Needs API access and the read:attestations scope, on any plan that includes API access.
Required scope: read:attestations
apiKeyAuthorizationBearer <token>Send the key as Authorization: Bearer plk_live_.... No other header is accepted.
The public keys, current key first.
application/jsondata*curl -X GET "https://api.prodgator.io/v1/provenance/keys" \ -H "Authorization: Bearer plk_live_YOUR_KEY"{ "data": { "keys": [ { "keyid": "string", "alg": "ecdsa-p256-sha256", "pem": "string" } ] }}A DSSE envelope with an in-toto change record statement. Needs the Enterprise plan (release provenance and signed attestations). A 409 names its cause in error.details.reason: CHAIN_BROKEN, NOT_LANDED, NO_COMMIT or RECORD_EXPIRED.
Required scope: read:attestations
apiKeyAuthorizationBearer <token>Send the key as Authorization: Bearer plk_live_.... No other header is accepted.
id*string^[A-Za-z0-9._:-]{1,128}$The signed statement.
application/jsondata*curl -X GET "https://api.prodgator.io/v1/provenance/changes/string/statement" \ -H "Authorization: Bearer plk_live_YOUR_KEY"{ "data": { "envelope": { "payloadType": "string", "payload": "string", "signatures": [ { "keyid": "string", "sig": "string" } ] }, "statement_digest": "string" }}A DSSE envelope with an in-toto promotion path statement. Needs the Enterprise plan. A 409 names its cause in error.details.reason: LINEAGE_NOT_READY or NO_COMMIT.
Required scope: read:attestations
apiKeyAuthorizationBearer <token>Send the key as Authorization: Bearer plk_live_.... No other header is accepted.
id*string^[A-Za-z0-9._:-]{1,128}$The signed statement.
application/jsondata*curl -X GET "https://api.prodgator.io/v1/provenance/deployments/string/lineage/statement" \ -H "Authorization: Bearer plk_live_YOUR_KEY"{ "data": { "envelope": { "payloadType": "string", "payload": "string", "signatures": [ { "keyid": "string", "sig": "string" } ] }, "statement_digest": "string" }}A DSSE envelope with a SLSA verification summary. Needs the Enterprise plan. A 404 has error.details.reason NOT_PROTECTED (not a protected environment) or NO_CHANGE (no change record). A 409 has CHAIN_BROKEN, NO_COMMIT, NOT_DEPLOYED or RECORD_EXPIRED.
Required scope: read:attestations
apiKeyAuthorizationBearer <token>Send the key as Authorization: Bearer plk_live_.... No other header is accepted.
id*string^[A-Za-z0-9._:-]{1,128}$The signed statement.
application/jsondata*curl -X GET "https://api.prodgator.io/v1/provenance/deployments/string/verification" \ -H "Authorization: Bearer plk_live_YOUR_KEY"{ "data": { "envelope": { "payloadType": "string", "payload": "string", "signatures": [ { "keyid": "string", "sig": "string" } ] }, "statement_digest": "string" }}