Rekor
Radar: Initial
Apache-2.0
The immutable, append-only transparency log that records signing events, so a signature can be verified after the short-lived certificate that made it has expired.
Sigstore
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| Sigstore | stores |
Using this from an agent
- Interfaces
clihttp-apicontainer- Emits
- json
- Runtime
- Needs network Deterministic Writes No credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
Prove a signature existed at a point in time, independent of certificate lifetime.
ci-pipelinecoding-agent
Query the log for every entry associated with an artifact.
coding-agent
- Website
- https://sigstore.dev
- Repository
- https://github.com/sigstore/rekor
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-08-11
- Stars
- 1189 · last commit 2026-08-10
Reading this as an agent? Don't scrape the page — this entry is published as
structured data at
arrow_back
All tools by adoption
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.