List signed deployments
const url = 'https://example.com/v1/deployments?limit=25';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url 'https://example.com/v1/deployments?limit=25' \ --header 'Authorization: Bearer <token>'Cursor-paginated. Sort order: activatedAt descending (binding-defined tiebreak on deploymentId). Optional ?imageRefPrefix= narrows to deployments whose imageRef starts with the prefix; ?signerKeyId= narrows to a specific signing key (useful for revocation audits).
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Query Parameters
Section titled “Query Parameters”1..100. Default 25.
Opaque cursor from a prior response. Absent → first page.
Prefix match on Deployment.imageRef.
Filter to deployments signed by this key id.
Responses
Section titled “Responses”Page of deployments.
object
object
Full digest-pinned OCI reference: <host>/<repo>@sha256:<hex>.
Idempotency key. Extracted from imageRef after the @.
Issuer-supplied YYYYMMDD.N — matches what was signed.
Sha256 of the canonicalised /app/index.json inside the image.
Base64 of the raw Ed25519 public key bytes (32 bytes → 44 chars).
Base64 of the raw Ed25519 signature (64 bytes → 88 chars).
Issuer-supplied timestamp inside the signed envelope.
Server-side ledger timestamp — when the register call succeeded.
object
object
object
Absent for guardrails, which have no version.
object
Absent for guardrails, which have no version.
object
Absent for guardrails, which have no version.
object
Absent for guardrails, which have no version.
Examplegenerated
{ "data": [ { "deploymentId": "example", "tenantId": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "imageRef": "example", "imageDigest": "example", "artifactVersion": "example", "indexHash": "example", "signerKeyId": "example", "signerPublicKey": "example", "signature": "example", "publishedAt": "2026-04-15T12:00:00Z", "activatedAt": "2026-04-15T12:00:00Z", "primitives": { "tools": 1, "guardrails": 1, "agents": 1, "flows": 1 }, "contents": { "tools": [ { "id": "example", "version": "example" } ], "guardrails": [ { "id": "example", "version": "example" } ], "agents": [ { "id": "example", "version": "example" } ], "flows": [ { "id": "example", "version": "example" } ] } } ], "nextCursor": "example", "hasMore": true}Missing / malformed / expired / revoked bearer token.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}List failed inside the caller-plugged binding.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}