openapi: 3.2.0 info: title: Harness Evidence Vault [Beta] API version: '1.0' description: The Harness Software Delivery Platform uses OpenAPI Specification v3.0. contact: name: API Support email: contact@harness.io url: https://harness.io/ x-logo: url: https://mma.prnewswire.com/media/779232/Harnes_logo_horizontal.jpg?p=facebook altText: Harness termsOfService: https://harness.io/terms-of-use/ servers: - url: https://app.harness.io description: Harness host URL - url: https://{vanity} description: Vanity URL variables: vanity: default: app.harness.io security: - x-api-key: [] tags: - name: Evidence Vault [Beta] paths: /gateway/ssca-manager/v2/orgs/{org}/projects/{project}/attestations/upload/{orchestration}: parameters: - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/ProjectParam1' - $ref: '#/components/parameters/OrchestrationId' post: summary: Upload attestation tags: - Evidence Vault [Beta] responses: '201': $ref: '#/components/responses/AttestationUploadResponse' '400': description: Bad request (invalid JSON / missing fields) '401': description: Unauthorized '403': description: Forbidden (insufficient RBAC) '422': description: Unprocessable Entity (signature verification failed) '500': description: Internal Server Error operationId: uploadAttestation x-internal: false x-stoplight: id: attestation-upload parameters: - $ref: '#/components/parameters/AccountHeader6' - name: Idempotency-Key in: header required: false schema: type: string description: Client-provided UUID for safe retries requestBody: $ref: '#/components/requestBodies/AttestationUploadRequestBody' security: - x-api-key: [] /gateway/ssca-manager/v2/orgs/{org}/projects/{project}/attestations/download/{digest}: parameters: - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/ProjectParam1' - $ref: '#/components/parameters/DigestParam' get: summary: Download attestation by digest(gitoidSha256 or payload digest) tags: - Evidence Vault [Beta] responses: '200': $ref: '#/components/responses/AttestationDownloadResponse' '401': description: Unauthorized '404': description: Not found '500': description: Internal Server Error operationId: downloadAttestation x-internal: false x-stoplight: id: attestation-download parameters: - $ref: '#/components/parameters/AccountHeader6' security: - x-api-key: [] /gateway/ssca-manager/v2/orgs/{org}/projects/{project}/attestations/query: parameters: - $ref: '#/components/parameters/OrgParam1' - $ref: '#/components/parameters/ProjectParam1' post: summary: GraphQL query endpoint for attestations tags: - Evidence Vault [Beta] responses: '200': $ref: '#/components/responses/AttestationQueryResponse' '400': description: Bad GraphQL request '401': description: Unauthorized '500': description: Internal Server Error operationId: queryAttestationsGraphQL x-internal: false x-stoplight: id: attestation-query parameters: - $ref: '#/components/parameters/AccountHeader6' requestBody: $ref: '#/components/requestBodies/AttestationQueryRequestBody' security: - x-api-key: [] components: parameters: DigestParam: name: digest in: path required: true schema: type: string description: Attestation digest (gitoidSha256 or payload digest) OrgParam1: name: org in: path required: true schema: type: string description: Harness organization ID OrchestrationId: name: orchestration in: path required: true schema: type: string description: Harness Pipeline Execution ID AccountHeader6: name: Harness-Account in: header required: true schema: type: string description: Identifier field of the account the resource is scoped to. This is required for Authorization methods other than the x-api-key header. If you are using the x-api-key header, this can be skipped. ProjectParam1: in: path required: true schema: type: string description: Harness project ID name: project schemas: ExecutionDetail: type: object required: - type properties: type: $ref: '#/components/schemas/ExecutionType' github: $ref: '#/components/schemas/GithubExecutionDetail' harness: $ref: '#/components/schemas/HarnessExecutionDetail' AttestationUploadResponseBody: title: AttestationUploadResponseBody type: object properties: gitoidSha256: type: string example: 300cd77db87c312b00b2e712d82a7581b20972e6a49e0ed11f4cdd1e2be942a0 description: GitOID SHA256 digest of the attestation status: type: string example: ingested description: Ingestion status verified: type: boolean example: true description: Whether the signature was verified indexed: type: boolean example: false description: Whether the attestation has been indexed artifactId: type: string description: Associated artifact identifier orchestrationId: type: string description: Orchestration identifier for this attestation links: $ref: '#/components/schemas/AttestationLinks' DSSEEnvelope: title: DSSEEnvelope type: object required: - payloadType - payload properties: payloadType: type: string example: application/vnd.in-toto+json description: MIME type of the payload payload: type: string description: base64-encoded JSON payload (in-toto Statement) example: eyJfdHlwZSI6ICJod... signatures: type: array items: $ref: '#/components/schemas/DSSESignature' metadata: type: object additionalProperties: true description: optional metadata such as source / ingestedBy / timestamp GithubExecutionDetail: title: GithubExecutionDetail x-stoplight: id: nfcbibnr1z2rw type: object properties: repository: type: string x-stoplight: id: sac861lasuewn github_action: type: string x-stoplight: id: l8azkn1th708h action_path: type: string x-stoplight: id: twcllxr8bibkc job_id: type: string x-stoplight: id: gxvhjwmosdutz run_id: type: string x-stoplight: id: cunrcn7ohnpy2 workflow_ref: type: string x-stoplight: id: gnclwe27klokp runner_detail: $ref: '#/components/schemas/GithubRunner' description: Github Pipeline Execution Details DSSESignature: title: DSSESignature type: object properties: keyid: type: string example: harness-ci-signer description: Identifier of the signing key sig: type: string example: MEUCIQ... description: Base64-encoded signature HarnessRunner: title: HarnessRunner x-stoplight: id: vfsaqcya7qwfx type: object properties: trigger_type: type: string x-stoplight: id: rzkmd5bqoc9r9 trigger_by_id: type: string x-stoplight: id: b36ytjxzv2yq6 trigger_by_name: type: string x-stoplight: id: a7g4t02vts8gf RepositoryPlatform: type: string title: RepositoryPlatform x-stoplight: id: prybalroyw6dc enum: - HARNESS - GITHUB - BITBUCKET - GITLAB - GIT - AZURE ArtifactVariant: title: ArtifactVariant x-stoplight: id: uyb3jwhgs9wjh type: object properties: type: type: string x-stoplight: id: 2r8lmxejmwqbf enum: - tag - branch - gitTag - commit description: type of the variant of the artifact. value: type: string x-stoplight: id: hd1p3s7bugn88 description: Value of the variant of the artifact. AttestationUploadRequest: title: AttestationUploadRequest type: object required: - envelope - artifact properties: envelope: $ref: '#/components/schemas/DSSEEnvelope' artifact: $ref: '#/components/schemas/Artifact1' executionContext: $ref: '#/components/schemas/ExecutionDetail' ExecutionType: type: string enum: - harness - github GraphQLError: title: GraphQLError type: object properties: message: type: string description: Error message locations: type: array items: type: object properties: line: type: integer column: type: integer path: type: array items: type: string GraphQLRequest: title: GraphQLRequest type: object required: - query properties: query: type: string example: '{ dsses(first:10) { edges { node { gitoidSha256 } } } }' description: GraphQL query string variables: type: object description: GraphQL variables for filtering DSS entries properties: gitoidSha256: type: string description: Exact match on attestation ID gitoidSha256In: type: array items: type: string description: Match any ID in list subjectName: type: string description: Exact match on subject name subjectNameContains: type: string description: Wildcard contains search subjectNameStartsWith: type: string description: Prefix search subjectSha256: type: string description: Exact match on subject digest signerKeyId: type: string description: Exact match on signer key ID signerKeyIdIn: type: array items: type: string description: Match any key ID in list status: type: string description: Filter by status (PENDING, INDEXED, etc.) verified: type: boolean description: Filter by verification status artifactId: type: string description: Filter by artifact ID createdAtGTE: type: integer format: int64 description: Created after timestamp (epoch ms) createdAtLTE: type: integer format: int64 description: Created before timestamp (epoch ms) and: type: array items: type: object description: Logical AND of multiple filter conditions or: type: array items: type: object description: Logical OR of multiple filter conditions not: type: object description: Logical NOT filter condition Artifact1: title: Artifact x-go-name: ArtifactListItem x-stoplight: id: 13qkvpww6x2ku type: object x-examples: {} required: - type - name - registry_url properties: id: type: string description: id of the artifact example: 089855ea-f90e-4bea-a5c9-b5ddf85d3180 type: type: string description: type of the artifact enum: - image - repository default: image example: image name: type: string description: name of the artifact example: harness/image tag: type: string description: tag of the artifact default: latest example: latest registry_url: type: string description: url of the artifact example: https://console.cloud.google.com/gcr/images/imageName url: type: string x-stoplight: id: 2gcc89tfmislv variant: $ref: '#/components/schemas/ArtifactVariant' digest: type: string description: digest of the artifact example: sha256:1234567890 metadata: type: object additionalProperties: true x-stoplight: id: bcmiu856m2sf8 repository_platform: $ref: '#/components/schemas/RepositoryPlatform' AttestationLinks: title: AttestationLinks type: object properties: download: type: string example: /orgs/SSCA/projects/SSCA_Sanity/attestations/300cd77... description: Download URL for this attestation graph: type: string example: /orgs/SSCA/projects/SSCA_Sanity/attestations/graph?artifactId=68f09... description: Graph query URL for related attestations GithubRunner: title: GithubRunner x-stoplight: id: 32axq2gn4gemv type: object properties: name: type: string x-stoplight: id: x0aeloqpvaybd account_id: type: string x-stoplight: id: aod8pc43fmjbt GraphQLResponse: title: GraphQLResponse type: object properties: data: type: object additionalProperties: true description: GraphQL response data errors: type: array items: $ref: '#/components/schemas/GraphQLError' description: GraphQL errors if any HarnessExecutionDetail: title: HarnessExecutionDetail x-stoplight: id: 26kpn09zundb0 type: object properties: org: type: string x-stoplight: id: zf78rh1u21y55 project: type: string x-stoplight: id: lghyhop0hsg0f pipeline_execution_id: type: string x-stoplight: id: svsw1myd4slwa pipeline_id: type: string x-stoplight: id: 6ms1cohmjf8rv pipeline_name: type: string x-stoplight: id: qecka5f2dfvxx sequence_id: type: string x-stoplight: id: tvb3c7trq28pt step_id: type: string x-stoplight: id: bj8ul3cpt9061 step_execution_id: type: string x-stoplight: id: eyon9kxjzpuu5 step_name: type: string x-stoplight: id: li446ik3qfg8l stage_id: type: string x-stoplight: id: uk4e6msb1annk stage_execution_id: type: string x-stoplight: id: ltrcdcpqky4rv stage_name: type: string x-stoplight: id: n27q5wlhtrd65 stage_type: type: string x-stoplight: id: 22ha61i5fiwzc description: Stage type in which the step executed runner_detail: $ref: '#/components/schemas/HarnessRunner' description: Harness Pipeline Execution Details responses: AttestationUploadResponse: description: Attestation upload success response content: application/json: schema: $ref: '#/components/schemas/AttestationUploadResponseBody' AttestationDownloadResponse: description: DSSE envelope download response content: application/json: schema: $ref: '#/components/schemas/DSSEEnvelope' AttestationQueryResponse: description: GraphQL query response content: application/json: schema: $ref: '#/components/schemas/GraphQLResponse' requestBodies: AttestationQueryRequestBody: content: application/json: schema: $ref: '#/components/schemas/GraphQLRequest' AttestationUploadRequestBody: content: application/json: schema: $ref: '#/components/schemas/AttestationUploadRequest' securitySchemes: x-api-key: name: x-api-key type: apiKey in: header description: API key is a token provided while making the API calls. This is used to authenticate the client at the exposed endpoint. externalDocs: description: Find out more about Swagger url: http://swagger.io x-stoplight: id: oc91t4vrfnjyi x-tagGroups: - name: Organizations tags: - Organization - name: Projects tags: - Org Project - Project - name: Secrets tags: - Account Secret - Org Secret - Project Secret - Secrets - name: Connectors tags: - Account Connector - Org Connector - Project Connector - Connectors - GoogleSecretManagerConnector - name: Roles tags: - Account Roles - Organization Roles - Project Roles - Roles - name: Resource Groups tags: - Account Resource Groups - Organization Resource Groups - Project Resource Groups - Filter Resource Groups - Harness Resource Group - Zendesk - name: Role Assignments tags: - Account Role Assignments - Org Role Assignments - Project Role Assignments - Role Assignments - name: Platform tags: - Access Control List - Account Banner - Account Banner - Account Licensed Modules - Account License Type - Account Webhooks - AccountSetting - Accounts - Analyze Account Access Policy - Analyze Organization Access Policy - Analyze Project Access Policy - ApiKey - Audit - AuditFilters - Authentication Settings - Canny - Devops Essentials License Data By Account - EULA - Filter - Harness Resource Type - Invite - IP Allowlist - Nextgen Ldap - Notification Channels - Notification Rules - OIDC - Oidc-Access-Token - Oidc-ID-Token - Org Webhooks - Permissions - Project Webhooks - Secret Managers - Service Account - Setting - SMTP - Source Code Manager - Token - User - User Group - Variables - name: Delegate tags: - Agent mTLS Endpoint Management - Delegate Download Resource - Delegate Group Tags Resource - Delegate Setup Resource - Delegate Token Resource - name: Pipelines tags: - Pipelines - Input Sets - Approvals - Pipeline Execution - Pipeline Dashboard - Pipeline Input Set - Pipeline - Pipeline Execution Details - Pipeline Execute - Pipeline Refresh - Pipeline data retention - Triggers - TriggersEvents - Webhook Triggers - Webhook Event Handler - DryRunPipeline - name: Artifact Registry tags: - Registries - Artifacts - Docker Artifacts - Helm Artifacts - quarantine - Webhooks - Spaces - Replication - Registry V3 - Registries - Registry V3 - Packages - Registry V3 - Versions - Registry V3 - Files - Registry V3 - Metadata - Registry V3 - Firewall - Registry V3 - Transfer - name: Database DevOps tags: - Database Schema - Database Instance - Deployed State - Execution Config - Migration State - name: CD tags: - K8s Release Service Mapping - CustomDeployment - Environments - EnvironmentGroup - Infrastructures - Usage - File Store - Service Dashboard - ServiceOverrides - Rollback - tas - name: Deployment Freeze tags: - Freeze CRUD - Freeze Evaluation - Freeze Schema - name: Services tags: - Account Services - Org Services - Project Services - Services - name: Rancher Infrastructures tags: - Account Rancher Infrastructure - Org Rancher Infrastructure - Project Rancher Infrastructure - name: Templates tags: - Account Template - Org Template - Project Template - Templates - Global Templates - name: GitOps tags: - Agents - Application - Applications - Certificates - Clusters - Dashboard Aggregates - Dashboards - GnuPGP Keys - GPG Keys - Hosts - Project mappings - Projects - Reconciler - Repositories - Repository Certificates - Repository credentials - ValidateHost - name: GitX tags: - GitX Webhooks - Org Gitx Webhooks - Project Gitx Webhooks - name: CACM tags: - Anomalies Ignorelist Rule - Anomalies - BI Dashboards - Budgets - Budget Groups - Cost Categories - Cloud Accounts - K8S Connectors Metadata - Notification Settings v2 - Overview - Data Job Status - Recommendation cost settings - Unit Metric - Anomaly Comments - Cloud and AI cost anomaly details - Cloud and AI cost anomalies v2 - Cost Details - Currency Preferences - External Data Provider - AiEngine - CACM governance cost settings - Governance Enforcement Recommendation APIs - Governance Alert - Governance Overview - Governance Recommendation APIs - RuleEnforcement - Rule Executions - Rule - Rule Sets - Perspectives Folders - Perspective Reports - Perspectives - Cost Category Jira Project Mapping - Recommendations Details - Recommendations - Recommendation Jira - Recommendation Preferences - Recommendation Presets - Recommendation Servicenow - Recommendation Tags - Recommendation Ignore List - AutoStopping Rules - AutoStopping Rules V2 - AutoStopping Load Balancers - AutoStopping Fixed Schedules - AutoStopping Alerts - Commitment Orchestrator Events APIs - name: Feature Flags tags: - API Keys - Feature Flags - Targets - Target Groups - Environment Perspectives - Anomalies - Proxy - Tags - name: SRM tags: - Monitored Services - SLOs dashboard - NG SLOs - SLOs - Downtime - Srm Notification - name: Internal Developer Portal - IDP tags: - Entities - Teams - CatalogCustomProperties - Scores - DataSource - KubernetesDataPoints - AggregationRules - AppConfig - PluginInfo - LayoutProxy - Kinds - LayoutsV3 - LayoutsV4 - name: Environment Management - IDP tags: - Environment - Infrastructure - Instance - name: Custom Dashboards tags: - aida - dashboards - downloads - embed - folders - name: Policy Management tags: - dashboard - examples - policies - evaluate - evaluations - policysets - system - name: Code tags: - repository - status_checks - pullreq - upload - webhook - resource - rules - labels - name: IaCM tags: - usage - approvals - costs - executions - module-registry - workspaces - settings - tf-standard-backend - variables - name: STO tags: - Exemptions - Issues - Scans - Products - Test Targets - Target Variants - name: SEI tags: - Collection categories - Collections - Contributors - DORA - name: Git Sync (deprecated) tags: - Git Branches - Git Full Sync - Git Sync Settings - Git Sync - Git Sync Errors - name: Error Models tags: - Error Response - Governance Metadata - name: Supply Chain Security tags: - integration - PipelineInfraConfig - SBOM - Integration Step Config - Delete Step Config - Delete Repositories - Pipeline Store Config - Evidence Vault [Beta] - name: Release Management tags: - Release Groups - Releases - Orchestration Processes - Orchestration Activities - Orchestration Executions - Conflicts - Freeze - Reports - Uploads - name: Resilience Testing tags: - Actions - Action Templates - Chaos Components - Chaos Hubs - ChaosGuard Conditions - ChaosGuard Rules - DR Tests - Experiments - Experiment Templates - Faults - Fault Templates - Chaos Infrastructure - Health - Network Maps - Onboarding - Probes - Probe Templates - Chaos Recommendations - Risks