aid: spire deliveryModel: model: self-hosted license: Apache-2.0 open_source: true commercial: false callable_host: false label: Self-hosted open source ยท you run it yourself confidence: high source: - license - openapi generated: '2026-08-28' method: derived accessModel: pricing: freemium onboarding: unknown trial: false try_now: false public: false label: Freemium confidence: medium source: - plans generated: '2026-07-22' method: derived image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/spire.png name: SPIRE description: SPIRE (SPIFFE Runtime Environment) is the reference implementation of the SPIFFE standard, providing a toolchain for establishing trust between software systems across a wide variety of hosting platforms through automated attestation and workload identity distribution. SPIRE manages a certificate authority, performs node and workload attestation, and issues SVIDs to workloads through the SPIFFE Workload API. url: https://spiffe.io/docs/latest/spire-about/ tags: - Authentication - Cloud-Native - Graduated - Identity - Security - Zero Trust tags_raw: - Authentication - Cloud Native - Graduated - Identity - Security - Zero Trust created: '2025' modified: '2026-05-19' specificationVersion: '0.23' type: Index apis: - aid: spire:spire-workload-api name: SPIRE Workload API description: >- The SPIRE Agent exposes the SPIFFE Workload API as a Unix domain socket, allowing workloads running on the same node to request their X.509-SVIDs and JWT-SVIDs without requiring any credentials. The Workload API also delivers trust bundle updates so that workloads can verify the identity of other workloads. humanURL: https://spiffe.io/docs/latest/spire-about/spire-concepts/ properties: - type: Documentation url: https://spiffe.io/docs/latest/spire-about/spire-concepts/ - type: Reference url: https://github.com/spiffe/spiffe/blob/main/standards/SPIFFE_Workload_API.md - type: AsyncAPI url: asyncapi/spire-workload-asyncapi.yml - type: GitHubRepository url: https://github.com/spiffe/spire - url: graphql/spire-graphql.md type: GraphQL tags: - gRPC - Identity - JWT - Workload - X.509 - aid: spire:spire-server-api name: SPIRE Server API description: >- The SPIRE Server exposes a gRPC API used by administrators and the SPIRE Agent to manage registration entries, node attestation, bundle federation, and server health. It allows creating and managing workload registration entries that define the SPIFFE IDs issued to workloads matching specified selectors, and supports federation with external SPIFFE trust domains. humanURL: https://spiffe.io/docs/latest/deploying/spire_server/ properties: - type: Documentation url: https://spiffe.io/docs/latest/deploying/spire_server/ - type: Reference url: https://github.com/spiffe/spire-api-sdk - type: JSONSchema url: json-schema/spire-registration-schema.json - type: GitHubRepository url: https://github.com/spiffe/spire-api-sdk tags: - Administration - Attestation - gRPC - Registration - Server - aid: spire:spire-discovery-api name: SPIRE Discovery API description: >- OpenID Connect discovery document endpoint that describes the OIDC provider configuration and supported capabilities. humanURL: https://spiffe.io/docs/latest/spire-about/spire-concepts/ tags: - Discovery properties: - type: OpenAPI url: openapi/spire-discovery-api-openapi.yml - type: Documentation url: https://spiffe.io/docs/latest/deploying/spire_agent/ - type: Reference url: https://spiffe.io/docs/latest/deploying/spire_agent/ - type: GitHubRepository url: https://github.com/spiffe/spire - type: JSONStructure url: json-structure/spire-registration-structure.json - type: Documentation url: https://spiffe.io/docs/latest/keyless/oidc-federation-aws/ - type: GitHubRepository url: https://github.com/spiffe/spire/tree/main/support/oidc-discovery-provider - type: JSONStructure url: json-structure/spire-svid-structure.json - aid: spire:spire-health-api name: SPIRE Health API description: >- Liveness and readiness health check endpoints for SPIRE Server and SPIRE Agent components, suitable for use as Kubernetes probes. humanURL: https://spiffe.io/docs/latest/spire-about/spire-concepts/ tags: - Health properties: - type: OpenAPI url: openapi/spire-health-api-openapi.yml - type: Documentation url: https://spiffe.io/docs/latest/deploying/spire_agent/ - type: Reference url: https://spiffe.io/docs/latest/deploying/spire_agent/ - type: GitHubRepository url: https://github.com/spiffe/spire - type: JSONStructure url: json-structure/spire-registration-structure.json - type: Documentation url: https://spiffe.io/docs/latest/keyless/oidc-federation-aws/ - type: GitHubRepository url: https://github.com/spiffe/spire/tree/main/support/oidc-discovery-provider - type: JSONStructure url: json-structure/spire-svid-structure.json - aid: spire:spire-keys-api name: SPIRE Keys API description: >- JSON Web Key Set endpoint that exposes public keys used to verify JWT-SVIDs issued by SPIRE. humanURL: https://spiffe.io/docs/latest/spire-about/spire-concepts/ tags: - Keys properties: - type: OpenAPI url: openapi/spire-keys-api-openapi.yml - type: Documentation url: https://spiffe.io/docs/latest/deploying/spire_agent/ - type: Reference url: https://spiffe.io/docs/latest/deploying/spire_agent/ - type: GitHubRepository url: https://github.com/spiffe/spire - type: JSONStructure url: json-structure/spire-registration-structure.json - type: Documentation url: https://spiffe.io/docs/latest/keyless/oidc-federation-aws/ - type: GitHubRepository url: https://github.com/spiffe/spire/tree/main/support/oidc-discovery-provider - type: JSONStructure url: json-structure/spire-svid-structure.json common: - type: IssueTracker url: https://github.com/spiffe/spire/issues - type: Releases url: https://github.com/spiffe/spire/releases - type: CodeOfConduct url: https://github.com/spiffe/spire/blob/main/CODE-OF-CONDUCT.md - type: ContributionGuide url: https://github.com/spiffe/spire/blob/main/CONTRIBUTING.md - type: License name: Apache-2.0 url: https://github.com/spiffe/spire/blob/main/LICENSE - type: AgenticAccess url: agentic-access/spire-agentic-access.yml - type: DomainSecurity url: security/spire-domain-security.yml - type: Website url: https://spiffe.io/ - type: Documentation url: https://spiffe.io/docs/latest/ - type: GettingStarted url: https://spiffe.io/docs/latest/try/getting-started-k8s/ - type: GitHubOrganization url: https://github.com/spiffe - type: GitHubRepository url: https://github.com/spiffe/spire - type: Community url: https://spiffe.io/community/ - type: Slack url: https://slack.spiffe.io - type: Blog url: https://spiffe.io/blog/ - type: ChangeLog url: https://github.com/spiffe/spire/blob/main/CHANGELOG.md - type: Security url: https://github.com/spiffe/spire/blob/main/SECURITY.md - type: StackOverflow url: https://stackoverflow.com/questions/tagged/spiffe - type: JSONSchema url: json-schema/spire-svid-schema.json - type: JSONSchema url: json-schema/spire-registration-schema.json - type: JSONStructure url: json-structure/spire-svid-structure.json - type: JSONStructure url: json-structure/spire-registration-structure.json - type: JSONLD url: json-ld/spire-context.jsonld - type: SpectralRules url: rules/spire-rules.yml - type: Vocabulary url: vocabulary/spire-vocabulary.yml maintainers: - FN: Kin Lane email: kin@apievangelist.com