How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Notation

Apache-2.0

Signs and verifies OCI artifacts against a trust policy, storing signatures in the registry alongside what they sign.

Notary Project

Specifications it implements

What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.

StandardRoleWhat that means
Notary Project signs
also verifies
Using this from an agent
Interfaces
clilibrary
Install
brew notation
Invoke
notation verify <registry>/<image>:<tag>
Consumes
oci-image
Emits
json, text
Runtime
Needs network Deterministic Writes Needs credentials

Where it applies

Jobs this tool actually does, and the surface each one is exercised on.

Verify an image is signed by a trusted identity before deploying it.
ci-pipelinecoding-agent
Sign artifacts with keys from an existing enterprise PKI rather than a new trust root.
ci-pipeline

The practical difference from Sigstore — Notation fits organisations that already have a CA and intend to keep using it.

Website
https://notaryproject.dev
Repository
https://github.com/notaryproject/notation
License
Apache-2.0 — reported by the GitHub API, verified 2026-08-11
Stars
493 · last commit 2026-08-03
Matching caveat
The name is an ordinary English word, so the job-corpus matcher cannot use it — sampled matches were "JavaScript Object Notation (JSON)", "Big O notation" The bare name is blocked in the matcher, so this count reflects only qualified matches. Real adoption needs another source.
Reading this as an agent? Don't scrape the page — this entry is published as structured data at /tools.json, against the tool.schema.json schema, using the roles.json vocabulary. Start at /llms.txt.
arrow_back All tools by adoption