specification: API Commons Plans specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/Plans provider: Cosign providerId: cosign created: '2026-05-04' modified: '2026-09-07' generated: '2026-09-07' method: searched source: >- https://www.sigstore.dev/ ; https://docs.sigstore.dev/cosign/system_config/public_deployment/ ; https://github.com/sigstore/cosign/blob/main/LICENSE (probed 2026-09-07) description: >- Cosign publishes no plans and no pricing, and this is not an omission — it is an Apache-2.0 open source project of the OpenSSF, and the Sigstore public-good instance it talks to is free to use for everyone with no account, no key and no billing relationship. There is no signup, no paid tier and no enterprise "contact us" form. This file replaces a 2026-05-04 bulk-sweep scaffold that invented a "Free" tier with an "API Requests" quota; no such tier or quota exists. plan_count: 0 plans: [] pricing_model: free-open-source license: Apache-2.0 license_url: https://github.com/sigstore/cosign/blob/main/LICENSE pricing_page: published: false note: >- sigstore.dev has no /pricing page. No Pricing pointer is emitted, because there is nothing to point at. cost_to_operate: note: >- The cost that does exist is operational, and it falls on whoever runs the infrastructure. Users who cannot rely on the public-good instance are directed to run their own Fulcio, Rekor and TUF root — see https://docs.sigstore.dev/cosign/system_config/custom_components/. Commercial hosted Sigstore offerings exist from third parties; none is a Cosign product.