Use this API to manage the packages stored in a project or a group.

Download the maven package file for a group

GET /api/v4/groups/{id}/-/packages/maven/{path}/{file_name}

This feature was introduced in GitLab 11.7

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the group
file_name
Path, required
StringPackage file name
Example: mypkg-1.0-SNAPSHOT.jar
path
Path, required
StringPackage path
Example: foo/bar/mypkg/1.0-SNAPSHOT

Responses

CodeDescriptionSchema
200OK—
302Found—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

List all packages for a group

GET /api/v4/groups/{id}/packages

Lists all packages for a specified group. When accessed without authentication, only packages of public projects are returned. By default, packages with default, deprecated, and error status are returned. Use the status parameter to view other packages.

Parameters

NameTypeDescription
id
Path, required
String or integerID or URL-encoded path of the group
exclude_subgroups
Query
BooleanDetermines if subgroups should be excluded
Default: false
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20
order_by
Query
StringReturn packages ordered by created_at, name, version or type fields
Allowed values: created_at, name, version, type, project_path
Default: created_at
sort
Query
StringReturn packages sorted in asc or desc order
Allowed values: asc, desc
Default: asc
package_type
Query
StringReturn packages of a certain type
Allowed values: maven, npm, conan, nuget, pypi, composer, generic, golang, debian, rubygems, helm, terraform_module, rpm, ml_model, cargo
package_name
Query
StringReturn packages with this name
package_version
Query
StringReturn packages with this version
include_versionless
Query
BooleanReturns packages without a version
status
Query
StringReturn packages with specified status
Allowed values: default, hidden, processing, error, pending_destruction, deprecated

Responses

CodeDescriptionSchema
200OKAPIEntitiesPackage
400Bad Request—
401Unauthorized—
404Group Not Found—

Download the maven package file for the instance

GET /api/v4/packages/maven/{path}/{file_name}

This feature was introduced in GitLab 11.6

Parameters

NameTypeDescription
file_name
Path, required
StringPackage file name
Example: mypkg-1.0-SNAPSHOT.jar
path
Path, required
StringPackage path
Example: foo/bar/mypkg/1.0-SNAPSHOT

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

List all packages for a project

GET /api/v4/projects/{id}/packages

Lists all packages for a specified project. All package types are included in results. Unauthenticated requests return only packages of public projects. By default, packages with default, deprecated, and error status are returned. Use the status parameter to view other packages.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20
order_by
Query
StringReturn packages ordered by created_at, name, version or type fields
Allowed values: created_at, name, version, type
Default: created_at
sort
Query
StringReturn packages sorted in asc or desc order
Allowed values: asc, desc
Default: asc
package_type
Query
StringReturn packages of a certain type
Allowed values: maven, npm, conan, nuget, pypi, composer, generic, golang, debian, rubygems, helm, terraform_module, rpm, ml_model, cargo
package_name
Query
StringReturn packages with this name
package_version
Query
StringReturn packages with this version
include_versionless
Query
BooleanReturns packages without a version
status
Query
StringReturn packages with specified status
Allowed values: default, hidden, processing, error, pending_destruction, deprecated

Responses

CodeDescriptionSchema
200OKAPIEntitiesPackage
400Bad Request—
403Forbidden—
404Project Not Found—

Download package file

GET /api/v4/projects/{id}/packages/generic/{package_name}/{package_version}/{file_name}

This feature was introduced in GitLab 13.5

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringPackage name
Pattern: ^[A-Za-z0-9._\-+]+$
file_name
Path, required
StringPackage file name
Pattern: ^(?!~)(?!@)[A-Za-z0-9._\-+~@]+(?<!~)(?<!@)$
package_version
Path, required
StringPackage version
Pattern: ^(?!(?:[\uD800-\uDBFF][\uDC00-\uDFFF]|[^\n\uD800-\uDFFF])*\.\.)[\w+.\-]+$
download_mode
Query
StringRequested download transfer mode (proxy or direct). Only honored when allowed by the object storage configuration
Allowed values: proxy, direct

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Upload package file

PUT /api/v4/projects/{id}/packages/generic/{package_name}/{package_version}/{file_name}

This feature was introduced in GitLab 13.5

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringPackage name
Pattern: ^[A-Za-z0-9._\-+]+$
file_name
Path, required
StringPackage file name
Pattern: ^(?!~)(?!@)[A-Za-z0-9._\-+~@]+(?<!~)(?<!@)$
package_version
Path, required
StringPackage version
Pattern: ^(?!(?:[\uD800-\uDBFF][\uDC00-\uDFFF]|[^\n\uD800-\uDFFF])*\.\.)[\w+.\-]+$

Request body (multipart/form-data)

PropertyTypeDescription
file
Required
String (binary)The package file to publish (generated by Multipart middleware)
selectStringResponse format selector. If set to “package_file”, returns the created package file object in the response
Allowed values: package_file
statusStringPackage status
Allowed values: default, hidden

Responses

CodeDescriptionSchema
200OK—
201Created—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Workhorse authorize generic package file

PUT /api/v4/projects/{id}/packages/generic/{package_name}/{package_version}/{file_name}/authorize

This feature was introduced in GitLab 13.5

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringPackage name
Pattern: ^[A-Za-z0-9._\-+]+$
file_name
Path, required
StringPackage file name
Pattern: ^(?!~)(?!@)[A-Za-z0-9._\-+~@]+(?<!~)(?<!@)$
package_version
Path, required
StringPackage version
Pattern: ^(?!(?:[\uD800-\uDBFF][\uDC00-\uDFFF]|[^\n\uD800-\uDFFF])*\.\.)[\w+.\-]+$

Request body (application/json)

PropertyTypeDescription
statusStringPackage status
Allowed values: default, hidden

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Download package file

GET /api/v4/projects/{id}/packages/generic/{package_name}/{package_version}/{path}/{file_name}

This feature was introduced in GitLab 13.5

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringPackage name
Pattern: ^[A-Za-z0-9._\-+]+$
file_name
Path, required
StringPackage file name
Pattern: ^(?!~)(?!@)[A-Za-z0-9._\-+~@]+(?<!~)(?<!@)$
package_version
Path, required
StringPackage version
Pattern: ^(?!(?:[\uD800-\uDBFF][\uDC00-\uDFFF]|[^\n\uD800-\uDFFF])*\.\.)[\w+.\-]+$
path
Path, required
StringFile directory path
download_mode
Query
StringRequested download transfer mode (proxy or direct). Only honored when allowed by the object storage configuration
Allowed values: proxy, direct

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Upload package file

PUT /api/v4/projects/{id}/packages/generic/{package_name}/{package_version}/{path}/{file_name}

This feature was introduced in GitLab 13.5

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringPackage name
Pattern: ^[A-Za-z0-9._\-+]+$
file_name
Path, required
StringPackage file name
Pattern: ^(?!~)(?!@)[A-Za-z0-9._\-+~@]+(?<!~)(?<!@)$
package_version
Path, required
StringPackage version
Pattern: ^(?!(?:[\uD800-\uDBFF][\uDC00-\uDFFF]|[^\n\uD800-\uDFFF])*\.\.)[\w+.\-]+$
path
Path, required
StringFile directory path

Request body (multipart/form-data)

PropertyTypeDescription
file
Required
String (binary)The package file to publish (generated by Multipart middleware)
selectStringResponse format selector. If set to “package_file”, returns the created package file object in the response
Allowed values: package_file
statusStringPackage status
Allowed values: default, hidden

Responses

CodeDescriptionSchema
200OK—
201Created—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Workhorse authorize generic package file

PUT /api/v4/projects/{id}/packages/generic/{package_name}/{package_version}/{path}/{file_name}/authorize

This feature was introduced in GitLab 13.5

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringPackage name
Pattern: ^[A-Za-z0-9._\-+]+$
file_name
Path, required
StringPackage file name
Pattern: ^(?!~)(?!@)[A-Za-z0-9._\-+~@]+(?<!~)(?<!@)$
package_version
Path, required
StringPackage version
Pattern: ^(?!(?:[\uD800-\uDBFF][\uDC00-\uDFFF]|[^\n\uD800-\uDFFF])*\.\.)[\w+.\-]+$
path
Path, required
——

Request body (application/json)

PropertyTypeDescription
statusStringPackage status
Allowed values: default, hidden

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

List

GET /api/v4/projects/{id}/packages/go/{module_name}/@v/list

Get all tagged versions for a given Go module.See go help goproxy, GET $GOPROXY/<module>/@v/list. This feature was introduced in GitLab 13.1.

Parameters

NameTypeDescription
id
Path, required
String or integerThe project ID or full path of a project
module_name
Path, required
StringThe name of the Go module

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
404Not Found—

Version metadata

GET /api/v4/projects/{id}/packages/go/{module_name}/@v/{module_version}.info

Get all tagged versions for a given Go module.See go help goproxy, GET $GOPROXY/<module>/@v/<version>.info. This feature was introduced in GitLab 13.1

Parameters

NameTypeDescription
id
Path, required
String or integerThe project ID or full path of a project
module_name
Path, required
StringThe name of the Go module
module_version
Path, required
StringThe version of the Go module

Responses

CodeDescriptionSchema
200OKAPIEntitiesGoModuleVersion
400Bad Request—
404Not Found—

Download module file

GET /api/v4/projects/{id}/packages/go/{module_name}/@v/{module_version}.mod

Get the module file of a given module version.See go help goproxy, GET $GOPROXY/<module>/@v/<version>.mod. This feature was introduced in GitLab 13.1.

Parameters

NameTypeDescription
id
Path, required
String or integerThe project ID or full path of a project
module_name
Path, required
StringThe name of the Go module
module_version
Path, required
StringThe version of the Go module

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
404Not Found—

Download module source

GET /api/v4/projects/{id}/packages/go/{module_name}/@v/{module_version}.zip

Get a zip of the source of the given module version.See go help goproxy, GET $GOPROXY/<module>/@v/<version>.zip. This feature was introduced in GitLab 13.1.

Parameters

NameTypeDescription
id
Path, required
String or integerThe project ID or full path of a project
module_name
Path, required
StringThe name of the Go module
module_version
Path, required
StringThe version of the Go module

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
404Not Found—

Download the maven package file for a project

GET /api/v4/projects/{id}/packages/maven/{path}/{file_name}

This feature was introduced in GitLab 11.3

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
file_name
Path, required
StringPackage file name
Example: mypkg-1.0-SNAPSHOT.jar
path
Path, required
StringPackage path
Example: foo/bar/mypkg/1.0-SNAPSHOT

Responses

CodeDescriptionSchema
200OK—
302Found—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Upload the maven package file

PUT /api/v4/projects/{id}/packages/maven/{path}/{file_name}

This feature was introduced in GitLab 11.3

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
path
Path, required
StringPackage path
Example: foo/bar/mypkg/1.0-SNAPSHOT
file_name
Path, required
StringPackage file name
Pattern: ^[A-Za-z0-9._\-+]+$
Example: mypkg-1.0-SNAPSHOT.pom

Request body (multipart/form-data)

PropertyTypeDescription
file
Required
String (binary)The package file to be published (generated by Multipart middleware)

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—
422Unprocessable Entity—

Workhorse authorize the maven package file upload

PUT /api/v4/projects/{id}/packages/maven/{path}/{file_name}/authorize

This feature was introduced in GitLab 11.3

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
path
Path, required
StringPackage path
Example: foo/bar/mypkg/1.0-SNAPSHOT
file_name
Path, required
StringPackage file name
Pattern: ^[A-Za-z0-9._\-+]+$
Example: mypkg-1.0-SNAPSHOT.pom

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Retrieve a project package

GET /api/v4/projects/{id}/packages/{package_id}

Retrieves a specified project package. Only packages with status default or deprecated are returned.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_id
Path, required
IntegerThe ID of a package

Responses

CodeDescriptionSchema
200OKAPIEntitiesPackage
400Bad Request—
403Forbidden—
404Not Found—

Delete a project package

DELETE /api/v4/projects/{id}/packages/{package_id}

Deletes a specified project package.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_id
Path, required
IntegerThe ID of a package

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
403Forbidden—
404Not Found—

List all package files

GET /api/v4/projects/{id}/packages/{package_id}/package_files

Lists all package files for a specified package.

Parameters

NameTypeDescription
id
Path, required
String or integerID or URL-encoded path of the project
package_id
Path, required
IntegerID of a package
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20
order_by
Query
StringReturn package files ordered by id, created_at or file_name
Allowed values: id, created_at, file_name
Default: id
sort
Query
StringReturn package files sorted in asc or desc order
Allowed values: asc, desc
Default: asc

Responses

CodeDescriptionSchema
200OKAPIEntitiesPackageFile
400Bad Request—
404Not Found—

Delete a package file

DELETE /api/v4/projects/{id}/packages/{package_id}/package_files/{package_file_id}

Deletes a specified package file.

Parameters

NameTypeDescription
id
Path, required
String or integerID or URL-encoded path of the project
package_id
Path, required
IntegerID of a package
package_file_id
Path, required
IntegerID of a package file

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
403Forbidden—
404Not found—

Download a package file

GET /api/v4/projects/{id}/packages/{package_id}/package_files/{package_file_id}/download

This feature was introduced in GitLab 18.4

Parameters

NameTypeDescription
id
Path, required
String or integerID or URL-encoded path of the project
package_id
Path, required
IntegerID of a package
package_file_id
Path, required
IntegerID of a package file
download_mode
Query
StringRequested download transfer mode (proxy or direct). Only honored when allowed by the object storage configuration
Allowed values: proxy, direct

Responses

CodeDescriptionSchema
200OKString (binary) (application/octet-stream)
400Bad Request—
401Unauthorized—
403Forbidden—
404Not found—

List all package pipelines

GET /api/v4/projects/{id}/packages/{package_id}/pipelines

Lists all pipelines for a specified package. The results are sorted by id in descending order. The results are paginated and return up to 20 records per page. This feature was introduced in GitLab 16.1.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Maximum: 20
Minimum: 1
Example: 20
package_id
Path, required
IntegerThe ID of a package
cursor
Query
StringCursor for obtaining the next set of records

Responses

CodeDescriptionSchema
200OKAPIEntitiesPackagePipeline
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Schemas

Objects returned by the operations above and objects nested in their request bodies.

APIEntitiesCustomAttribute

PropertyTypeDescription
keyStringExample: foo
valueStringExample: bar

APIEntitiesGoModuleVersion

PropertyTypeDescription
TimeStringExample: 1617822312 -0600
VersionStringExample: v1.0.0

APIEntitiesPackage

PropertyTypeDescription
_linksObject—
_links.delete_api_pathString—
_links.web_pathString—
conan_package_nameString—
created_atString (date-time)Example: 2022-09-16T12:47:31.949Z
creator_idInteger (int64)ID of the user who created the package
Example: 1
idInteger (int64)Example: 1
last_downloaded_atString (date-time)Example: 2022-09-19T11:32:35.169Z
nameStringExample: @foo/bar
package_typeStringExample: npm
pipelineAPIEntitiesPackagePipeline—
pipelinesAPIEntitiesPackagePipeline—
project_idInteger (int64)Example: 2
project_pathStringExample: gitlab/foo/bar
statusStringExample: default
tagsString—
versionStringExample: 1.0.3
versionsAPIEntitiesPackageVersion—

APIEntitiesPackageFile

PropertyTypeDescription
created_atString (date-time)Example: 2018-11-07T15:25:52.199Z
file_md5StringExample: 58e6a45a629910c6ff99145a688971ac
file_nameStringExample: my-app-1.5-20181107.152550-1.jar
file_sha1StringExample: ebd193463d3915d7e22219f52740056dfd26cbfe
file_sha256StringExample: a903393463d3915d7e22219f52740056dfd26cbfeff321b
idInteger (int64)Example: 225
package_idInteger (int64)Example: 4
pipelinesAPIEntitiesPackagePipeline—
sizeIntegerExample: 2421

APIEntitiesPackagePipeline

PropertyTypeDescription
created_atString (date-time)Example: 2022-10-21T16:49:48.000+02:00
idInteger (int64)Example: 1
iidIntegerExample: 2
project_idInteger (int64)Example: 3
refStringExample: feature-branch
shaStringExample: 0ec9e58fdfca6cdd6652c083c9edb53abc0bad52
sourceStringExample: push
statusStringExample: success
updated_atString (date-time)Example: 2022-10-21T16:49:48.000+02:00
userAPIEntitiesUserBasic—
web_urlStringExample: https://gitlab.example.com/gitlab-org/gitlab-foss/-/pipelines/61

APIEntitiesPackageVersion

PropertyTypeDescription
created_atString—
idString—
pipelineAPIEntitiesPackagePipeline—
tagsString—
versionString—

APIEntitiesUserBasic

PropertyTypeDescription
avatar_pathStringExample: /user/avatar/28/The-Big-Lebowski-400-400.png
avatar_urlStringExample: https://gravatar.com/avatar/1
custom_attributesArray of APIEntitiesCustomAttribute—
idInteger (int64)Example: 1
lockedBoolean—
nameStringExample: Administrator
public_emailStringExample: john@example.com
stateStringExample: active
usernameStringExample: admin
web_urlStringExample: https://gitlab.example.com/root