release.garden API (0.0.0)

Download OpenAPI specification:

Authentication attempts are limited to 600 requests per client IP per minute. Authenticated requests are also rate limited per account or project key. Excess requests return 429 with Retry-After. Uploads also have hourly and concurrency limits.

The CLI sends its SemVer version in X-Rls-Version. Unsupported CLI versions return 400 with code: cli_version_unsupported, an update message in error, and the supported SemVer range in supported_versions. Direct API clients do not need this header.

Verifying release signatures

GET /projects/{slug}/releases/{version}/signature returns the release's signed manifest and attestation. GET /signing-keys returns the root public key named by attestation.key_version.

Root keys use ECDSA NIST P-256 with SHA-256. Public keys are base64-encoded PKIX SubjectPublicKeyInfo DER; root signatures are base64-encoded ASN.1 DER. Verify the root signature over SHA-256 of the attestation's exact JSON bytes, preserving field order, escaping, and whitespace. Check the attestation's release identity, manifest hash, and publisher key against the release bundle. Verify the publisher's Ed25519 signature over SHA-256 of the canonical manifest.

Account

Get the current account

Requires an account API key.

Authorizations:
bearerAuth

Responses

Response samples

Content type
application/json
{
  • "email": "string"
}

Projects

List accessible projects

Returns up to 100 items per page, newest first. Pass next_cursor as cursor to continue. Account keys see owned and joined projects; automation keys see only their project.

Authorizations:
bearerAuth
query Parameters
limit
integer [ 1 .. 100 ]
Default: 100
cursor
string

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "next_cursor": "string"
}

Create a project

Requires an account API key. Defaults to public visibility and a slug generated from the name. An explicit slug must be available. Private projects require Plus.

Authorizations:
bearerAuth
Request Body schema: application/json
required
name
required
string non-empty

Trimmed before validation; must be 1–100 UTF-8 bytes.

slug
string [ 1 .. 100 ] characters ^[a-z0-9]+(-[a-z0-9]+)*$

Exact project slug. Omit to generate one from the name.

visibility
string
Default: "public"
Enum: "public" "private"

Set during creation. Private projects require licenses for downloads.

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "slug": "string",
  • "visibility": "public"
}

Response samples

Content type
application/json
{
  • "name": "string",
  • "slug": "string",
  • "suggest_push": true
}

Show a project

Requires an owner or member account key, or a project automation key. Returns visibility and each channel's current non-yanked release, including for private projects.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$

Responses

Response samples

Content type
application/json
{
  • "name": "string",
  • "slug": "string",
  • "visibility": "public",
  • "channels": [
    ]
}

Rename a project

Requires the project owner's account key.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
Request Body schema: application/json
required
name
required
string non-empty

Trimmed before validation; must be 1–100 UTF-8 bytes.

Responses

Request samples

Content type
application/json
{
  • "name": "string"
}

Response samples

Content type
application/json
{
  • "name": "string",
  • "slug": "string",
  • "suggest_push": true
}

Delete a project

Requires the project owner's account key. Deletes the project's releases, project API keys, memberships, and invitations, then queues artifact cleanup. Fails if the project has any licenses — revoke them first.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$

Responses

Response samples

Content type
application/json
{
  • "error": "string",
  • "code": "string",
  • "supported_versions": "string"
}

Change a project's public slug

Requires the project owner's account key. Existing public links using the old slug will stop working.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
Request Body schema: application/json
required
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$

Responses

Request samples

Content type
application/json
{
  • "slug": "string"
}

Response samples

Content type
application/json
{
  • "name": "string",
  • "slug": "string",
  • "suggest_push": true
}

Change project visibility

Requires the project owner's account key.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
Request Body schema: application/json
required
visibility
required
string
Enum: "public" "private"

Responses

Request samples

Content type
application/json
{
  • "visibility": "public"
}

Response samples

Content type
application/json
{
  • "error": "string",
  • "code": "string",
  • "supported_versions": "string"
}

Project Keys

List active project keys

Requires the project owner's account key. Complete key values are never returned.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Create a project key

Requires the project owner's account key. The complete key is returned only once and expires after 30 days.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
Request Body schema: application/json
required
name
string <= 200 characters

Optional label. Whitespace at either end is removed; an empty value uses Automation key.

Responses

Request samples

Content type
application/json
{
  • "name": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "prefix": "string",
  • "created_at": "2019-08-24T14:15:22Z",
  • "last_used_at": "2019-08-24T14:15:22Z",
  • "expires_at": "2019-08-24T14:15:22Z",
  • "key": "string"
}

Revoke a project key

Requires the project owner's account key.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
key
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "error": "string",
  • "code": "string",
  • "supported_versions": "string"
}

Members

List project members

Requires an account key belonging to the owner or a member.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Remove a project member

Requires the project owner's account key. The owner cannot be removed.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
member
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "error": "string",
  • "code": "string",
  • "supported_versions": "string"
}

Change a project member's role

Requires the project owner's account key. A member can be a contributor or support; the owner role cannot be assigned.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
member
required
string <uuid>
Request Body schema: application/json
required
role
required
string
Enum: "contributor" "support"

Responses

Request samples

Content type
application/json
{
  • "role": "contributor"
}

Response samples

Content type
application/json
{
  • "role": "contributor"
}

Leave a project

Requires a member's account key. The owner cannot leave.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$

Responses

Response samples

Content type
application/json
{
  • "error": "string",
  • "code": "string",
  • "supported_versions": "string"
}

Invitations

Accept a project invitation

Requires the invited account's API key. Send the invitation token in the request body.

Authorizations:
bearerAuth
Request Body schema: application/json
required
token
required
string = 43 characters ^[A-Za-z0-9_-]{43}$

Responses

Request samples

Content type
application/json
{
  • "token": "stringstringstringstringstringstringstrings"
}

Response samples

Content type
application/json
{
  • "error": "string",
  • "code": "string",
  • "supported_versions": "string"
}

List pending invitations

Requires the project owner's account key.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$

Responses

Response samples

Content type
application/json
[
  • {
    }
]

Invite a project member

Requires the project owner's account key. Sends an invitation email that expires after seven days. Dashboard and API sends share limits of 20 emails per account and 60 per client IP per hour, with a five-minute resend cooldown per recipient. Throttled requests return 429 with Retry-After and do not change the invitation or send email.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
Request Body schema: application/json
required
email
required
string <email>
role
string
Default: "contributor"
Enum: "contributor" "support"

Responses

Request samples

Content type
application/json
{}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "email": "[email protected]",
  • "role": "contributor",
  • "created_at": "2019-08-24T14:15:22Z",
  • "expires_at": "2019-08-24T14:15:22Z"
}

Cancel a project invitation

Requires the project owner's account key.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
invitation
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "error": "string",
  • "code": "string",
  • "supported_versions": "string"
}

Publish

Upload files directly to storage, then ask Garden to verify and publish them. The CLI's rls push handles these steps for you.

  1. POST /projects/{slug}/uploads with your release metadata and each file's filename and exact byte size. Save the returned upload ID.
  2. POST /projects/{slug}/uploads/{uploadId}/files/{fileIndex}/parts for each file. File indexes start at zero and follow the order in your request.
  3. PUT each file's byte ranges to the returned URLs using the supplied headers and exact part sizes. Empty files have no parts. Keep upload URLs private; they expire after 15 minutes. Request fresh URLs if needed. Retrying a part replaces its previous upload.
  4. GET /projects/{slug}/uploads/{uploadId} every 30 seconds while uploading to keep the session active. A session expires after three minutes without activity, or after three hours total.
  5. Once all parts have uploaded, POST /projects/{slug}/uploads/{uploadId}/complete. Repeating this request is safe. If the validation queue is full, retry this request after Retry-After and keep the uploading session active.
  6. Poll GET /projects/{slug}/uploads/{uploadId} until status is published or failed. Only published confirms success and includes your release. On failure, inspect error and error_status. Queued sessions expire eight hours after queue admission.

Use the same API key for all requests in a session. DELETE /projects/{slug}/uploads/{uploadId} cancels an upload before processing starts. To retry after cancellation, expiry, or failure, start a new session.

Start a release upload

Start an upload session for any release size. See the publishing steps above. Requires an owner or contributor account key, or a project automation key. Any file format is accepted within your plan's artifact and storage limits. Filenames must be unique. Install metadata generates scripts for declared platforms: tar.gz for Linux and macOS, ZIP with a matching EXE for Windows. It reserves install.sh and install.ps1. At capacity, uploads return 429 with Retry-After. Capacity rejections do not consume the hourly upload allowance.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
Request Body schema: application/json
required
version
required
string [ 1 .. 1024 ] characters ^[A-Za-z0-9][A-Za-z0-9._+-]*$

A unique, case-sensitive release label. Use SemVer, CalVer, or your own format. Start with a letter or digit; use ASCII letters, digits, dots, underscores, hyphens, and plus signs. latest and changelog are reserved.

channel
string^[a-z]([a-z0-9-]{0,30}[a-z0-9])?$
Default: "stable"
notes
string

UTF-8 Markdown, up to 256 KiB.

object

Install configuration, up to 16 KiB of JSON.

ephemeral_pubkey
string

Base64-encoded Ed25519 public key.

artifact_signature
string

Base64-encoded signature of the release manifest digest.

required
Array of objects (ReleaseUploadFile) [ 1 .. 20 ] items

Responses

Request samples

Content type
application/json
{
  • "version": "1.0.0",
  • "channel": "stable",
  • "notes": "string",
  • "install": {
    },
  • "ephemeral_pubkey": "string",
  • "artifact_signature": "string",
  • "files": [
    ]
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "status": "uploading",
  • "part_size": 0,
  • "files": [
    ],
  • "release": {
    },
  • "error": "string",
  • "error_status": 0
}

Check release upload progress

Poll until published or failed. A successful upload includes the published release. Uploading sessions expire after three hours; queued sessions expire eight hours after queue admission.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
uploadId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "status": "uploading",
  • "part_size": 0,
  • "files": [
    ],
  • "release": {
    },
  • "error": "string",
  • "error_status": 0
}

Cancel an unfinished upload

Cancels uploading or queued sessions. Returns 409 once verification starts or the upload is finished.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
uploadId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "error": "string",
  • "code": "string",
  • "supported_versions": "string"
}

Authorize file part uploads

Returns upload URLs, headers, and part sizes for one file. PUT each byte range to its URL using the supplied headers and exact size. URLs expire after 15 minutes; request fresh URLs if needed.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
uploadId
required
string <uuid>
fileIndex
required
integer [ 0 .. 19 ]

Responses

Response samples

Content type
application/json
{
  • "parts": [
    ]
}

Verify and publish uploaded files

Queues validation and publication of your uploaded release. Poll the progress endpoint until published or failed. Repeated requests return the current status without publishing again. If the queue is full, retry this request after Retry-After while keeping the uploading session active; do not upload the files again.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
uploadId
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "status": "uploading",
  • "part_size": 0,
  • "files": [
    ],
  • "release": {
    },
  • "error": "string",
  • "error_status": 0
}

Releases

List releases, including yanked releases

Returns up to 100 releases per page, newest first, including yanked releases. Channels show current non-yanked targets. Pass next_cursor as cursor to continue. Requires an owner or member account key, or the project automation key.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
query Parameters
limit
integer [ 1 .. 100 ]
Default: 100
cursor
string

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "next_cursor": "string"
}

List public channel targets

Lists each channel's current eligible release for a public project. Private and inaccessible projects return 404.

path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$

Responses

Response samples

Content type
application/json
{
  • "channels": [
    ]
}

Withdraw a release

Requires an owner or contributor account key, or a project automation key. The version remains reserved and its public page shows a withdrawal notice, but its files can no longer be downloaded. Repeating the request succeeds.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
version
required
string

Responses

Response samples

Content type
application/json
{
  • "error": "string",
  • "code": "string",
  • "supported_versions": "string"
}

Assign an existing release to a channel

Requires a publisher API key. Supplying from_channel also removes that assignment atomically. Release contents and identity are unchanged.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
version
required
string
Request Body schema: application/json
required
channel
required
string^[a-z]([a-z0-9-]{0,30}[a-z0-9])?$
from_channel
string^[a-z]([a-z0-9-]{0,30}[a-z0-9])?$

Responses

Request samples

Content type
application/json
{
  • "channel": "string",
  • "from_channel": "string"
}

Response samples

Content type
application/json
{
  • "error": "string",
  • "code": "string",
  • "supported_versions": "string"
}

Remove a release from a channel

Requires a publisher API key. The version URL and artifacts remain available.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
version
required
string
channel
required
string

Responses

Response samples

Content type
application/json
{
  • "error": "string",
  • "code": "string",
  • "supported_versions": "string"
}

Get a release's files and checksums

Returns metadata and SHA-256 checksums for a public release. Private, missing, or suspended projects, and projects with suspended or disabled owners, return 404. Use an account or project API key with the authenticated API for private projects. Yanked releases return yanked: true and an empty file list.

path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
version
required
string
query Parameters
channel
string

Channel used when version is latest; defaults to stable.

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "version": "string",
  • "channels": [
    ],
  • "yanked": true,
  • "files": [
    ]
}

Get a release's signature bundle

Returns the signed manifest, one-time publisher signature, and release.garden attestation binding the publisher key to the project and release. Verify the attestation with its key from GET /signing-keys. Generated installers are excluded from the manifest and carry embedded checksums. Yanked or unsigned releases return only signed: false.

path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
version
required
string
query Parameters
channel
string

Channel used when version is latest; defaults to stable.

Responses

Response samples

Content type
application/json
{
  • "signed": true,
  • "manifest": [
    ],
  • "ephemeral_pubkey": "string",
  • "artifact_signature": "string",
  • "attestation": {
    },
  • "attestation_signature": "string",
  • "key_version": "string"
}

Get a release file's download URL

Returns file metadata and a one-minute download URL. Use "latest" for the newest eligible version. Public, non-suspended projects need no credential. Private downloads require Authorization: Bearer <license key>. Account and project API keys are not accepted. Missing or invalid credentials return 401; ineligible licenses and missing releases or files return 404. Private generated installers return personalized content_base64 instead of download_url. All other files return download_url.

Authorizations:
NonelicenseKeyAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
version
required
string
filename
required
string
query Parameters
channel
string

Channel used when version is latest; defaults to stable.

Responses

Response samples

Content type
application/json
{
  • "filename": "string",
  • "artifact_type": "string",
  • "byte_size": 0,
  • "sha256": "string",
  • "download_url": "string",
  • "content_base64": "string"
}

Licenses

Issue a license

Requires an owner or support account key, or a project automation key. Reuse Idempotency-Key within the project to retry without issuing another license. Retries return the existing license without its key.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
header Parameters
Idempotency-Key
string <= 255 characters
Request Body schema: application/json
required
name
required
string [ 1 .. 200 ] characters

Customer or order label. Does not affect access.

updates_until
string or null <date-time>

Update cutoff. Omit or set to null for lifetime updates. Access to releases published on or before this date continues after it passes.

metadata
object

JSON metadata for your customer or order records, up to 4096 bytes. Does not affect access.

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "updates_until": "2019-08-24T14:15:22Z",
  • "metadata": { }
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "key": "string",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updates_until": "2019-08-24T14:15:22Z",
  • "revoked_at": "2019-08-24T14:15:22Z",
  • "metadata": { }
}

List licenses

Requires an owner or support account key, or a project automation key. Complete keys are never included. Follow next_cursor until it is null.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
query Parameters
limit
integer [ 1 .. 100 ]
Default: 100

Maximum number of licenses to return.

cursor
string

Opaque next_cursor from a previous response for this project.

Responses

Response samples

Content type
application/json
{
  • "items": [
    ],
  • "next_cursor": "string"
}

Get a license

Requires an owner or support account key, or a project automation key. The complete key is never included.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
license
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "name": "string",
  • "key": "string",
  • "created_at": "2019-08-24T14:15:22Z",
  • "updates_until": "2019-08-24T14:15:22Z",
  • "revoked_at": "2019-08-24T14:15:22Z",
  • "metadata": { }
}

Revoke a license

Requires an owner or support account key, or a project automation key. Immediately and permanently revokes all access. Repeated requests succeed.

Authorizations:
bearerAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
license
required
string <uuid>

Responses

Response samples

Content type
application/json
{
  • "error": "string",
  • "code": "string",
  • "supported_versions": "string"
}

Public

Public endpoints; no API key required.

List public channel targets

Lists each channel's current eligible release for a public project. Private and inaccessible projects return 404.

path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$

Responses

Response samples

Content type
application/json
{
  • "channels": [
    ]
}

Get a release's files and checksums

Returns metadata and SHA-256 checksums for a public release. Private, missing, or suspended projects, and projects with suspended or disabled owners, return 404. Use an account or project API key with the authenticated API for private projects. Yanked releases return yanked: true and an empty file list.

path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
version
required
string
query Parameters
channel
string

Channel used when version is latest; defaults to stable.

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "version": "string",
  • "channels": [
    ],
  • "yanked": true,
  • "files": [
    ]
}

Get a release's signature bundle

Returns the signed manifest, one-time publisher signature, and release.garden attestation binding the publisher key to the project and release. Verify the attestation with its key from GET /signing-keys. Generated installers are excluded from the manifest and carry embedded checksums. Yanked or unsigned releases return only signed: false.

path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
version
required
string
query Parameters
channel
string

Channel used when version is latest; defaults to stable.

Responses

Response samples

Content type
application/json
{
  • "signed": true,
  • "manifest": [
    ],
  • "ephemeral_pubkey": "string",
  • "artifact_signature": "string",
  • "attestation": {
    },
  • "attestation_signature": "string",
  • "key_version": "string"
}

Get a release file's download URL

Returns file metadata and a one-minute download URL. Use "latest" for the newest eligible version. Public, non-suspended projects need no credential. Private downloads require Authorization: Bearer <license key>. Account and project API keys are not accepted. Missing or invalid credentials return 401; ineligible licenses and missing releases or files return 404. Private generated installers return personalized content_base64 instead of download_url. All other files return download_url.

Authorizations:
NonelicenseKeyAuth
path Parameters
slug
required
string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$
version
required
string
filename
required
string
query Parameters
channel
string

Channel used when version is latest; defaults to stable.

Responses

Response samples

Content type
application/json
{
  • "filename": "string",
  • "artifact_type": "string",
  • "byte_size": 0,
  • "sha256": "string",
  • "download_url": "string",
  • "content_base64": "string"
}

List release.garden's signing keys

Returns current and historical public keys for verifying release attestations. Match the attestation’s key_version to a key here. Historical keys remain listed indefinitely, so releases stay verifiable after key rotation.

Responses

Response samples

Content type
application/json
[
  • {
    }
]