> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentvolumes.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a trust attachment upload intent for an unscoped release



## OpenAPI

````yaml /spec/0.1.0-rc.1/api-reference/bibliotheca.openapi.json post /api/v1/volumes/{name}/{version}/trust/uploads
openapi: 3.1.1
info:
  title: Agent Volumes Bibliotheca API
  version: 0.1.0-rc.1
servers: []
security: []
paths:
  /api/v1/volumes/{name}/{version}/trust/uploads:
    post:
      summary: Create a trust attachment upload intent for an unscoped release
      operationId: createVolumeTrustUploadIntent
      parameters:
        - in: path
          name: name
          required: true
          schema:
            $ref: '#/components/schemas/NameSegment'
        - in: path
          name: version
          required: true
          schema:
            $ref: '#/components/schemas/SemVer'
        - in: header
          name: Idempotency-Key
          required: false
          description: >-
            Preferred portable idempotency key. If this header and a body
            idempotencyKey are both present, they MUST match exactly.
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/TrustUploadIntentRequest'
      responses:
        '201':
          description: >-
            Upload intent created. Upload instructions are opaque implementation
            data.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/trust-upload-intent.schema'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
        '413':
          $ref: '#/components/responses/PayloadTooLarge'
        '415':
          $ref: '#/components/responses/UnsupportedMediaType'
        '429':
          $ref: '#/components/responses/TooManyRequests'
      security:
        - bearerAuth: []
components:
  schemas:
    NameSegment:
      type: string
      maxLength: 128
      pattern: ^(?!.*--)[a-z0-9](?:[a-z0-9-]*[a-z0-9])?$
    SemVer:
      type: string
      pattern: >-
        ^(0|[1-9]\d*)\.(0|[1-9]\d*)\.(0|[1-9]\d*)(?:-((?:0|[1-9]\d*|\d*[A-Za-z-][0-9A-Za-z-]*)(?:\.(?:0|[1-9]\d*|\d*[A-Za-z-][0-9A-Za-z-]*))*))?(?:\+([0-9A-Za-z-]+(?:\.[0-9A-Za-z-]+)*))?$
    TrustUploadIntentRequest:
      type: object
      additionalProperties: false
      required:
        - subject
        - attachment
        - declaredDigest
      properties:
        subject:
          type: object
          additionalProperties: false
          required:
            - purl
            - integrity
          properties:
            purl:
              $ref: '#/components/schemas/ReleasePurl'
            integrity:
              $ref: '#/components/schemas/Digest'
        attachment:
          type: object
          additionalProperties: false
          required:
            - category
            - format
          properties:
            category:
              type: string
              enum:
                - bom
                - provenance
                - signature
                - other
            format:
              type: object
              additionalProperties: false
              required:
                - family
                - mediaType
              properties:
                family:
                  type: string
                mediaType:
                  type: string
                predicateType:
                  type: string
                  format: uri
                profile:
                  type: string
                version:
                  type: string
        declaredDigest:
          $ref: '#/components/schemas/Digest'
        declaredSize:
          type: integer
          minimum: 0
    trust-upload-intent.schema:
      $schema: https://json-schema.org/draft/2020-12/schema
      $id: >-
        https://agentvolumes.org/spec/0.1.0-rc.1/schemas/trust-upload-intent.schema.json
      title: Agent Volumes Trust Upload Intent
      type: object
      additionalProperties: false
      required:
        - uploadId
        - subject
        - attachment
        - declaredDigest
        - upload
        - expiresAt
        - state
      properties:
        uploadId:
          type: string
          minLength: 1
        subject:
          $ref: '#/components/schemas/releaseSubject'
        attachment:
          $ref: '#/components/schemas/attachmentMetadata'
        declaredDigest:
          type: string
          pattern: ^sha256:[a-f0-9]{64}$
        declaredSize:
          type: integer
          minimum: 0
        upload:
          type: object
          additionalProperties: true
          required:
            - instructionType
          properties:
            instructionType:
              type: string
              description: >-
                Upload profile identifier. The v0.1 portable baseline profile is
                http-put.
            url:
              type: string
              format: uri-reference
            method:
              type: string
              description: HTTP method for http-put; omitted or PUT means PUT.
            headers:
              type: object
              additionalProperties:
                type: string
        expiresAt:
          type: string
          format: date-time
        state:
          type: string
          enum:
            - pending-upload
            - uploading
            - uploaded
            - expired
            - failed
        idempotencyKey:
          type: string
      $defs:
        releaseSubject:
          type: object
          additionalProperties: false
          required:
            - purl
            - integrity
          properties:
            purl:
              type: string
              pattern: >-
                ^pkg:volume/(?:%40(?![a-z0-9-]*--)[a-z0-9](?:[a-z0-9-]{0,62}[a-z0-9])?/)?(?![a-z0-9-]*--)[a-z0-9](?:[a-z0-9-]{0,126}[a-z0-9])?@(0|[1-9]\d*)\.(0|[1-9]\d*)\.(0|[1-9]\d*)(?:-((?:0|[1-9]\d*|\d*[A-Za-z-][0-9A-Za-z-]*)(?:\.(?:0|[1-9]\d*|\d*[A-Za-z-][0-9A-Za-z-]*))*))?(?:\+([0-9A-Za-z-]+(?:\.[0-9A-Za-z-]+)*))?$
            integrity:
              type: string
              pattern: ^sha256:[a-f0-9]{64}$
        attachmentMetadata:
          type: object
          additionalProperties: false
          required:
            - category
            - format
          properties:
            category:
              type: string
              enum:
                - bom
                - provenance
                - signature
                - other
            format:
              type: object
              description: >-
                Trust artifact format identity. Baseline examples include
                CycloneDX JSON BOMs, SLSA provenance predicates, and Sigstore
                bundle signatures.
              additionalProperties: false
              required:
                - family
                - mediaType
              properties:
                family:
                  type: string
                  description: >-
                    Format family such as cyclonedx, slsa-provenance, or
                    sigstore-bundle.
                mediaType:
                  type: string
                predicateType:
                  type: string
                  format: uri
                  description: >-
                    Predicate URI for in-toto/SLSA-style artifacts when
                    applicable.
                profile:
                  type: string
                  description: >-
                    Optional profile identifier for a more specific artifact
                    convention.
                version:
                  type: string
    ReleasePurl:
      type: string
      pattern: >-
        ^pkg:volume/(?:%40(?![a-z0-9-]*--)[a-z0-9](?:[a-z0-9-]{0,62}[a-z0-9])?/)?(?![a-z0-9-]*--)[a-z0-9](?:[a-z0-9-]{0,126}[a-z0-9])?@(0|[1-9]\d*)\.(0|[1-9]\d*)\.(0|[1-9]\d*)(?:-((?:0|[1-9]\d*|\d*[A-Za-z-][0-9A-Za-z-]*)(?:\.(?:0|[1-9]\d*|\d*[A-Za-z-][0-9A-Za-z-]*))*))?(?:\+([0-9A-Za-z-]+(?:\.[0-9A-Za-z-]+)*))?$
    Digest:
      type: string
      pattern: ^sha256:[a-f0-9]{64}$
    releaseSubject:
      type: object
      additionalProperties: false
      required:
        - purl
        - integrity
      properties:
        purl:
          type: string
          pattern: >-
            ^pkg:volume/(?:%40(?![a-z0-9-]*--)[a-z0-9](?:[a-z0-9-]{0,62}[a-z0-9])?/)?(?![a-z0-9-]*--)[a-z0-9](?:[a-z0-9-]{0,126}[a-z0-9])?@(0|[1-9]\d*)\.(0|[1-9]\d*)\.(0|[1-9]\d*)(?:-((?:0|[1-9]\d*|\d*[A-Za-z-][0-9A-Za-z-]*)(?:\.(?:0|[1-9]\d*|\d*[A-Za-z-][0-9A-Za-z-]*))*))?(?:\+([0-9A-Za-z-]+(?:\.[0-9A-Za-z-]+)*))?$
        integrity:
          type: string
          pattern: ^sha256:[a-f0-9]{64}$
    attachmentMetadata:
      type: object
      additionalProperties: false
      required:
        - category
        - format
      properties:
        category:
          type: string
          enum:
            - bom
            - provenance
            - signature
            - other
        format:
          type: object
          description: >-
            Trust artifact format identity. Baseline examples include CycloneDX
            JSON BOMs, SLSA provenance predicates, and Sigstore bundle
            signatures.
          additionalProperties: false
          required:
            - family
            - mediaType
          properties:
            family:
              type: string
              description: >-
                Format family such as cyclonedx, slsa-provenance, or
                sigstore-bundle.
            mediaType:
              type: string
            predicateType:
              type: string
              format: uri
              description: Predicate URI for in-toto/SLSA-style artifacts when applicable.
            profile:
              type: string
              description: >-
                Optional profile identifier for a more specific artifact
                convention.
            version:
              type: string
    ProblemDetails:
      oneOf:
        - $ref: '#/components/schemas/AuthenticationRequiredProblem'
        - $ref: '#/components/schemas/AuthorizationFailedProblem'
        - $ref: '#/components/schemas/NotFoundProblem'
        - $ref: '#/components/schemas/ValidationFailedProblem'
        - $ref: '#/components/schemas/InvalidManifestProblem'
        - $ref: '#/components/schemas/InvalidArchiveProblem'
        - $ref: '#/components/schemas/IdentityMismatchProblem'
        - $ref: '#/components/schemas/VersionConflictProblem'
        - $ref: '#/components/schemas/DigestMismatchProblem'
        - $ref: '#/components/schemas/SubjectBindingMismatchProblem'
        - $ref: '#/components/schemas/InconsistentRegistryStateProblem'
        - $ref: '#/components/schemas/UploadExpiredProblem'
        - $ref: '#/components/schemas/MissingUploadedBytesProblem'
        - $ref: '#/components/schemas/InvalidUploadStateProblem'
        - $ref: '#/components/schemas/IdempotencyConflictProblem'
        - $ref: '#/components/schemas/PayloadTooLargeProblem'
        - $ref: '#/components/schemas/UnsupportedMediaTypeProblem'
        - $ref: '#/components/schemas/PermissionEscalationProblem'
        - $ref: '#/components/schemas/RateLimitedProblem'
    AuthenticationRequiredProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/authentication-required
            status:
              const: 401
    AuthorizationFailedProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/authorization-failed
            status:
              const: 403
    NotFoundProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/not-found
            status:
              const: 404
    ValidationFailedProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/validation-failed
            status:
              const: 400
    InvalidManifestProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/invalid-manifest
            status:
              const: 400
    InvalidArchiveProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/invalid-archive
            status:
              const: 400
    IdentityMismatchProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/identity-mismatch
            status:
              const: 409
    VersionConflictProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/version-conflict
            status:
              const: 409
    DigestMismatchProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/digest-mismatch
            status:
              const: 400
    SubjectBindingMismatchProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/subject-binding-mismatch
            status:
              const: 400
    InconsistentRegistryStateProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/inconsistent-registry-state
            status:
              const: 409
    UploadExpiredProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/upload-expired
            status:
              const: 410
    MissingUploadedBytesProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/missing-uploaded-bytes
            status:
              const: 400
    InvalidUploadStateProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/invalid-upload-state
            status:
              const: 409
    IdempotencyConflictProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/idempotency-conflict
            status:
              const: 409
    PayloadTooLargeProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/payload-too-large
            status:
              const: 413
    UnsupportedMediaTypeProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/unsupported-media-type
            status:
              const: 415
    PermissionEscalationProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/permission-escalation
            status:
              const: 400
    RateLimitedProblem:
      allOf:
        - $ref: '#/components/schemas/ProblemDetailsBase'
        - type: object
          properties:
            type:
              const: https://agentvolumes.org/problems/rate-limited
            status:
              const: 429
    ProblemDetailsBase:
      type: object
      additionalProperties: true
      required:
        - type
        - title
        - status
      properties:
        type:
          type: string
        title:
          type: string
          minLength: 1
        status:
          type: integer
          minimum: 100
          maximum: 599
        detail:
          type: string
        instance:
          type: string
          format: uri-reference
  responses:
    BadRequest:
      description: Bad request
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
          examples:
            validationFailed:
              summary: Request or metadata validation failed
              value:
                type: https://agentvolumes.org/problems/validation-failed
                title: Validation failed
                status: 400
            invalidManifest:
              summary: Submitted volume.toml is invalid
              value:
                type: https://agentvolumes.org/problems/invalid-manifest
                title: Invalid manifest
                status: 400
            invalidArchive:
              summary: Submitted archive violates the transport profile
              value:
                type: https://agentvolumes.org/problems/invalid-archive
                title: Invalid archive
                status: 400
            digestMismatch:
              summary: Submitted bytes do not match the declared digest
              value:
                type: https://agentvolumes.org/problems/digest-mismatch
                title: Digest mismatch
                status: 400
            subjectBindingMismatch:
              summary: Trust artifact subject does not match the release
              value:
                type: https://agentvolumes.org/problems/subject-binding-mismatch
                title: Subject binding mismatch
                status: 400
            missingUploadedBytes:
              summary: Finalize was requested before upload bytes were available
              value:
                type: https://agentvolumes.org/problems/missing-uploaded-bytes
                title: Missing uploaded bytes
                status: 400
    Unauthorized:
      description: Authentication needed or invalid bearer token
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
          examples:
            authenticationRequired:
              value:
                type: https://agentvolumes.org/problems/authentication-required
                title: Authentication required
                status: 401
    Forbidden:
      description: Request is refused by authorization or access policy
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
          examples:
            authorizationFailed:
              value:
                type: https://agentvolumes.org/problems/authorization-failed
                title: Authorization failed
                status: 403
    NotFound:
      description: Resource not found
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
          examples:
            notFound:
              value:
                type: https://agentvolumes.org/problems/not-found
                title: Not found
                status: 404
    Conflict:
      description: Resource conflict
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
          examples:
            versionConflict:
              value:
                type: https://agentvolumes.org/problems/version-conflict
                title: Version conflict
                status: 409
            identityMismatch:
              value:
                type: https://agentvolumes.org/problems/identity-mismatch
                title: Identity mismatch
                status: 409
            idempotencyConflict:
              value:
                type: https://agentvolumes.org/problems/idempotency-conflict
                title: Idempotency conflict
                status: 409
            invalidUploadState:
              value:
                type: https://agentvolumes.org/problems/invalid-upload-state
                title: Invalid upload state
                status: 409
            inconsistentRegistryState:
              value:
                type: https://agentvolumes.org/problems/inconsistent-registry-state
                title: Inconsistent registry state
                status: 409
    PayloadTooLarge:
      description: Submitted payload or declared upload size is too large
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
          examples:
            payloadTooLarge:
              value:
                type: https://agentvolumes.org/problems/payload-too-large
                title: Payload too large
                status: 413
    UnsupportedMediaType:
      description: Unsupported media type
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
          examples:
            unsupportedMediaType:
              value:
                type: https://agentvolumes.org/problems/unsupported-media-type
                title: Unsupported media type
                status: 415
    TooManyRequests:
      description: Rate limited
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
          examples:
            rateLimited:
              value:
                type: https://agentvolumes.org/problems/rate-limited
                title: Rate limited
                status: 429
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````