---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Create an artifact"
description: "`artifacts.artifacts.create` (POST /v1/{parent}/artifacts): Registers an artifact whose bytes were pushed by digest; verification runs after."
type: reference
product: platform
summary: "Registers an artifact whose bytes were pushed by digest; verification runs after."
updated: 2026-09-28
nav: false
---

> **This method is not served on the public API.** `api.sylphx.com` does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

Registers an artifact whose bytes were pushed by digest; verification runs after.

**Not available yet.** Sylphx Artifacts is declared in the registry but no backend serves it: every call answers `501` with the problem code `UNIMPLEMENTED`.

- **Path** `POST https://api.sylphx.com/v1/orgs/acme/projects/shop/artifacts`
- **Scope** `artifacts:write`
- **Effect** `write` — a successful call changes state.
- **Collection** [artifacts](/docs/api/artifacts)
- **Query** `artifact_id`, `validate_only`

## Request

| Field | Type | What it is |
| --- | --- | --- |
| `parent` | `string` | The project to create in. Required. |
| `artifact` | `Artifact` | The artifact to create; only spec and caller-writable metadata are read. Required. |
| `artifact_id` | `string` | The id of the new artifact, the digest with `-` for `:`; the server derives it from `digest` when empty; the server assigns one when empty. |
| `validate_only` | `bool` | Validate and return the result without writing anything. |

### Artifact

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/artifacts/{artifact}`, where `{artifact}` is the digest with `-` for `:`, for example `sha256-4f1c…`. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `digest` | `string` | The algorithm-qualified digest of the stored bytes, for example `sha256:4f1c…`. Required. |
| `kind` | `ArtifactKind` | What the Artifact is. Required. One of `image`, `sbom`, `provenance`, `signature`, `bundle`. |
| `media_type` | `string` | The media type, for example `application/vnd.oci.image.manifest.v1+json`. Required. |
| `size_bytes` | `int64` | The size of the stored bytes. Required. |
| `subject` | `string` | The Artifact this one describes, for an SBOM, provenance, or signature. |
| `source_digests` | `string[]` | Digests of the sources and inputs that produced it. |
| `retention` | `RetentionClass` | How long the Artifact is kept. One of `standard`, `referenced`. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |

## Response

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/artifacts/{artifact}`, where `{artifact}` is the digest with `-` for `:`, for example `sha256-4f1c…`. |
| `uid` | `string` | `art_<cell><ulid>`. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `digest` | `string` | The algorithm-qualified digest of the stored bytes, for example `sha256:4f1c…`. Required. |
| `kind` | `ArtifactKind` | What the Artifact is. Required. One of `image`, `sbom`, `provenance`, `signature`, `bundle`. |
| `media_type` | `string` | The media type, for example `application/vnd.oci.image.manifest.v1+json`. Required. |
| `size_bytes` | `int64` | The size of the stored bytes. Required. |
| `subject` | `string` | The Artifact this one describes, for an SBOM, provenance, or signature. |
| `source_digests` | `string[]` | Digests of the sources and inputs that produced it. |
| `builder` | `string` | The builder identity (a SPIFFE id) that produced it. Output only. |
| `sbom` | `string` | The newest SBOM whose subject is this Artifact. Output only. |
| `provenance` | `string` | The newest provenance attestation whose subject is this Artifact. Output only. |
| `verification_state` | `VerificationState` | Whether the signature and provenance verified. Evidence, never identity: a failure does not change the digest. Output only. One of `unverified`, `pending`, `verified`, `failed`. |
| `verify_time` | `timestamp` | When verification last ran. Output only. |
| `retention` | `RetentionClass` | How long the Artifact is kept. One of `standard`, `referenced`. |
| `legal_hold` | `bool` | A legal hold is active; Delete fails. Output only. |
| `regions` | `string[]` | The regions the bytes are replicated to. Output only. |
| `reference` | `string` | The OCI reference by digest to pull, for example `registry.sylphx.com/<project>@sha256:4f1c…`. Output only. |

### ResourceMeta

| Field | Type | What it is |
| --- | --- | --- |
| `generation` | `int64` | Increases by one on every change to `spec`. Output only. |
| `etag` | `string` | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as `If-Match` or `etag` to make Update and Delete conditional; a mismatch fails with ABORTED / 409 `ETAG_MISMATCH`. Output only. |
| `create_time` | `timestamp` | When the Resource was created. Output only. |
| `update_time` | `timestamp` | When the Resource last changed. Output only. |
| `delete_time` | `timestamp` | Set while the Resource is being deleted. Output only. |
| `labels` | `map<string, string>` | Caller-writable, indexed labels (AIP-122 label rules). |
| `annotations` | `map<string, string>` | Caller-writable, unindexed annotations. |
| `display_name` | `string` | Caller-writable human-readable name. |
| `creator` | `string` | The principal that created the Resource. Output only. |

## Errors

- [`UNAUTHENTICATED`](/docs/api/errors/UNAUTHENTICATED) — No valid key or token was presented.
- [`PERMISSION_DENIED`](/docs/api/errors/PERMISSION_DENIED) — The key lacks the method's permission.
- [`UNKNOWN_FIELD`](/docs/api/errors/UNKNOWN_FIELD) — The request has a field the schema does not know.
- [`INVALID_FIELD`](/docs/api/errors/INVALID_FIELD) — A field failed validation.
- [`RESOURCE_ALREADY_EXISTS`](/docs/api/errors/RESOURCE_ALREADY_EXISTS) — A Resource with this name exists.
- [`IDEMPOTENCY_KEY_REUSED`](/docs/api/errors/IDEMPOTENCY_KEY_REUSED) — An Idempotency-Key was reused with another body.
- [`IDEMPOTENCY_IN_PROGRESS`](/docs/api/errors/IDEMPOTENCY_IN_PROGRESS) — The first call with this Idempotency-Key is still running.
- [`PLAN_LIMIT_REACHED`](/docs/api/errors/PLAN_LIMIT_REACHED) — The plan's limit is reached.

Every error arrives in the body [Errors](/docs/platform/errors) describes.

## Examples

**cURL**

```curl
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/artifacts" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"digest":"…","kind":"image","media_type":"…","size_bytes":1}'
```

**TypeScript**

```ts
const response = await sylphx.artifacts.artifacts.create({ artifact: { digest: '…', kind: 'image', mediaType: '…', sizeBytes: 1 }, parent: 'orgs/acme/projects/shop' })
```

**Rust**

```rust
let mut req = sylphx::artifacts::CreateArtifactRequest::default();
req.artifact = Some(sylphx::artifacts::Artifact {
    digest: "…".to_string(),
    kind: sylphx::artifacts::ArtifactKind::Image,
    media_type: "…".to_string(),
    size_bytes: 1,
    ..Default::default()
});
req.parent = "orgs/acme/projects/shop".to_string();
let response = sx.artifacts().artifacts().create(req).await?;
```

**CLI**

```bash
sylphx artifacts artifacts create --parent orgs/acme/projects/shop --digest … --kind image --media-type … --size-bytes 1
```

**MCP**

```json
{ "method_id": "artifacts.artifacts.create", "args": {"artifact":{"digest":"…","kind":"image","media_type":"…","size_bytes":1},"parent":"orgs/acme/projects/shop"} }
```
