---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Artifacts"
description: "The `artifacts` collection of Sylphx Artifacts: An Artifact is one immutable content object addressed by digest: an image, or evidence about one (an SBOM, a provenance attestation, a signature) that names it as its subject."
type: reference
product: platform
summary: "An Artifact is one immutable content object addressed by digest: an image, or evidence about one (an SBOM, a provenance attestation, a…"
updated: 2026-09-28
order: 900
---

> **This method is not served on the public API.** `api.sylphx.com` does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

An Artifact is one immutable content object addressed by digest: an image, or evidence about one (an SBOM, a provenance attestation, a signature) that names it as its subject.

**Service** Sylphx Artifacts · **Resource type** `artifacts.sylphx.com/Artifact` · **Name pattern** `orgs/{org}/projects/{project}/artifacts/{artifact}` · **Shape** `record`

**Not available yet.** Sylphx Artifacts is declared in the registry but no backend serves it: every call answers `501` with the problem code `UNIMPLEMENTED`.

## Fields

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/artifacts/{artifact}`, where `{artifact}` is the digest with `-` for `:`, for example `sha256-4f1c…`. |
| `uid` | `string` | `art_<cell><ulid>`. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `digest` | `string` | The algorithm-qualified digest of the stored bytes, for example `sha256:4f1c…`. Required. |
| `kind` | `ArtifactKind` | What the Artifact is. Required. One of `image`, `sbom`, `provenance`, `signature`, `bundle`. |
| `media_type` | `string` | The media type, for example `application/vnd.oci.image.manifest.v1+json`. Required. |
| `size_bytes` | `int64` | The size of the stored bytes. Required. |
| `subject` | `string` | The Artifact this one describes, for an SBOM, provenance, or signature. |
| `source_digests` | `string[]` | Digests of the sources and inputs that produced it. |
| `builder` | `string` | The builder identity (a SPIFFE id) that produced it. Output only. |
| `sbom` | `string` | The newest SBOM whose subject is this Artifact. Output only. |
| `provenance` | `string` | The newest provenance attestation whose subject is this Artifact. Output only. |
| `verification_state` | `VerificationState` | Whether the signature and provenance verified. Evidence, never identity: a failure does not change the digest. Output only. One of `unverified`, `pending`, `verified`, `failed`. |
| `verify_time` | `timestamp` | When verification last ran. Output only. |
| `retention` | `RetentionClass` | How long the Artifact is kept. One of `standard`, `referenced`. |
| `legal_hold` | `bool` | A legal hold is active; Delete fails. Output only. |
| `regions` | `string[]` | The regions the bytes are replicated to. Output only. |
| `reference` | `string` | The OCI reference by digest to pull, for example `registry.sylphx.com/<project>@sha256:4f1c…`. Output only. |

## Methods

Every method of the collection, in the registry's order, with the scope it
needs. The full request, response and examples are one link away.

| Method | Call | What it does |
| --- | --- | --- |
| `GET` | [`get`](/docs/api/artifacts#get) | Gets an artifact. |
| `GET` | [`list`](/docs/api/artifacts#list) | Lists a project's artifacts; filter by `digest`, `kind`, or `subject`. |
| `POST` | [`create`](/docs/api/artifacts#create) | Registers an artifact whose bytes were pushed by digest; verification runs after. |
| `DELETE` | [`delete`](/docs/api/artifacts#delete) | Deletes an artifact; fails while a Release references it or a legal hold is active. |

## get

Gets an artifact.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/artifacts/artifact` · scope `artifacts:read` · effect `read` · not available yet · [Request, response and examples](/docs/api/artifacts/get)

## list

Lists a project's artifacts; filter by `digest`, `kind`, or `subject`.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/artifacts` · scope `artifacts:read` · effect `read` · not available yet · paginated · [Request, response and examples](/docs/api/artifacts/list)

## create

Registers an artifact whose bytes were pushed by digest; verification runs after.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/artifacts` · scope `artifacts:write` · effect `write` · not available yet · [Request, response and examples](/docs/api/artifacts/create)

## delete

Deletes an artifact; fails while a Release references it or a legal hold is active.

`DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/artifacts/artifact` · scope `artifacts:write` · effect `destructive` · not available yet · [Request, response and examples](/docs/api/artifacts/delete)
