Cosign · Authentication Profile
Cosign Authentication
Authentication
Cosign has no API key and no account. Its identity model is OIDC: the signer proves who they are to an OIDC provider, exchanges that token at Fulcio for a short-lived X.509 code-signing certificate, signs, and the event is recorded in the Rekor transparency log. Everything else is a local key material choice — a generated key pair, a cloud KMS URI, or a hardware token — plus ordinary registry credentials for the OCI registry the artifact lives in.
Cosign declares 6 security scheme(s) across its OpenAPI definitions.
Apache 2.0AttestationsCLICode SigningContainersFulcioGoKeylessOCIOIDCOpen-SourceRekorSigstoreSupply ChainTransparency LogVerification
Methods:
Schemes: 6
OAuth flows:
API key in:
Security Schemes
openIdConnect
key
key
key
http
none
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.