Use this API to retrieve and download provenance attestations for a project.
The availability of these endpoints is controlled by a feature flag. They are available for testing, but not ready for production use.
Retrieve an attestation bundle
GET /api/v4/projects/{id}/attestations/{attestation_iid}/download
This feature was introduced in GitLab 18.7
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
attestation_Path, | String or integer | The iid of the attestation |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | — |
400 | Bad Request | — |
404 | Artifact SHA- | — |
List all attestations for a project
GET /api/v4/projects/{id}/attestations/{subject_digest}
Lists all attestations for a specified project and artifact hash. This feature was introduced in GitLab 18.7.
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- |
subject_Path, | String | The SHA- |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Bad Request | — |
404 | Artifact SHA- | — |
Schemas
Objects returned by the operations above and objects nested in their request bodies.
APIEntitiesSupplyChainAttestation
| Property | Type | Description |
|---|---|---|
build_ | Integer (int64) | — |
created_ | String (date- | Example:2025- |
download_ | String | — |
expire_ | String (date- | Example:2025- |
id | Integer (int64) | Example:1 |
iid | Integer | Example:14 |
predicate_ | String | Example:provenance |
predicate_ | String | Example:https: |
project_ | Integer (int64) | — |
status | String | Example:success |
subject_ | String | Example:5db1fee4b5703808c480 |
updated_ | String (date- | Example:2025- |