Use this API to retrieve and download provenance attestations for a project.

The availability of these endpoints is controlled by a feature flag. They are available for testing, but not ready for production use.

Retrieve an attestation bundle

GET /api/v4/projects/{id}/attestations/{attestation_iid}/download

This feature was introduced in GitLab 18.7

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
attestation_iid
Path, required
String or integerThe iid of the attestation

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
404Artifact SHA-256 not found—

List all attestations for a project

GET /api/v4/projects/{id}/attestations/{subject_digest}

Lists all attestations for a specified project and artifact hash. This feature was introduced in GitLab 18.7.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
subject_digest
Path, required
StringThe SHA-256 hash of the artifact

Responses

CodeDescriptionSchema
200OKAPIEntitiesSupplyChainAttestation
400Bad Request—
404Artifact SHA-256 not found—

Schemas

Objects returned by the operations above and objects nested in their request bodies.

APIEntitiesSupplyChainAttestation

PropertyTypeDescription
build_idInteger (int64)—
created_atString (date-time)Example: 2025-09-17T02:26:10.898Z
download_urlString—
expire_atString (date-time)Example: 2025-09-17T02:26:10.898Z
idInteger (int64)Example: 1
iidIntegerExample: 14
predicate_kindStringExample: provenance
predicate_typeStringExample: https://slsa.dev/provenance/v1
project_idInteger (int64)—
statusStringExample: success
subject_digestStringExample: 5db1fee4b5703808c48078a76768b155b421b210c0761cd6a5d223f4d99f1eaa
updated_atString (date-time)Example: 2025-09-17T02:26:10.898Z