How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Witness

Apache-2.0

Wraps any build command and produces a signed in-toto attestation about what it observed — the materials, the products, and the environment.

in-totoSLSA

Specifications it implements

What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.

StandardRoleWhat that means
in-toto attests
SLSA attests
Using this from an agent
Interfaces
clilibraryci-action
Install
go github.com/in-toto/witness
Invoke
witness run -s <step-name> -o <attestation.json> -- <build-command>
Emits
in-toto-attestation, json
Runtime
Runs offline Non-deterministic Writes Needs credentials

Where it applies

Jobs this tool actually does, and the surface each one is exercised on.

Add provenance to an existing build without restructuring the pipeline.
ci-pipeline

Wrapping the command is what makes this adoptable — the build does not have to change, it just gets observed.

Enforce that a build ran the steps a policy requires, in order.
ci-pipeline
Website
https://witness.dev
Repository
https://github.com/in-toto/witness
License
Apache-2.0 — reported by the GitHub API, verified 2026-08-11
Stars
544 · last commit 2026-08-10
Matching caveat
The name is an ordinary English word, so the job-corpus matcher cannot use it — sampled matches were "you'll witness first-hand", "Factory witness testing (FWT)" The bare name is blocked in the matcher, so this count reflects only qualified matches. Real adoption needs another source.
Reading this as an agent? Don't scrape the page — this entry is published as structured data at /tools.json, against the tool.schema.json schema, using the roles.json vocabulary. Start at /llms.txt.
arrow_back All tools by adoption