specification: API Commons Rate Limits specificationVersion: '0.1' schema: https://raw.githubusercontent.com/api-evangelist/interface-research/main/schema/api-commons.yml#/$defs/RateLimits provider: Cosign providerId: cosign created: '2026-05-04' modified: '2026-09-07' generated: '2026-09-07' method: probed source: >- https://docs.sigstore.dev/logging/overview/ ; https://docs.sigstore.dev/cosign/system_config/public_deployment/ ; live header probes of rekor.sigstore.dev and fulcio.sigstore.dev on 2026-09-07 description: >- Cosign itself is a local binary and has no rate limit. The question that matters is what the Sigstore public-good services it calls will accept, and the honest answer is that no request-rate limit is published and no rate-limit headers are returned. What IS published is an availability SLO and a payload size limit. This file replaces a 2026-05-04 bulk-sweep scaffold that carried invented limits. limit_count: 0 limits: [] headers: observed: [] note: >- Probed 2026-09-07. GET https://rekor.sigstore.dev/api/v1/log returned HTTP 200 with only cache-control and x-accel-expires beyond the standard set — no RateLimit-*, no X-RateLimit-*, no Retry-After. GET https://fulcio.sigstore.dev/api/v2/configuration returned HTTP 200 with no rate-limit headers either. An agent gets no runtime budget signal from these services. exhaustion_status: unknown published_limits: request_rate: published: false note: >- No per-second, per-minute or per-day request limit is documented for the public Rekor or Fulcio instances. Whether and how to rate limit the Rekor read path is still an open question in the project itself (sigstore/rekor-tiles issue #355). payload_size: value: 100 unit: KB scope: Attestation upload to the public Rekor instance note: >- Uploads larger than the documented 100KB attestation limit require running your own Rekor instance. This is a size limit, not a rate limit, and is recorded here because it is the only published quantitative constraint on the public instance. availability_slo: value: 99.5% scope: Rekor public instance source: https://docs.sigstore.dev/logging/overview/ note: >- "The public instance offers an SLO of 99.5% availability and is monitored by an oncall team." The staging environment at sigstage.dev carries no SLO. fair_use: note: >- The public-good instance is a free, donated service. Sigstore directs high-volume and size-constrained users to run their own Fulcio, Rekor and TUF root rather than leaning on the shared deployment.