{"openapi":"3.1.0","info":{"title":"CRACI API","description":"Find your SBOMs, job network traces and more!","version":"2026-09-11"},"servers":[{"url":"https://api.craci.com"}],"paths":{"/v1experimental1/sbom/oci_manifest":{"get":{"summary":"Get an SBOM for a OCI image manifest or image index.","description":"Multiple jobs can contribute towards one OCI image or index manifest. This endpoint helps to find all involved jobs and the dependencies of those jobs. The SBOM contains metadata listing all involved jobs, their type of involvement (created a manifest, a config blob, or a layer blob), and which dependencies were observed in the job.","operationId":"getOciManifestSbom","parameters":[{"name":"digest","in":"query","description":"Manifest digest, either sha256 or sha512.","required":true,"schema":{"type":"string"},"example":"sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"},{"name":"job_involvement","in":"query","description":"Scope listed jobs by involvement type. Available values: `any` (default), `manifest`, `config-blob`, `layer-blob`. Parameter can be repeated.","required":false,"schema":{"type":"array","items":{"type":"string"}},"style":"form","explode":true}],"responses":{"200":{"description":"CycloneDX 1.7 SBOM with flat job metadata and component job references","content":{"application/vnd.cyclonedx+json; version=1.7":{}}},"400":{"description":"Malformed digest, unknown involvement or query parameter, or repeated digest","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"401":{"description":"Missing or invalid API token","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"404":{"description":"Manifest or index not recorded for your organization","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"409":{"description":"A contributing job has not finished; retry later","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"422":{"description":"Artifact graph exceeds the supported export size","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"503":{"description":"Dependency unavailable or stored evidence could not be read","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}}}}},"/v1preview1/artifact-provenance/gha_cache":{"get":{"summary":"Get GitHub Actions cache provenance","description":"Find which job created a GitHub Actions cache entry, selected either by cache entry identifier or by archive digest within a repository.","operationId":"getGhaCacheProvenance","parameters":[{"name":"cache_id","in":"query","description":"GitHub Actions cache entry identifier. Required unless `digest` and\n`repository` are supplied.","required":false,"schema":{"type":"integer","format":"int64"},"example":1234},{"name":"digest","in":"query","description":"Content digest of the cache archive, `sha256:` followed by 64\nhexadecimal characters. Requires `repository`.","required":false,"schema":{"type":"string"},"example":"sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"},{"name":"repository","in":"query","description":"GitHub repository in OWNER/REPOSITORY form. Requires `digest`.","required":false,"schema":{"type":"string"},"example":"octo-org/octo-repo"}],"responses":{"200":{"description":"Artifact identity and creating jobs","content":{"application/json":{"schema":{"$ref":"#/components/schemas/PreviewArtifactProvenance"}}}},"400":{"description":"Malformed selector","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"401":{"description":"Missing, invalid, expired, or revoked token","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"404":{"description":"Unknown artifact","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"503":{"description":"Internal dependency unavailable or stored artifact invalid","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}}}}},"/v1preview1/artifact-provenance/oci_blob":{"get":{"summary":"Get OCI blob provenance","description":"Find which jobs uploaded an OCI blob. A blob CRACI has only seen referenced by a manifest returns no creating jobs.","operationId":"getOciBlobProvenance","parameters":[{"name":"digest","in":"query","description":"Content digest including its algorithm prefix: `sha256:` followed by 64\nhexadecimal characters, or `sha512:` followed by 128.","required":true,"schema":{"type":"string"},"example":"sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"}],"responses":{"200":{"description":"Artifact identity and creating jobs","content":{"application/json":{"schema":{"$ref":"#/components/schemas/PreviewArtifactProvenance"}}}},"400":{"description":"Malformed selector","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"401":{"description":"Missing, invalid, expired, or revoked token","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"404":{"description":"Unknown artifact","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"503":{"description":"Internal dependency unavailable or stored artifact invalid","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}}}}},"/v1preview1/artifact-provenance/oci_manifest":{"get":{"summary":"Get OCI manifest provenance","description":"Find which jobs created an OCI image manifest or image index, and what it points at. Follow each reference's `ref` to walk the graph.","operationId":"getOciManifestProvenance","parameters":[{"name":"digest","in":"query","description":"Content digest including its algorithm prefix: `sha256:` followed by 64\nhexadecimal characters, or `sha512:` followed by 128.","required":true,"schema":{"type":"string"},"example":"sha256:0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"}],"responses":{"200":{"description":"Artifact identity, creating jobs, and direct references","content":{"application/json":{"schema":{"$ref":"#/components/schemas/PreviewArtifactProvenance"}}}},"400":{"description":"Malformed selector","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"401":{"description":"Missing, invalid, expired, or revoked token","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"404":{"description":"Unknown artifact","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"503":{"description":"Internal dependency unavailable or stored artifact invalid","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}}}}},"/v1preview1/job-logs":{"get":{"summary":"Get job logs","description":"Stream stored GitHub Actions step output as timestamped plain text. Set follow=true to append new lines until the client disconnects.","operationId":"getJobLogs","parameters":[{"name":"provider","in":"query","description":"CI provider. The only supported provider is GitHub (`github`).","required":true,"schema":{"type":"string"},"example":"github"},{"name":"repo","in":"query","description":"GitHub repository in OWNER/REPOSITORY form.","required":true,"schema":{"type":"string"},"example":"octo-org/octo-repo"},{"name":"job_id","in":"query","description":"GitHub job ID.","required":true,"schema":{"type":"string"},"example":"12345678901"},{"name":"tail","in":"query","description":"Return only the last number of stored lines. Omit or use zero for all stored lines.","required":false,"schema":{"type":"integer","format":"int32","maximum":100000,"minimum":0}},{"name":"follow","in":"query","description":"Keep the response open and append new lines until the client disconnects.","required":false,"schema":{"type":"boolean"}}],"responses":{"200":{"description":"RFC 3339 timestamp, tab, and log text on each line","content":{"text/plain; charset=utf-8":{}}},"400":{"description":"Malformed selectors or options","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"401":{"description":"Missing, invalid, expired, or revoked token","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"404":{"description":"Unknown job","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"503":{"description":"Internal dependency unavailable","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}}}}},"/v1preview1/jobs":{"get":{"summary":"List jobs","description":"List the authenticated organization's jobs, newest first. The active status includes pending, provisioning, and running jobs.","operationId":"listJobs","parameters":[{"name":"status","in":"query","description":"Job status group. The only supported value is `active`.","required":true,"schema":{"type":"string"},"example":"active"},{"name":"since","in":"query","description":"Include jobs CRACI recorded at or after this RFC 3339 timestamp. Defaults to seven days before the request.","required":false,"schema":{"type":"string","format":"date-time"},"example":"2026-08-16T12:00:00Z"}],"responses":{"200":{"description":"Matching jobs","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Jobs"}}}},"400":{"description":"Missing or invalid filters","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"401":{"description":"Missing, invalid, expired, or revoked token","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"503":{"description":"Internal dependency unavailable","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}}}}},"/v1preview1/network-trace":{"get":{"summary":"Get a job network trace","description":"Get the job metadata and its observed network accesses by GitHub job identity.","operationId":"getNetworkTrace","parameters":[{"name":"provider","in":"query","description":"CI provider. The only supported provider is GitHub (`github`).","required":true,"schema":{"type":"string"},"example":"github"},{"name":"repo","in":"query","description":"GitHub repository in OWNER/REPOSITORY form.","required":true,"schema":{"type":"string"},"example":"octo-org/octo-repo"},{"name":"job_id","in":"query","description":"GitHub job ID.","required":true,"schema":{"type":"string"},"example":"12345678901"}],"responses":{"200":{"description":"Job metadata and observed network accesses","content":{"application/json":{"schema":{"$ref":"#/components/schemas/NetworkTrace"}}}},"400":{"description":"Malformed selectors","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"401":{"description":"Missing, invalid, expired, or revoked token","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"404":{"description":"Unknown tuple","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"409":{"description":"Job is not terminal","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"503":{"description":"Internal dependency unavailable","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}}}}},"/v1preview1/sbom":{"get":{"summary":"Download a CycloneDX SBOM","description":"Download a CycloneDX SBOM for a job by GitHub job identity.","operationId":"getSbom","parameters":[{"name":"provider","in":"query","description":"CI provider. The only supported provider is GitHub (`github`).","required":true,"schema":{"type":"string"},"example":"github"},{"name":"repo","in":"query","description":"GitHub repository in OWNER/REPOSITORY form.","required":true,"schema":{"type":"string"},"example":"octo-org/octo-repo"},{"name":"job_id","in":"query","description":"GitHub job ID.","required":true,"schema":{"type":"string"},"example":"12345678901"}],"responses":{"200":{"description":"CycloneDX 1.7 SBOM","content":{"application/vnd.cyclonedx+json; version=1.7":{}}},"400":{"description":"Malformed selectors","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"401":{"description":"Missing, invalid, expired, or revoked token","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"404":{"description":"Unknown tuple","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"409":{"description":"Job is not terminal","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"503":{"description":"Internal dependency unavailable","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}}}}},"/v1preview1/usage":{"get":{"summary":"Get compute usage","description":"Get the authenticated organization's total completed-job usage from the billing system for a time range.","operationId":"getUsage","parameters":[{"name":"start","in":"query","description":"Start of the usage period, inclusive, as an RFC 3339 timestamp.","required":true,"schema":{"type":"string","format":"date-time"},"example":"2026-08-01T00:00:00Z"},{"name":"end","in":"query","description":"End of the usage period, exclusive, as an RFC 3339 timestamp.","required":true,"schema":{"type":"string","format":"date-time"},"example":"2026-09-01T00:00:00Z"}],"responses":{"200":{"description":"Compute usage","content":{"application/json":{"schema":{"$ref":"#/components/schemas/Usage"}}}},"400":{"description":"Missing or invalid filters","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"401":{"description":"Missing, invalid, expired, or revoked token","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}},"503":{"description":"Billing service unavailable","content":{"application/problem+json":{"schema":{"$ref":"#/components/schemas/Problem"}}}}}}}},"components":{"schemas":{"DnsNetworkObservation":{"type":"object","title":"DNS network observation","required":["sequence","observedAt","protocol","dns"],"properties":{"dns":{"$ref":"#/components/schemas/DnsObservation","description":"DNS query and response details."},"observedAt":{"type":"string","format":"date-time","description":"Time at which the network access was observed, in RFC 3339 format."},"protocol":{"type":"string","title":"DNS protocol discriminator","enum":["dns"]},"sequence":{"type":"integer","format":"int32","description":"Stable ordering of this observation within the job trace.","minimum":0}}},"DnsObservation":{"type":"object","required":["nameserverIp","record","response"],"properties":{"nameserverIp":{"type":"string","description":"IP address of the DNS resolver."},"record":{"type":"string","description":"DNS record name and type requested by the job."},"response":{"type":"string","description":"Response returned by the DNS resolver."}}},"HashValue":{"type":"object","properties":{"md5":{"type":["string","null"],"description":"MD5 digest of the body."},"sha256":{"type":["string","null"],"description":"SHA-256 digest of the body."},"sha512":{"type":["string","null"],"description":"SHA-512 digest of the body."}}},"HttpNetworkObservation":{"type":"object","title":"HTTP network observation","required":["sequence","observedAt","protocol","http"],"properties":{"http":{"$ref":"#/components/schemas/HttpObservation","description":"HTTP request and response details."},"observedAt":{"type":"string","format":"date-time","description":"Time at which the network access was observed, in RFC 3339 format."},"protocol":{"type":"string","title":"HTTP protocol discriminator","enum":["http"]},"sequence":{"type":"integer","format":"int32","description":"Stable ordering of this observation within the job trace.","minimum":0}}},"HttpObservation":{"type":"object","required":["method","originUrl","ipAddress","statusCode","bodySizeBytes","policyDenied"],"properties":{"bodyHash":{"oneOf":[{"type":"null"},{"$ref":"#/components/schemas/HashValue","description":"Hashes of the response body, when captured."}]},"bodySizeBytes":{"type":"string","description":"Response body size encoded as a decimal string to preserve 64-bit precision."},"denyReason":{"type":["string","null"],"description":"Reason the request was denied, when applicable."},"ipAddress":{"type":"string","description":"Remote IP address used for the request."},"matchedRule":{"type":["string","null"],"description":"Network policy rule that matched the request, when any."},"method":{"type":"string","description":"HTTP request method."},"originUrl":{"type":"string","description":"Original URL requested by the job."},"policyDenied":{"type":"boolean","description":"Whether network policy denied the request."},"statusCode":{"type":"integer","format":"int32","description":"HTTP response status code.","minimum":0}}},"Id":{"type":"string","description":"64-bit identifier encoded as a decimal string to preserve precision.","pattern":"^-?[0-9]+$"},"JobMetadata":{"type":"object","required":["provider","repository","runId","jobId","runAttempt","commitSha","branch","workflow","jobName","status"],"properties":{"branch":{"type":"string","description":"Git branch associated with the workflow run."},"commitSha":{"type":"string","description":"Git commit checked out by the job."},"jobId":{"type":"string","description":"GitHub job identifier encoded as a decimal string to preserve 64-bit precision."},"jobName":{"type":"string","description":"Display name of the GitHub Actions job."},"provider":{"type":"string","description":"CI provider that ran the job. Currently always GitHub (`github`)."},"repository":{"type":"string","description":"GitHub repository in OWNER/REPOSITORY form."},"runAttempt":{"type":"integer","format":"int32","description":"One-based attempt number for the workflow run."},"runId":{"type":"string","description":"GitHub run identifier encoded as a decimal string to preserve 64-bit precision."},"status":{"type":"string","description":"Final status reported for the job."},"workflow":{"type":"string","description":"Name or path of the GitHub Actions workflow."}}},"JobSummary":{"type":"object","required":["provider","repository","runId","jobId","runAttempt","commitSha","branch","workflow","jobName","status","startedAt","url"],"properties":{"branch":{"type":"string"},"commitSha":{"type":"string"},"jobId":{"type":"string"},"jobName":{"type":"string"},"provider":{"type":"string"},"repository":{"type":"string"},"runAttempt":{"type":"integer","format":"int32"},"runId":{"type":"string"},"startedAt":{"type":"string","format":"date-time","description":"Provider start time when available, otherwise when CRACI recorded the job."},"status":{"type":"string"},"url":{"type":"string"},"workflow":{"type":"string"}}},"Jobs":{"type":"object","required":["jobs"],"properties":{"jobs":{"type":"array","items":{"$ref":"#/components/schemas/JobSummary"}}}},"NetworkObservation":{"oneOf":[{"$ref":"#/components/schemas/HttpNetworkObservation"},{"$ref":"#/components/schemas/DnsNetworkObservation"},{"$ref":"#/components/schemas/TcpNetworkObservation"},{"$ref":"#/components/schemas/SshGitNetworkObservation"}],"title":"Network observation","discriminator":{"propertyName":"protocol","mapping":{"dns":"#/components/schemas/DnsNetworkObservation","http":"#/components/schemas/HttpNetworkObservation","ssh_git":"#/components/schemas/SshGitNetworkObservation","tcp":"#/components/schemas/TcpNetworkObservation"}}},"NetworkTrace":{"type":"object","required":["schemaVersion","job","observations"],"properties":{"job":{"$ref":"#/components/schemas/JobMetadata","description":"GitHub job that produced the observations."},"observations":{"type":"array","items":{"$ref":"#/components/schemas/NetworkObservation"},"description":"Network accesses in their original observation order."},"schemaVersion":{"type":"string","description":"Version of the network trace document schema."}}},"PreviewArtifactKind":{"type":"string","title":"Artifact kind","enum":["oci_image_manifest","oci_image_index","oci_unknown_manifest","oci_manifest","oci_blob","gha_cache"]},"PreviewArtifactProvenance":{"type":"object","title":"Artifact provenance","required":["artifact_id","kind","digest","jobs_created_in","refers"],"properties":{"annotations":{"type":"object","description":"Annotations carried by the artifact's own content.","additionalProperties":{"type":"string"},"propertyNames":{"type":"string"}},"artifact_id":{"$ref":"#/components/schemas/Id","description":"CRACI identifier for this artifact."},"artifact_type":{"type":["string","null"],"description":"Artifact type declared by an OCI artifact manifest."},"cache_id":{"oneOf":[{"type":"null"},{"$ref":"#/components/schemas/Id","description":"GitHub Actions cache entry identifier, for cache artifacts."}]},"digest":{"type":"string","description":"Content digest including its algorithm prefix, for example `sha256:…`."},"jobs_created_in":{"type":"array","items":{"$ref":"#/components/schemas/PreviewCreatingJob"},"description":"Every job observed creating this exact content, newest first. A\nreproducible build yields more than one; an artifact CRACI has only seen\nreferenced yields none."},"kind":{"$ref":"#/components/schemas/PreviewArtifactKind","description":"What kind of artifact this is."},"media_type":{"type":["string","null"],"description":"Media type of the artifact's own content, for manifests."},"purl":{"type":"string","description":"Package URL of the artifact, when one is known."},"refers":{"type":"array","items":{"$ref":"#/components/schemas/PreviewReference"},"description":"Artifacts this artifact points at by digest, in manifest order. Follow\neach `ref` to walk the graph."},"subject":{"oneOf":[{"type":"null"},{"$ref":"#/components/schemas/PreviewDescriptor","description":"Manifest this artifact is attached to, for attestations and signatures."}]}}},"PreviewCreatingJob":{"type":"object","title":"Creating job","required":["craci_job_id","provider","accepted_at","metadata"],"properties":{"accepted_at":{"type":"string","description":"Time at which CRACI accepted the publication, in RFC 3339 format."},"craci_job_id":{"$ref":"#/components/schemas/Id","description":"Unique CRACI job ID."},"metadata":{"$ref":"#/components/schemas/PreviewPublicationMetadata","description":"Where this job put the artifact."},"provider":{"$ref":"#/components/schemas/PreviewProviderJobIdentity","description":"The same job as identified by the code-hosting platform."}}},"PreviewDescriptor":{"type":"object","title":"Descriptor","required":["media_type","digest","size_bytes"],"properties":{"digest":{"type":"string","description":"Digest of the described content, including its algorithm prefix."},"media_type":{"type":"string","description":"OCI media type of the described content."},"size_bytes":{"type":"integer","format":"int64","description":"Declared size in bytes.","minimum":0}}},"PreviewGhaCachePublicationMetadata":{"type":"object","title":"GitHub Actions cache publication metadata","required":["kind","cache_key","version","size_bytes"],"properties":{"cache_key":{"type":"string","description":"Cache key supplied by the workflow."},"kind":{"type":"string","title":"GitHub Actions cache publication discriminator","enum":["gha_cache"]},"size_bytes":{"type":"integer","format":"int64","description":"Size of the cache archive in bytes."},"version":{"type":"string","description":"GitHub Actions cache version."}}},"PreviewGithubJobIdentity":{"type":"object","title":"GitHub job identity","required":["kind","repository","job_id"],"properties":{"job_id":{"$ref":"#/components/schemas/Id","description":"GitHub job identifier."},"kind":{"type":"string","title":"GitHub provider discriminator","enum":["github"]},"repository":{"type":"string","description":"GitHub repository in OWNER/REPOSITORY form."}}},"PreviewOciPublicationMetadata":{"type":"object","title":"OCI publication metadata","required":["kind","registry","repository","reference"],"properties":{"kind":{"type":"string","title":"OCI publication discriminator","enum":["oci"]},"reference":{"type":"string","description":"Tag or digest the job pushed under."},"registry":{"type":"string","description":"OCI registry hostname the job pushed to."},"repository":{"type":"string","description":"Repository path within that registry."}}},"PreviewPlatform":{"type":"object","title":"Platform","required":["os","architecture"],"properties":{"architecture":{"type":"string"},"os":{"type":"string"},"os_features":{"type":"array","items":{"type":"string"}},"os_version":{"type":["string","null"]},"variant":{"type":["string","null"]}}},"PreviewProviderJobIdentity":{"oneOf":[{"$ref":"#/components/schemas/PreviewGithubJobIdentity"}],"title":"Provider job identity","discriminator":{"propertyName":"kind","mapping":{"github":"#/components/schemas/PreviewGithubJobIdentity"}}},"PreviewPublicationMetadata":{"oneOf":[{"$ref":"#/components/schemas/PreviewOciPublicationMetadata"},{"$ref":"#/components/schemas/PreviewGhaCachePublicationMetadata"}],"title":"Publication metadata","discriminator":{"propertyName":"kind","mapping":{"gha_cache":"#/components/schemas/PreviewGhaCachePublicationMetadata","oci":"#/components/schemas/PreviewOciPublicationMetadata"}}},"PreviewReference":{"type":"object","title":"Artifact reference","required":["kind","role","digest","media_type","size_bytes","ref"],"properties":{"digest":{"type":"string","description":"Digest of the referenced artifact, including its algorithm prefix."},"kind":{"$ref":"#/components/schemas/PreviewArtifactKind","description":"Kind of the referenced artifact."},"media_type":{"type":"string","description":"Media type the referring manifest declared for this artifact."},"platform":{"oneOf":[{"type":"null"},{"$ref":"#/components/schemas/PreviewPlatform","description":"Platform an image index selects this manifest for."}]},"position":{"type":["integer","null"],"format":"int32","description":"Zero-based position within the ordered list this role belongs to. Absent\nfor a config blob, which the manifest names once and does not order.","minimum":0},"ref":{"type":"string","description":"Path of this API that returns the referenced artifact's provenance."},"role":{"$ref":"#/components/schemas/PreviewReferenceKind","description":"How the referring manifest uses this artifact."},"size_bytes":{"type":"integer","format":"int64","description":"Size the referring manifest declared for this artifact.","minimum":0},"urls":{"type":"array","items":{"type":"string"},"description":"Locations a non-distributable layer may be fetched from."}}},"PreviewReferenceKind":{"type":"string","title":"Reference role","enum":["config","layer","manifest"]},"Problem":{"type":"object","title":"API problem","required":["type","title","status","detail"],"properties":{"detail":{"type":"string","description":"Human-readable explanation specific to this occurrence."},"status":{"type":"integer","format":"int32","description":"HTTP status code returned with the problem.","minimum":0},"title":{"type":"string","description":"Short, human-readable summary of the problem."},"type":{"type":"string","description":"URI identifying the problem type. `about:blank` uses the HTTP status meaning."}}},"SshGitNetworkObservation":{"type":"object","title":"SSH Git network observation","required":["sequence","observedAt","protocol","sshGit"],"properties":{"observedAt":{"type":"string","format":"date-time","description":"Time at which the network access was observed, in RFC 3339 format."},"protocol":{"type":"string","title":"SSH Git protocol discriminator","enum":["ssh_git"]},"sequence":{"type":"integer","format":"int32","description":"Stable ordering of this observation within the job trace.","minimum":0},"sshGit":{"$ref":"#/components/schemas/SshGitObservation","description":"SSH Git command and transfer details."}}},"SshGitObservation":{"type":"object","required":["host","port","user","service","repoPath","originUrl","allowed","bytesToUpstream","bytesFromUpstream","depthForced"],"properties":{"allowed":{"type":"boolean","description":"Whether network policy allowed the command."},"bytesFromUpstream":{"type":"string","description":"Bytes received upstream, encoded as a decimal string."},"bytesToUpstream":{"type":"string","description":"Bytes sent upstream, encoded as a decimal string."},"denyReason":{"type":["string","null"],"description":"Reason the command was denied, when applicable."},"depthForced":{"type":"boolean","description":"Whether CRACI forced a shallow fetch."},"duration":{"type":["string","null"],"description":"Command duration as a human-readable interval, when available."},"exitStatus":{"type":["integer","null"],"format":"int32","description":"Exit status reported by the SSH command, when available."},"host":{"type":"string","description":"SSH server hostname."},"matchedRule":{"type":["string","null"],"description":"Network policy rule that matched the command, when any."},"originUrl":{"type":"string","description":"Original Git remote URL used by the job."},"port":{"type":"integer","format":"int32","description":"SSH server port.","minimum":0},"repoPath":{"type":"string","description":"Repository path sent to the Git server."},"service":{"type":"string","description":"Requested Git service, such as `git-upload-pack`."},"user":{"type":"string","description":"SSH username."}}},"TcpNetworkObservation":{"type":"object","title":"TCP network observation","required":["sequence","observedAt","protocol","tcp"],"properties":{"observedAt":{"type":"string","format":"date-time","description":"Time at which the network access was observed, in RFC 3339 format."},"protocol":{"type":"string","title":"TCP protocol discriminator","enum":["tcp"]},"sequence":{"type":"integer","format":"int32","description":"Stable ordering of this observation within the job trace.","minimum":0},"tcp":{"$ref":"#/components/schemas/TcpObservation","description":"TCP connection details."}}},"TcpObservation":{"type":"object","required":["remoteIp","resolvedHosts","port","bytesToRemote","bytesFromRemote","allowed","tlsAlpn"],"properties":{"allowed":{"type":"boolean","description":"Whether network policy allowed the connection."},"bytesFromRemote":{"type":"string","description":"Bytes received from the remote endpoint, encoded as a decimal string."},"bytesToRemote":{"type":"string","description":"Bytes sent to the remote endpoint, encoded as a decimal string."},"denyReason":{"type":["string","null"],"description":"Reason the connection was denied, when applicable."},"duration":{"type":["string","null"],"description":"Connection duration as a human-readable interval, when available."},"error":{"type":["string","null"],"description":"Connection error, when the connection failed."},"matchedRule":{"type":["string","null"],"description":"Network policy rule that matched the connection, when any."},"port":{"type":"integer","format":"int32","description":"Remote TCP port.","minimum":0},"remoteIp":{"type":"string","description":"Remote IP address of the connection."},"resolvedHosts":{"type":"array","items":{"type":"string"},"description":"Hostnames that resolved to the remote IP address."},"tlsAlpn":{"type":"array","items":{"type":"string"},"description":"Application protocols offered during the TLS handshake."},"tlsServerName":{"type":["string","null"],"description":"Server name sent during the TLS handshake, when present."}}},"Usage":{"type":"object","required":["start","end","total"],"properties":{"end":{"type":"string","format":"date-time","description":"Exclusive end of the reported period."},"start":{"type":"string","format":"date-time","description":"Inclusive start of the reported period."},"total":{"$ref":"#/components/schemas/UsageTotal"}}},"UsageTotal":{"type":"object","required":["vcpuSeconds"],"properties":{"vcpuSeconds":{"type":"integer","format":"int64","description":"Billed compute usage before conversion to vCPU-minutes."}}}},"securitySchemes":{"bearerAuth":{"type":"http","scheme":"bearer","bearerFormat":"opaque","description":"Use a CRACI API token in the `Authorization: Bearer <token>` header. Organization administrators can create and revoke tokens in **Settings → API tokens**. [Learn how to manage API tokens](https://docs.craci.com/api/authentication/)."}}},"security":[{"bearerAuth":[]}]}