, CLI, Code Signing, and Containers.
0 Limits
Apache 2.0AttestationsCLICode SigningContainersFulcioGoKeylessOCIOIDCOpen-SourceRekorSigstoreSupply ChainTransparency LogVerification
Work with this as data
Every rate limit here is available over the APIs.io API and to AI agents over MCP.