Archivista
apartment
1 companies hiring
Radar: Initial
Apache-2.0
A storage and graph service for in-toto attestations — makes attestations queryable instead of leaving them scattered across build logs.
in-toto
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| in-toto | stores |
Using this from an agent
- Interfaces
containerhttp-api- Consumes
- in-toto-attestation
- Emits
- json
- Runtime
- Runs offline Non-deterministic Writes Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Ask what is known about an artifact's origin, across every build that touched it.
coding-agentci-pipeline
Attestations are only useful if you can find them later. This is the part most supply-chain rollouts skip and then regret.
- Website
- https://github.com/in-toto/archivista
- Repository
- https://github.com/in-toto/archivista
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-08-11
- Stars
- 116 · last commit 2026-08-08
- Companies hiring
- 1 — distinct companies whose job postings name this tool, Q3-2026. A demand signal, not a deployment count.
Reading this as an agent? Don't scrape the page — this entry is published as
structured data at
arrow_back
All tools by adoption
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.