in-toto
apartment
2 companies hiring
Radar: Initial
Apache-2.0
The reference implementation of the in-toto framework — records signed attestations about each step of a build, so the finished artifact can be traced to how it was made.
in-toto
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| in-toto | attests |
Using this from an agent
- Interfaces
clilibrary- Install
-
pypi
in-toto - Emits
- in-toto-attestation
- Runtime
- Runs offline Non-deterministic Writes Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Prove a released artifact came from the pipeline it claims to, and not from somewhere else.
ci-pipeline
- Website
- https://in-toto.io
- Repository
- https://github.com/in-toto/in-toto
- License
- Apache-2.0 — read from the repository's LICENSE file, verified 2026-08-11
- Stars
- 1026 · last commit 2026-08-05
- Companies hiring
- 2 — distinct companies whose job postings name this tool, Q3-2026. A demand signal, not a deployment count.
Reading this as an agent? Don't scrape the page — this entry is published as
structured data at
arrow_back
All tools by adoption
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.