Get what you need to verify an image yourself
Read · GET /v1/tenants/{tenant}/submissions/{submission}/attestation · MCP tool attestation
Returns the signed statement about your build (a DSSE envelope), the digests it covers, the key ID and the public key. With these you can check the signature and the provenance yourself, without having to trust Tarsana. The answer also contains the result of Tarsana's own check, kept apart so that you can compare it with yours.
Roles that can call it: viewer, builder, deployer.
Parameters
| Name | In | Required | Description |
|---|---|---|---|
tenant | path | yes | Your tenant ID |
submission | path | yes | The submission ID that submit returned |
Returns
A JSON object with these keys: submission, tenant, attestation, guarantee, caller_authenticated.
Example request
curl https://api.tarsana.io/v1/tenants/acme/submissions/sha256:cdff062988d4722b2ff052c97ebefb8b571858c493ce47b159df73b1c88809b1/attestation \
-H "X-Tarsana-Access-Token: $ACCESS_TOKEN" \
-H 'X-Tarsana-Tenant: acme'
Example response
{
"submission": "sha256:cdff062988d4722b2ff052c97ebefb8b571858c493ce47b159df73b1c88809b1",
"tenant": "acme",
"attestation": {
"schema": "tarsana.submission-attestation/v1",
"key": {
"keyid": "52f4abfb...",
"public_key": "-----BEGIN PUBLIC KEY-----\n...\n-----END PUBLIC KEY-----\n",
"registered": true,
"claim": "A sentence that says what a signature by this key covers."
},
"signature": {
"algorithm": "ed25519",
"format": "in-toto-dsse",
"keyid": "52f4abfb...",
"envelope": {
"payloadType": "application/vnd.in-toto+json",
"payload": "eyJfdHlwZSI6...",
"signatures": [
{
"algorithm": "ed25519",
"keyid": "52f4abfb...",
"sig": "MEUCIQ..."
}
]
}
},
"subject": {
"image": {
"digest": "sha256:0f1e2d3c...",
"attested": true
},
"release": {
"plain_sha256": "9487214a...",
"plain_size": 2147483648,
"version": "20261005-030112"
},
"sbom": {
"digest": "sha256:fb917071...",
"format": "CycloneDX"
}
},
"verification": {
"verdict": "verified",
"checks": [
{
"id": "signature_verifies",
"result": "pass",
"detail": "A sentence about this check."
}
]
},
"verify_it_yourself": {
"why": "A sentence.",
"steps": []
}
},
"guarantee": "namespaces are separated, callers are not authenticated",
"caller_authenticated": false
}
Errors
| Code | HTTP | What it means |
|---|---|---|
invalid_parameter | 400 | A value in your request does not have the expected format, for example a submission ID that is not a spec hash. Check the value against the field's description and try again. |
no_acting_tenant | 400 | Your request does not say which tenant you are acting for. Send your tenant ID in the X-Tarsana-Tenant header, or with --as on the command line. |
isolation_refused | 403 | This address belongs to a tenant ID you do not have access to. Check the tenant ID in the address and in your request header. |
no_such_submission | 404 | You have no submission with this ID. Check the ID that submit returned. |
no_such_artifact | 404 | This submission does not have that record yet. The response says what state the build is in and what will produce the record. |
audit_unavailable | 503 | Your audit trail could not be written or read. If you made a change, it was carried out but is missing from the trail, so contact Tarsana support. |
unauthenticated | 401 | Your request has no credential, or one that Tarsana does not recognise. Sign in with login, or send a valid access token. |
forbidden | 403 | Your role does not allow this operation. The response names the roles that do; ask for a credential with one of them. |
rate_limited | 429 | You sent too many requests in a short time. Wait for the number of seconds in retry_after_seconds, then try again. |
surface_fault | 500 | Something went wrong on our side. Try again later, and contact Tarsana support if it keeps happening. |