# Forest Containers – OCI Referrers Discovery

> Forest Containers – OCI Referrers Discovery is a paid API for AI agents from http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run, paid per call via x402, $0.003/call, status unknown (last checked 2026-10-02).

Lists OCI 1.1 artifacts (such as SBOMs and attestation evidence) that refer to a specific image digest in a public container registry.

## Facts

- Endpoint: POST https://http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run/container/referrers?utm_source=zero.xyz
- Price: $0.003/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/forest-containers-oci-referrers-discovery-726e833c
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_vuU7D2E1l4iWO93wgUKKK

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability forest-containers-oci-referrers-discovery-726e833c -d '<json body>'
```

Example prompt: Can you list all OCI referrers — like SBOMs or attestation artifacts — for the image ghcr.io/myorg/myapp with digest sha256:abc123...64hexchars?

## When to prefer this

Use this endpoint when you need to discover supply chain artifacts (SBOMs, attestations, provenance) attached to a specific public container image via the OCI 1.1 referrers API. Prefer it over general registry inspection tools when you specifically want a lightweight presence report of referencing artifacts without downloading or verifying them. Not appropriate when you need signature verification or blob content retrieval.

## Known failure modes

- Invalid image repository format returns a validation error
- Malformed or wrong-length digest (not sha256:64hex) is rejected
- Registry is private or inaccessible — no referrers returned or error reported
- Image digest does not exist in the registry — empty referrer list
- Registry does not support OCI 1.1 referrer API — no results or error

## How this service works

Discover OCI 1.1 artifacts referring to an image digest, such as SBOM or attestation evidence. Presence is reported only; Forest does not verify signatures or download blobs. Base mainnet USDC

## Output

A list of OCI 1.1 artifacts that refer to the specified image digest, including artifact types such as SBOMs or attestation evidence. The endpoint only reports presence — it does not verify signatures or download artifact blobs.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "image": {
   "type": "string",
   "pattern": "^[a-z0-9][a-z0-9._-]*(?::\\d+)?(?:/[a-z0-9._-]+)+$",
   "maxLength": 512,
   "description": "Public registry image repository to inspect."
  },
  "digest": {
   "type": "string",
   "pattern": "^sha256:[a-f0-9]{64}$",
   "description": "Immutable image digest whose referring artifacts should be listed."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/forest-containers-oci-referrers-discovery-726e833c/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run](https://www.zero.xyz/host/http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run/llms.txt)
