release.garden API (0.0.0)
Download OpenAPI specification:
Authentication attempts are limited to 600 requests per client IP per minute. Authenticated requests are also rate limited per account or project key. Excess requests return 429 with Retry-After. Uploads also have hourly and concurrency limits.
The CLI sends its SemVer version in X-Rls-Version. Unsupported CLI versions
return 400 with code: cli_version_unsupported, an update message in error,
and the supported SemVer range in supported_versions. Direct API clients
do not need this header.
GET /projects/{slug}/releases/{version}/signature returns the release's signed
manifest and attestation. GET /signing-keys returns the root public key named
by attestation.key_version.
Root keys use ECDSA NIST P-256 with SHA-256. Public keys are base64-encoded PKIX SubjectPublicKeyInfo DER; root signatures are base64-encoded ASN.1 DER. Verify the root signature over SHA-256 of the attestation's exact JSON bytes, preserving field order, escaping, and whitespace. Check the attestation's release identity, manifest hash, and publisher key against the release bundle. Verify the publisher's Ed25519 signature over SHA-256 of the canonical manifest.
List accessible projects
Returns up to 100 items per page, newest first. Pass next_cursor as cursor to continue. Account keys see owned and joined projects; automation keys see only their project.
Authorizations:
query Parameters
| limit | integer [ 1 .. 100 ] Default: 100 |
| cursor | string |
Responses
Response samples
- 200
- 400
- 401
- 404
- 500
{- "items": [
- {
- "name": "string",
- "slug": "string",
- "visibility": "public",
- "role": "owner"
}
], - "next_cursor": "string"
}Create a project
Requires an account API key. Defaults to public visibility and a slug generated from the name. An explicit slug must be available. Private projects require Plus.
Authorizations:
Request Body schema: application/jsonrequired
| name required | string non-empty Trimmed before validation; must be 1–100 UTF-8 bytes. |
| slug | string [ 1 .. 100 ] characters ^[a-z0-9]+(-[a-z0-9]+)*$ Exact project slug. Omit to generate one from the name. |
| visibility | string Default: "public" Enum: "public" "private" Set during creation. Private projects require licenses for downloads. |
Responses
Request samples
- Payload
{- "name": "string",
- "slug": "string",
- "visibility": "public"
}Response samples
- 201
- 400
- 401
- 403
- 409
- 500
{- "name": "string",
- "slug": "string",
- "suggest_push": true
}Show a project
Requires an owner or member account key, or a project automation key. Returns visibility and each channel's current non-yanked release, including for private projects.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Responses
Response samples
- 200
- 400
- 401
- 404
- 500
{- "name": "string",
- "slug": "string",
- "visibility": "public",
- "channels": [
- {
- "name": "string",
- "version": "string"
}
]
}Rename a project
Requires the project owner's account key.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Request Body schema: application/jsonrequired
| name required | string non-empty Trimmed before validation; must be 1–100 UTF-8 bytes. |
Responses
Request samples
- Payload
{- "name": "string"
}Response samples
- 200
- 400
- 401
- 403
- 404
- 409
- 500
{- "name": "string",
- "slug": "string",
- "suggest_push": true
}Delete a project
Requires the project owner's account key. Deletes the project's releases, project API keys, memberships, and invitations, then queues artifact cleanup. Fails if the project has any licenses — revoke them first.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Responses
Response samples
- 400
- 401
- 403
- 404
- 409
- 500
{- "error": "string",
- "code": "string",
- "supported_versions": "string"
}Change a project's public slug
Requires the project owner's account key. Existing public links using the old slug will stop working.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Request Body schema: application/jsonrequired
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Responses
Request samples
- Payload
{- "slug": "string"
}Response samples
- 200
- 400
- 401
- 403
- 404
- 409
- 500
{- "name": "string",
- "slug": "string",
- "suggest_push": true
}Change project visibility
Requires the project owner's account key.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Request Body schema: application/jsonrequired
| visibility required | string Enum: "public" "private" |
Responses
Request samples
- Payload
{- "visibility": "public"
}Response samples
- 400
- 401
- 403
- 404
- 500
{- "error": "string",
- "code": "string",
- "supported_versions": "string"
}List active project keys
Requires the project owner's account key. Complete key values are never returned.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Responses
Response samples
- 200
- 401
- 403
- 404
- 500
[- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "prefix": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "last_used_at": "2019-08-24T14:15:22Z",
- "expires_at": "2019-08-24T14:15:22Z",
- "key": "string"
}
]Create a project key
Requires the project owner's account key. The complete key is returned only once and expires after 30 days.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Request Body schema: application/jsonrequired
| name | string <= 200 characters Optional label. Whitespace at either end is removed; an empty value uses Automation key. |
Responses
Request samples
- Payload
{- "name": "string"
}Response samples
- 201
- 400
- 401
- 403
- 404
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "prefix": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "last_used_at": "2019-08-24T14:15:22Z",
- "expires_at": "2019-08-24T14:15:22Z",
- "key": "string"
}Revoke a project key
Requires the project owner's account key.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| key required | string <uuid> |
Responses
Response samples
- 401
- 403
- 404
- 500
{- "error": "string",
- "code": "string",
- "supported_versions": "string"
}List project members
Requires an account key belonging to the owner or a member.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Responses
Response samples
- 200
- 401
- 403
- 404
- 500
[- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "is_owner": true,
- "role": "owner",
- "joined_at": "2019-08-24T14:15:22Z"
}
]Remove a project member
Requires the project owner's account key. The owner cannot be removed.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| member required | string <uuid> |
Responses
Response samples
- 401
- 403
- 404
- 500
{- "error": "string",
- "code": "string",
- "supported_versions": "string"
}Change a project member's role
Requires the project owner's account key. A member can be a contributor or support; the owner role cannot be assigned.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| member required | string <uuid> |
Request Body schema: application/jsonrequired
| role required | string Enum: "contributor" "support" |
Responses
Request samples
- Payload
{- "role": "contributor"
}Response samples
- 200
- 400
- 401
- 403
- 404
- 500
{- "role": "contributor"
}Leave a project
Requires a member's account key. The owner cannot leave.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Responses
Response samples
- 401
- 403
- 404
- 500
{- "error": "string",
- "code": "string",
- "supported_versions": "string"
}Accept a project invitation
Requires the invited account's API key. Send the invitation token in the request body.
Authorizations:
Request Body schema: application/jsonrequired
| token required | string = 43 characters ^[A-Za-z0-9_-]{43}$ |
Responses
Request samples
- Payload
{- "token": "stringstringstringstringstringstringstrings"
}Response samples
- 400
- 401
- 403
- 404
- 500
{- "error": "string",
- "code": "string",
- "supported_versions": "string"
}List pending invitations
Requires the project owner's account key.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Responses
Response samples
- 200
- 401
- 403
- 404
- 500
[- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "role": "contributor",
- "created_at": "2019-08-24T14:15:22Z",
- "expires_at": "2019-08-24T14:15:22Z"
}
]Invite a project member
Requires the project owner's account key. Sends an invitation email that expires after seven days. Dashboard and API sends share limits of 20 emails per account and 60 per client IP per hour, with a five-minute resend cooldown per recipient. Throttled requests return 429 with Retry-After and do not change the invitation or send email.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Request Body schema: application/jsonrequired
| email required | string <email> |
| role | string Default: "contributor" Enum: "contributor" "support" |
Responses
Request samples
- Payload
{- "role": "contributor"
}Response samples
- 201
- 400
- 401
- 403
- 404
- 429
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "role": "contributor",
- "created_at": "2019-08-24T14:15:22Z",
- "expires_at": "2019-08-24T14:15:22Z"
}Cancel a project invitation
Requires the project owner's account key.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| invitation required | string <uuid> |
Responses
Response samples
- 401
- 403
- 404
- 500
{- "error": "string",
- "code": "string",
- "supported_versions": "string"
}Upload files directly to storage, then ask Garden to verify and publish them.
The CLI's rls push handles these steps for you.
- POST
/projects/{slug}/uploadswith your release metadata and each file's filename and exact byte size. Save the returned upload ID. - POST
/projects/{slug}/uploads/{uploadId}/files/{fileIndex}/partsfor each file. File indexes start at zero and follow the order in your request. - PUT each file's byte ranges to the returned URLs using the supplied headers and exact part sizes. Empty files have no parts. Keep upload URLs private; they expire after 15 minutes. Request fresh URLs if needed. Retrying a part replaces its previous upload.
- GET
/projects/{slug}/uploads/{uploadId}every 30 seconds while uploading to keep the session active. A session expires after three minutes without activity, or after three hours total. - Once all parts have uploaded, POST
/projects/{slug}/uploads/{uploadId}/complete. Repeating this request is safe. If the validation queue is full, retry this request after Retry-After and keep the uploading session active. - Poll GET
/projects/{slug}/uploads/{uploadId}until status ispublishedorfailed. Onlypublishedconfirms success and includes your release. On failure, inspecterroranderror_status. Queued sessions expire eight hours after queue admission.
Use the same API key for all requests in a session. DELETE
/projects/{slug}/uploads/{uploadId} cancels an upload before processing starts.
To retry after cancellation, expiry, or failure, start a new session.
Start a release upload
Start an upload session for any release size. See the publishing steps above. Requires an owner or contributor account key, or a project automation key. Any file format is accepted within your plan's artifact and storage limits. Filenames must be unique. Install metadata generates scripts for declared platforms: tar.gz for Linux and macOS, ZIP with a matching EXE for Windows. It reserves install.sh and install.ps1. At capacity, uploads return 429 with Retry-After. Capacity rejections do not consume the hourly upload allowance.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Request Body schema: application/jsonrequired
| version required | string [ 1 .. 1024 ] characters ^[A-Za-z0-9][A-Za-z0-9._+-]*$ A unique, case-sensitive release label. Use SemVer, CalVer, or your own format. Start with a letter or digit; use ASCII letters, digits, dots, underscores, hyphens, and plus signs. latest and changelog are reserved. |
| channel | string^[a-z]([a-z0-9-]{0,30}[a-z0-9])?$ Default: "stable" |
| notes | string UTF-8 Markdown, up to 256 KiB. |
object Install configuration, up to 16 KiB of JSON. | |
| ephemeral_pubkey | string Base64-encoded Ed25519 public key. |
| artifact_signature | string Base64-encoded signature of the release manifest digest. |
required | Array of objects (ReleaseUploadFile) [ 1 .. 20 ] items |
Responses
Request samples
- Payload
{- "version": "1.0.0",
- "channel": "stable",
- "notes": "string",
- "install": {
- "targets": [
- {
- "os": "string",
- "arch": "string",
- "file": "string",
- "executables": {
- "grove": "bin/grove",
- "grove-admin": "bin/grove-admin"
}
}
]
}, - "ephemeral_pubkey": "string",
- "artifact_signature": "string",
- "files": [
- {
- "filename": "grove.tar.gz",
- "byte_size": 0
}
]
}Response samples
- 201
- 400
- 401
- 403
- 404
- 409
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "status": "uploading",
- "part_size": 0,
- "files": [
- {
- "filename": "grove.tar.gz",
- "byte_size": 0
}
], - "release": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "version": "string",
- "channel": "string",
- "suggest_automation": true
}, - "error": "string",
- "error_status": 0
}Check release upload progress
Poll until published or failed. A successful upload includes the published release. Uploading sessions expire after three hours; queued sessions expire eight hours after queue admission.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| uploadId required | string <uuid> |
Responses
Response samples
- 200
- 400
- 401
- 403
- 404
- 409
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "status": "uploading",
- "part_size": 0,
- "files": [
- {
- "filename": "grove.tar.gz",
- "byte_size": 0
}
], - "release": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "version": "string",
- "channel": "string",
- "suggest_automation": true
}, - "error": "string",
- "error_status": 0
}Cancel an unfinished upload
Cancels uploading or queued sessions. Returns 409 once verification starts or the upload is finished.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| uploadId required | string <uuid> |
Responses
Response samples
- 400
- 401
- 403
- 404
- 409
- 500
{- "error": "string",
- "code": "string",
- "supported_versions": "string"
}Authorize file part uploads
Returns upload URLs, headers, and part sizes for one file. PUT each byte range to its URL using the supplied headers and exact size. URLs expire after 15 minutes; request fresh URLs if needed.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| uploadId required | string <uuid> |
| fileIndex required | integer [ 0 .. 19 ] |
Responses
Response samples
- 200
- 400
- 401
- 403
- 404
- 409
- 500
{- "parts": [
- {
- "part_number": 0,
- "byte_size": 0,
- "url": "string",
- "headers": {
- "property1": [
- "string"
], - "property2": [
- "string"
]
}
}
]
}Verify and publish uploaded files
Queues validation and publication of your uploaded release. Poll the progress endpoint until published or failed. Repeated requests return the current status without publishing again. If the queue is full, retry this request after Retry-After while keeping the uploading session active; do not upload the files again.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| uploadId required | string <uuid> |
Responses
Response samples
- 202
- 400
- 401
- 403
- 404
- 409
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "status": "uploading",
- "part_size": 0,
- "files": [
- {
- "filename": "grove.tar.gz",
- "byte_size": 0
}
], - "release": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "version": "string",
- "channel": "string",
- "suggest_automation": true
}, - "error": "string",
- "error_status": 0
}List releases, including yanked releases
Returns up to 100 releases per page, newest first, including yanked releases. Channels show current non-yanked targets. Pass next_cursor as cursor to continue. Requires an owner or member account key, or the project automation key.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
query Parameters
| limit | integer [ 1 .. 100 ] Default: 100 |
| cursor | string |
Responses
Response samples
- 200
- 400
- 401
- 404
- 500
{- "items": [
- {
- "version": "string",
- "channels": [
- "string"
], - "status": "published",
- "created_at": "2019-08-24T14:15:22Z"
}
], - "next_cursor": "string"
}List public channel targets
Lists each channel's current eligible release for a public project. Private and inaccessible projects return 404.
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Responses
Response samples
- 200
- 404
- 500
{- "channels": [
- {
- "name": "string",
- "release_id": "51d53377-463c-43a4-a864-f9b3ed9178de",
- "version": "string"
}
]
}Withdraw a release
Requires an owner or contributor account key, or a project automation key. The version remains reserved and its public page shows a withdrawal notice, but its files can no longer be downloaded. Repeating the request succeeds.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| version required | string |
Responses
Response samples
- 400
- 401
- 403
- 404
- 500
{- "error": "string",
- "code": "string",
- "supported_versions": "string"
}Assign an existing release to a channel
Requires a publisher API key. Supplying from_channel also removes that assignment atomically. Release contents and identity are unchanged.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| version required | string |
Request Body schema: application/jsonrequired
| channel required | string^[a-z]([a-z0-9-]{0,30}[a-z0-9])?$ |
| from_channel | string^[a-z]([a-z0-9-]{0,30}[a-z0-9])?$ |
Responses
Request samples
- Payload
{- "channel": "string",
- "from_channel": "string"
}Response samples
- 400
- 401
- 403
- 404
- 500
{- "error": "string",
- "code": "string",
- "supported_versions": "string"
}Remove a release from a channel
Requires a publisher API key. The version URL and artifacts remain available.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| version required | string |
| channel required | string |
Responses
Response samples
- 400
- 401
- 403
- 404
- 500
{- "error": "string",
- "code": "string",
- "supported_versions": "string"
}Get a release's files and checksums
Returns metadata and SHA-256 checksums for a public release. Private, missing, or suspended projects, and projects with suspended or disabled owners, return 404. Use an account or project API key with the authenticated API for private projects. Yanked releases return yanked: true and an empty file list.
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| version required | string |
query Parameters
| channel | string Channel used when version is latest; defaults to stable. |
Responses
Response samples
- 200
- 404
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "version": "string",
- "channels": [
- "string"
], - "yanked": true,
- "files": [
- {
- "filename": "string",
- "artifact_type": "string",
- "byte_size": 0,
- "sha256": "string"
}
]
}Get a release's signature bundle
Returns the signed manifest, one-time publisher signature, and release.garden attestation binding the publisher key to the project and release. Verify the attestation with its key from GET /signing-keys.
Generated installers are excluded from the manifest and carry embedded checksums. Yanked or unsigned releases return only signed: false.
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| version required | string |
query Parameters
| channel | string Channel used when version is latest; defaults to stable. |
Responses
Response samples
- 200
- 404
- 500
{- "signed": true,
- "manifest": [
- {
- "filename": "string",
- "sha256": "string"
}
], - "ephemeral_pubkey": "string",
- "artifact_signature": "string",
- "attestation": {
- "project_id": "405d8375-3514-403b-8c43-83ae74cfe0e9",
- "release_id": "51d53377-463c-43a4-a864-f9b3ed9178de",
- "version": "string",
- "manifest_sha256": "string",
- "ephemeral_pubkey": "string",
- "key_version": "string",
- "issued_at": "2019-08-24T14:15:22Z"
}, - "attestation_signature": "string",
- "key_version": "string"
}Get a release file's download URL
Returns file metadata and a one-minute download URL. Use "latest" for the newest eligible version. Public, non-suspended projects need no credential.
Private downloads require Authorization: Bearer <license key>. Account and project API keys are not accepted. Missing or invalid credentials return 401; ineligible licenses and missing releases or files return 404.
Private generated installers return personalized content_base64 instead of download_url. All other files return download_url.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| version required | string |
| filename required | string |
query Parameters
| channel | string Channel used when version is latest; defaults to stable. |
Responses
Response samples
- 200
- 401
- 404
- 500
{- "filename": "string",
- "artifact_type": "string",
- "byte_size": 0,
- "sha256": "string",
- "download_url": "string",
- "content_base64": "string"
}Issue a license
Requires an owner or support account key, or a project automation key. Reuse Idempotency-Key within the project to retry without issuing another license. Retries return the existing license without its key.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
header Parameters
| Idempotency-Key | string <= 255 characters |
Request Body schema: application/jsonrequired
| name required | string [ 1 .. 200 ] characters Customer or order label. Does not affect access. |
| updates_until | string or null <date-time> Update cutoff. Omit or set to null for lifetime updates. Access to releases published on or before this date continues after it passes. |
| metadata | object JSON metadata for your customer or order records, up to 4096 bytes. Does not affect access. |
Responses
Request samples
- Payload
{- "name": "string",
- "updates_until": "2019-08-24T14:15:22Z",
- "metadata": { }
}Response samples
- 200
- 201
- 400
- 401
- 403
- 404
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "key": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updates_until": "2019-08-24T14:15:22Z",
- "revoked_at": "2019-08-24T14:15:22Z",
- "metadata": { }
}List licenses
Requires an owner or support account key, or a project automation key. Complete keys are never included. Follow next_cursor until it is null.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
query Parameters
| limit | integer [ 1 .. 100 ] Default: 100 Maximum number of licenses to return. |
| cursor | string Opaque next_cursor from a previous response for this project. |
Responses
Response samples
- 200
- 400
- 401
- 403
- 404
- 500
{- "items": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "key": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updates_until": "2019-08-24T14:15:22Z",
- "revoked_at": "2019-08-24T14:15:22Z",
- "metadata": { }
}
], - "next_cursor": "string"
}Get a license
Requires an owner or support account key, or a project automation key. The complete key is never included.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| license required | string <uuid> |
Responses
Response samples
- 200
- 401
- 403
- 404
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "key": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updates_until": "2019-08-24T14:15:22Z",
- "revoked_at": "2019-08-24T14:15:22Z",
- "metadata": { }
}Revoke a license
Requires an owner or support account key, or a project automation key. Immediately and permanently revokes all access. Repeated requests succeed.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| license required | string <uuid> |
Responses
Response samples
- 401
- 403
- 404
- 500
{- "error": "string",
- "code": "string",
- "supported_versions": "string"
}List public channel targets
Lists each channel's current eligible release for a public project. Private and inaccessible projects return 404.
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
Responses
Response samples
- 200
- 404
- 500
{- "channels": [
- {
- "name": "string",
- "release_id": "51d53377-463c-43a4-a864-f9b3ed9178de",
- "version": "string"
}
]
}Get a release's files and checksums
Returns metadata and SHA-256 checksums for a public release. Private, missing, or suspended projects, and projects with suspended or disabled owners, return 404. Use an account or project API key with the authenticated API for private projects. Yanked releases return yanked: true and an empty file list.
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| version required | string |
query Parameters
| channel | string Channel used when version is latest; defaults to stable. |
Responses
Response samples
- 200
- 404
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "version": "string",
- "channels": [
- "string"
], - "yanked": true,
- "files": [
- {
- "filename": "string",
- "artifact_type": "string",
- "byte_size": 0,
- "sha256": "string"
}
]
}Get a release's signature bundle
Returns the signed manifest, one-time publisher signature, and release.garden attestation binding the publisher key to the project and release. Verify the attestation with its key from GET /signing-keys.
Generated installers are excluded from the manifest and carry embedded checksums. Yanked or unsigned releases return only signed: false.
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| version required | string |
query Parameters
| channel | string Channel used when version is latest; defaults to stable. |
Responses
Response samples
- 200
- 404
- 500
{- "signed": true,
- "manifest": [
- {
- "filename": "string",
- "sha256": "string"
}
], - "ephemeral_pubkey": "string",
- "artifact_signature": "string",
- "attestation": {
- "project_id": "405d8375-3514-403b-8c43-83ae74cfe0e9",
- "release_id": "51d53377-463c-43a4-a864-f9b3ed9178de",
- "version": "string",
- "manifest_sha256": "string",
- "ephemeral_pubkey": "string",
- "key_version": "string",
- "issued_at": "2019-08-24T14:15:22Z"
}, - "attestation_signature": "string",
- "key_version": "string"
}Get a release file's download URL
Returns file metadata and a one-minute download URL. Use "latest" for the newest eligible version. Public, non-suspended projects need no credential.
Private downloads require Authorization: Bearer <license key>. Account and project API keys are not accepted. Missing or invalid credentials return 401; ineligible licenses and missing releases or files return 404.
Private generated installers return personalized content_base64 instead of download_url. All other files return download_url.
Authorizations:
path Parameters
| slug required | string <= 100 characters ^[a-z0-9]+(-[a-z0-9]+)*$ |
| version required | string |
| filename required | string |
query Parameters
| channel | string Channel used when version is latest; defaults to stable. |
Responses
Response samples
- 200
- 401
- 404
- 500
{- "filename": "string",
- "artifact_type": "string",
- "byte_size": 0,
- "sha256": "string",
- "download_url": "string",
- "content_base64": "string"
}List release.garden's signing keys
Returns current and historical public keys for verifying release attestations. Match the attestation’s key_version to a key here. Historical keys remain listed indefinitely, so releases stay verifiable after key rotation.
Responses
Response samples
- 200
- 500
[- {
- "key_version": "string",
- "public_key": "string",
- "algorithm": "ECDSA_SHA_256",
- "created_at": "2019-08-24T14:15:22Z"
}
]