Attestation
An Attestation records that a principal made a claim about specific Revisions, all in its Space: that they approve them, that a review or check passed or failed, or anything else its Type names. It is never updated; withdrawing one is a new Attestation naming it in RevokedAttestationID.
Operations
| Method | Endpoint | Description |
|---|---|---|
GET |
/attestation |
List of Attestations across spaces |
GET |
/space/{space_id}/attestation |
List ExtendedAttestations |
GET |
/space/{space_id}/attestation/{attestation_id} |
Get ExtendedAttestation |
POST |
/space/{space_id}/attestation |
Record an Attestation |
List of Attestations across spaces
GET /attestation
Retrieves a list of Attestations across spaces in the Organization
Operation ID: ListAllAttestations
Parameters
Query Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
where |
string | The specified string is an expression for the purpose of filtering the list of Attestations returned. The expression syntax was inspired by SQL. It supports conjunctions using AND of relational expressions of the form attribute operator attribute_or_literal. The attribute names are case-sensitive and PascalCase, as in the JSON encoding. Strings support the following operators: <, >, <=, >=, =, !=, LIKE, NOT LIKE, ILIKE, ~~, !~~, ~, ~*, !~, !~*, IN, NOT IN. String pattern operators: LIKE and ~~ for pattern matching with % and _ wildcards, ILIKE for case-insensitive pattern matching, NOT LIKE and !~~ for negated pattern matching. String regex operators: ~ for regex matching, ~* for case-insensitive regex, !~ and !~* for regex not matching (case-sensitive and insensitive). Integers support the following operators: <, >, <=, >=, =, !=, IN, NOT IN. UUIDs and boolean attributes support equality and inequality only. UUID and time literals must be quoted as string literals. String literals are quoted with single quotes, such as 'string'. Time literals use the same form as when serialized as JSON, such as: CreatedAt > '2025-02-18T23:16:34'. Integer and boolean literals are also supported for attributes of those types. Arrays support the ? operator to to match any element of the array, as in FromLinkID ? '7c61626f-ddbe-41af-93f6-b69f4ab6d308'. Arrays can perform LEN() to check for length, as in LEN(FromLinkID) > 0. An attribute naming a list of other entities can be filtered on their attributes with a * segment, as in FromLink.*.Slug = 'upgrade-app', which holds when any element satisfies it. Without the * such a reference is an error, since it names no single value to compare. Map support the dot notation to specify a particular map key, as in Labels.tier = 'Backend'. Maps support IS NULL and IS NOT NULL with dot notation to check for key absence or presence, as in Labels.tier IS NULL (key doesn't exist) or Labels.tier IS NOT NULL (key exists). Comparison results can be tested with IS TRUE, IS FALSE, IS NOT TRUE, and IS NOT FALSE. These are useful for nullable columns: MergeSourceID = '<uuid>' IS NOT FALSE matches rows where MergeSourceID equals the value OR is NULL. The IN and NOT IN operators accept a comma-separated list of values in parentheses, such as Slug IN ('slugone', 'slugtwo') or Labels.environment IN ('prod', 'staging'). Conjunctions are supported using the AND operator. An example conjunction is: CreatedAt >= '2025-01-07' AND Slug = 'test' AND Labels.mykey = 'myvalue'. Supported attributes for filtering on Attestation: AttestationID, ChangeOrderID, Claims, CreatedAt, EvidenceAttestationIDs, ExpiresAt, HiddenReason, Note, OrganizationID, Permissions, ReleaseID, Result, RevokedAttestationID, SpaceID, Type, UserID. The whole string must be query-encoded. |
|
filter |
string | UUID of a Filter entity to apply to the Attestation list. The Filter must be in the same Organization as the user credentials. The Filter's From field must match the entity type being filtered (Attestation). For Space-resident entities, if the Filter has a FromSpaceID, it must match the operation's SpaceID. The Filter's Where clause will be combined with any explicit 'where' parameter using AND logic. If both 'filter' and 'where' parameters are specified, they are combined with AND logic. | |
contains |
string | Free text search that approximately matches the specified string against string fields and map keys/values. The search is case-insensitive and uses pattern matching to find entities containing the text. Searchable string fields include attributes like Slug, DisplayName, and string-typed custom fields. For map fields (like Labels and Annotations), the search matches both map keys and values. The search uses OR logic across all searchable fields, so matching any field will return the entity. If both 'where' and 'contains' parameters are specified, they are combined with AND logic. Searchable fields for Attestation include string and map-type attributes from the queryable attributes list. The whole string must be query-encoded. | |
include |
string | Include clause for expanding related entities in the response for Attestation. The attribute names are case-sensitive, PascalCase, and expected in a comma-separated list format as in the JSON encoding. Supported attributes for Attestation are OrganizationID, SpaceID. The whole string must be query-encoded. | |
select |
string | Select clause for specifying which fields to include in the response for Attestation. The attribute names are case-sensitive, PascalCase, and expected in a comma-separated list format as in the JSON encoding. If not specified, all fields are returned. Entity and parent IDs (like OrganizationID, SpaceID, AttestationID) and Slug are always returned regardless of the select parameter. Fields used in where and contains filters, and fields named by order_by, are also automatically included. Example: 'DisplayName,CreatedAt,Labels' will return only those fields plus the required ID and Slug fields. The whole string must be query-encoded. | |
include_hidden |
string | Hidden Attestation entities, those with a HiddenReason, are left out of the results, or of what a bulk operation acts on, unless this names their HiddenReason. It is a comma-separated list of HiddenReasons, or * for all of them. A where clause naming the entities, by their Slug or ID with = or IN, or naming HiddenReason at all, also returns hidden entities it selects. ConfigHub/YAML Units, which hold the configuration of entities, are hidden with the HiddenReason BackingUnit. |
Responses
| Status | Description | Content-Type | Schema |
|---|---|---|---|
| 200 | OK | application/json |
Array of ExtendedAttestation |
| 400 | Attestation request is invalid (Bad Request). | application/json |
StandardErrorResponse |
| 401 | Unauthorized access. | application/json |
StandardErrorResponse |
| 403 | Forbidden access. | application/json |
StandardErrorResponse |
| 404 | Attestation not found. | application/json |
StandardErrorResponse |
| 500 | Something went wrong while processing Attestation. | application/json |
StandardErrorResponse |
| default | Unexpected error. | application/json |
StandardErrorResponse |
List ExtendedAttestations
GET /space/{space_id}/attestation
List ExtendedAttestations
Operation ID: ListExtendedAttestations
Parameters
Path Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
space_id |
string | ✓ | Unique identifier for a space_id |
Query Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
where |
string | The specified string is an expression for the purpose of filtering the list of Attestations returned. The expression syntax was inspired by SQL. It supports conjunctions using AND of relational expressions of the form attribute operator attribute_or_literal. The attribute names are case-sensitive and PascalCase, as in the JSON encoding. Strings support the following operators: <, >, <=, >=, =, !=, LIKE, NOT LIKE, ILIKE, ~~, !~~, ~, ~*, !~, !~*, IN, NOT IN. String pattern operators: LIKE and ~~ for pattern matching with % and _ wildcards, ILIKE for case-insensitive pattern matching, NOT LIKE and !~~ for negated pattern matching. String regex operators: ~ for regex matching, ~* for case-insensitive regex, !~ and !~* for regex not matching (case-sensitive and insensitive). Integers support the following operators: <, >, <=, >=, =, !=, IN, NOT IN. UUIDs and boolean attributes support equality and inequality only. UUID and time literals must be quoted as string literals. String literals are quoted with single quotes, such as 'string'. Time literals use the same form as when serialized as JSON, such as: CreatedAt > '2025-02-18T23:16:34'. Integer and boolean literals are also supported for attributes of those types. Arrays support the ? operator to to match any element of the array, as in FromLinkID ? '7c61626f-ddbe-41af-93f6-b69f4ab6d308'. Arrays can perform LEN() to check for length, as in LEN(FromLinkID) > 0. An attribute naming a list of other entities can be filtered on their attributes with a * segment, as in FromLink.*.Slug = 'upgrade-app', which holds when any element satisfies it. Without the * such a reference is an error, since it names no single value to compare. Map support the dot notation to specify a particular map key, as in Labels.tier = 'Backend'. Maps support IS NULL and IS NOT NULL with dot notation to check for key absence or presence, as in Labels.tier IS NULL (key doesn't exist) or Labels.tier IS NOT NULL (key exists). Comparison results can be tested with IS TRUE, IS FALSE, IS NOT TRUE, and IS NOT FALSE. These are useful for nullable columns: MergeSourceID = '<uuid>' IS NOT FALSE matches rows where MergeSourceID equals the value OR is NULL. The IN and NOT IN operators accept a comma-separated list of values in parentheses, such as Slug IN ('slugone', 'slugtwo') or Labels.environment IN ('prod', 'staging'). Conjunctions are supported using the AND operator. An example conjunction is: CreatedAt >= '2025-01-07' AND Slug = 'test' AND Labels.mykey = 'myvalue'. Supported attributes for filtering on Attestation: AttestationID, ChangeOrderID, Claims, CreatedAt, EvidenceAttestationIDs, ExpiresAt, HiddenReason, Note, OrganizationID, Permissions, ReleaseID, Result, RevokedAttestationID, SpaceID, Type, UserID. The whole string must be query-encoded. |
|
filter |
string | UUID of a Filter entity to apply to the Attestation list. The Filter must be in the same Organization as the user credentials. The Filter's From field must match the entity type being filtered (Attestation). For Space-resident entities, if the Filter has a FromSpaceID, it must match the operation's SpaceID. The Filter's Where clause will be combined with any explicit 'where' parameter using AND logic. If both 'filter' and 'where' parameters are specified, they are combined with AND logic. | |
contains |
string | Free text search that approximately matches the specified string against string fields and map keys/values. The search is case-insensitive and uses pattern matching to find entities containing the text. Searchable string fields include attributes like Slug, DisplayName, and string-typed custom fields. For map fields (like Labels and Annotations), the search matches both map keys and values. The search uses OR logic across all searchable fields, so matching any field will return the entity. If both 'where' and 'contains' parameters are specified, they are combined with AND logic. Searchable fields for Attestation include string and map-type attributes from the queryable attributes list. The whole string must be query-encoded. | |
include |
string | Include clause for expanding related entities in the response for Attestation. The attribute names are case-sensitive, PascalCase, and expected in a comma-separated list format as in the JSON encoding. Supported attributes for Attestation are OrganizationID, SpaceID. The whole string must be query-encoded. | |
select |
string | Select clause for specifying which fields to include in the response for Attestation. The attribute names are case-sensitive, PascalCase, and expected in a comma-separated list format as in the JSON encoding. If not specified, all fields are returned. Entity and parent IDs (like OrganizationID, SpaceID, AttestationID) and Slug are always returned regardless of the select parameter. Fields used in where and contains filters, and fields named by order_by, are also automatically included. Example: 'DisplayName,CreatedAt,Labels' will return only those fields plus the required ID and Slug fields. The whole string must be query-encoded. | |
include_hidden |
string | Hidden Attestation entities, those with a HiddenReason, are left out of the results, or of what a bulk operation acts on, unless this names their HiddenReason. It is a comma-separated list of HiddenReasons, or * for all of them. A where clause naming the entities, by their Slug or ID with = or IN, or naming HiddenReason at all, also returns hidden entities it selects. ConfigHub/YAML Units, which hold the configuration of entities, are hidden with the HiddenReason BackingUnit. |
Responses
| Status | Description | Content-Type | Schema |
|---|---|---|---|
| 200 | OK | application/json |
Array of ExtendedAttestation |
| 400 | ExtendedAttestation request is invalid (Bad Request). | application/json |
StandardErrorResponse |
| 401 | Unauthorized access. | application/json |
StandardErrorResponse |
| 403 | Forbidden access. | application/json |
StandardErrorResponse |
| 404 | ExtendedAttestation not found. | application/json |
StandardErrorResponse |
| 500 | Something went wrong while processing ExtendedAttestation. | application/json |
StandardErrorResponse |
| default | Unexpected error. | application/json |
StandardErrorResponse |
Get ExtendedAttestation
GET /space/{space_id}/attestation/{attestation_id}
Get ExtendedAttestation
Operation ID: GetExtendedAttestation
Parameters
Path Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
space_id |
string | ✓ | Unique identifier for a space_id |
attestation_id |
string | ✓ | Unique identifier for a attestation_id |
Query Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
include |
string | Include clause for expanding related entities in the response for Attestation. The attribute names are case-sensitive, PascalCase, and expected in a comma-separated list format as in the JSON encoding. Supported attributes for Attestation are OrganizationID, SpaceID. The whole string must be query-encoded. | |
select |
string | Select clause for specifying which fields to include in the response for Attestation. The attribute names are case-sensitive, PascalCase, and expected in a comma-separated list format as in the JSON encoding. If not specified, all fields are returned. Entity and parent IDs (like OrganizationID, SpaceID, AttestationID) and Slug are always returned regardless of the select parameter. Fields used in where and contains filters, and fields named by order_by, are also automatically included. Example: 'DisplayName,CreatedAt,Labels' will return only those fields plus the required ID and Slug fields. The whole string must be query-encoded. |
Responses
| Status | Description | Content-Type | Schema |
|---|---|---|---|
| 200 | Attestation with additional related entities expanded based on the request's include parameter. | application/json |
ExtendedAttestation |
| 400 | ExtendedAttestation request is invalid (Bad Request). | application/json |
StandardErrorResponse |
| 401 | Unauthorized access. | application/json |
StandardErrorResponse |
| 403 | Forbidden access. | application/json |
StandardErrorResponse |
| 404 | ExtendedAttestation not found. | application/json |
StandardErrorResponse |
| 500 | Something went wrong while processing ExtendedAttestation. | application/json |
StandardErrorResponse |
| default | Unexpected error. | application/json |
StandardErrorResponse |
Record an Attestation
POST /space/{space_id}/attestation
Record an Attestation in the Space, covering one Revision of each Unit WhereUnit selects, named by Revision. Units with no such Revision are reported as skipped. When nothing is covered, nothing is recorded. With RevokedAttestationID, withdraw an earlier Attestation instead; a revocation covers no Revisions of its own. Requires Approve permission on the Space.
Operation ID: CreateAttestation
Parameters
Path Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
space_id |
string | ✓ | Unique identifier for a space_id |
Query Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
dry_run |
boolean | Resolve the Revisions that would be covered and return the same response without writing anything. |
Request Body
Content-Type: application/json
Schema: AttestationCreateRequest
Responses
| Status | Description | Content-Type | Schema |
|---|---|---|---|
| 200 | OK | application/json |
AttestationCreateResponse |
| 400 | Attestation request is invalid (Bad Request). | application/json |
StandardErrorResponse |
| 401 | Unauthorized access. | application/json |
StandardErrorResponse |
| 403 | Forbidden access. | application/json |
StandardErrorResponse |
| 404 | Attestation not found. | application/json |
StandardErrorResponse |
| 409 | Attestation data conflict. Data has changed since last read. | application/json |
StandardErrorResponse |
| 500 | Something went wrong while processing Attestation. | application/json |
StandardErrorResponse |
| default | Unexpected error. | application/json |
StandardErrorResponse |
Schemas
AttestationCreateRequest
Properties
| Property | Type | Required | Description |
|---|---|---|---|
ChangeOrderID |
string (uuid) | ||
Claims |
object | ||
EvidenceAttestationIDs |
Array of UUID |
||
ExpiresAt |
string (date-time) | ||
Note |
string | ||
Permissions |
Permissions |
||
ReleaseID |
string (uuid) | ||
Result |
string | ||
Revision |
string | ||
RevokedAttestationID |
string (uuid) | ||
Type |
string | ||
WhereUnit |
string |
AttestationCreateResponse
Properties
| Property | Type | Required | Description |
|---|---|---|---|
Attestation |
Attestation |
||
SkippedUnits |
Array of AttestationSkippedUnit |
||
Subjects |
Array of AttestationSubject |
ExtendedAttestation
Attestation with additional related entities expanded based on the request's include parameter.
Properties
| Property | Type | Required | Description |
|---|---|---|---|
Attestation |
Attestation |
||
Organization |
Organization |
||
Space |
Space |
StandardErrorResponse
Error response details.
Properties
| Property | Type | Required | Description |
|---|---|---|---|
Code |
string | HTTP status code of the response. | |
Message |
string | Message returned with the response. |