Use this API to interact with the PyPI package manager client.

This API is used by the PyPI package manager client and is generally not meant for manual consumption.

These endpoints do not adhere to the standard API authentication methods. See the PyPI package registry documentation for details on which headers and token types are supported. Undocumented authentication methods might be removed in the future.

Twine 3.4.2 or greater is recommended when FIPS mode is enabled.

Download a package file from a group

GET /api/v4/groups/{id}/-/packages/pypi/files/{sha256}/{file_identifier}

This feature was introduced in GitLab 13.12

Parameters

NameTypeDescription
id
Path, required
Integer or stringThe ID or full path of the group
file_identifier
Path, required
StringThe PyPi package file identifier
Example: my.pypi.package-0.0.1.tar.gz
sha256
Path, required
StringThe PyPi package sha256 check sum
Example: 5y57017232013c8ac80647f4ca153k3726f6cba62d055cd747844ed95b3c65ff

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

List all packages for a group

GET /api/v4/groups/{id}/-/packages/pypi/simple

Lists all packages for a specified group in an HTML file.

Parameters

NameTypeDescription
id
Path, required
Integer or stringThe ID or full path of the group

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

The PyPi Simple Group Package Endpoint

GET /api/v4/groups/{id}/-/packages/pypi/simple/{package_name}

This feature was introduced in GitLab 12.10

Parameters

NameTypeDescription
id
Path, required
Integer or stringThe ID or full path of the group
package_name
Path, required
StringThe PyPi package name
Example: my.pypi.package

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Upload a package

POST /api/v4/projects/{id}/packages/pypi

Uploads a PyPI package for a specified project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project

Request body (multipart/form-data)

PropertyTypeDescription
author_emailStringEmail address for the package author
Example: cschultz@example.com, snoopy@peanuts.com
content
Required
String (binary)The package file to be published (generated by Multipart middleware)
descriptionStringDescription of the package
description_content_typeStringType of content for the package description
Example: text/markdown; charset=UTF-8; variant=GFM
keywordsStringKeywords listed for the package
Example: dog,puppy,voting,election
md5_digestStringMD5 checksum of the package
Example: 900150983cd24fb0d6963f7d28e17f72
metadata_versionStringMetadata version of the package
Example: 2.3
name
Required
StringName of the package
Example: my.pypi.package
requires_pythonStringPyPI version required for the package
Example: >=3.7
sha256_digestStringSHA256 checksum of the package
Pattern: (?:^[0-9A-Fa-f]{64}$)
Example: ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
summaryStringShort summary of the package
Example: A module for collecting votes from beagles.

Responses

CodeDescriptionSchema
201Created—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—
422Unprocessable Entity—

Authorize the PyPi package upload from workhorse

POST /api/v4/projects/{id}/packages/pypi/authorize

This feature was introduced in GitLab 12.10

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

The PyPi package download endpoint

GET /api/v4/projects/{id}/packages/pypi/files/{sha256}/{file_identifier}

This feature was introduced in GitLab 12.10

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
file_identifier
Path, required
StringThe PyPi package file identifier
Example: my.pypi.package-0.0.1.tar.gz
sha256
Path, required
StringThe PyPi package sha256 check sum
Example: 5y57017232013c8ac80647f4ca153k3726f6cba62d055cd747844ed95b3c65ff

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Download a forwarded (proxied) PyPI package file

GET /api/v4/projects/{id}/packages/pypi/forward/{package_name}/{upstream_path}

Enforces the Dependency Firewall then redirects to the upstream artifact.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringThe normalized PyPI package name
Example: my.pypi.package
upstream_path
Path, required
StringThe upstream artifact host and path, as emitted by the Simple index rewrite

Responses

CodeDescriptionSchema
302Found—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

List all packages for a project

GET /api/v4/projects/{id}/packages/pypi/simple

Lists all packages for a specified project in an HTML file.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

The PyPi Simple Project Package Endpoint

GET /api/v4/projects/{id}/packages/pypi/simple/{package_name}

This feature was introduced in GitLab 12.10

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringThe PyPi package name
Example: my.pypi.package

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—