Fetch a signed deployment record
const url = 'https://example.com/v1/deployments/example';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/v1/deployments/example \ --header 'Authorization: Bearer <token>'Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”Deployment id assigned by the ledger at register time.
Responses
Section titled “Responses”Deployment record.
object
Full digest-pinned OCI reference: <host>/<repo>@sha256:<hex>.
Idempotency key. Extracted from imageRef after the @.
Issuer-supplied YYYYMMDD.N — matches what was signed.
Sha256 of the canonicalised /app/index.json inside the image.
Base64 of the raw Ed25519 public key bytes (32 bytes → 44 chars).
Base64 of the raw Ed25519 signature (64 bytes → 88 chars).
Issuer-supplied timestamp inside the signed envelope.
Server-side ledger timestamp — when the register call succeeded.
object
object
object
Absent for guardrails, which have no version.
object
Absent for guardrails, which have no version.
object
Absent for guardrails, which have no version.
object
Absent for guardrails, which have no version.
Examplegenerated
{ "deploymentId": "example", "tenantId": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "imageRef": "example", "imageDigest": "example", "artifactVersion": "example", "indexHash": "example", "signerKeyId": "example", "signerPublicKey": "example", "signature": "example", "publishedAt": "2026-04-15T12:00:00Z", "activatedAt": "2026-04-15T12:00:00Z", "primitives": { "tools": 1, "guardrails": 1, "agents": 1, "flows": 1 }, "contents": { "tools": [ { "id": "example", "version": "example" } ], "guardrails": [ { "id": "example", "version": "example" } ], "agents": [ { "id": "example", "version": "example" } ], "flows": [ { "id": "example", "version": "example" } ] }}Missing / malformed / expired / revoked bearer token.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}No deployment with that id under this tenant.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}