# Forest Containers – OCI Tag Digest Resolver

> Forest Containers – OCI Tag Digest Resolver is a paid API for AI agents from http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run, paid per call via x402, $0.002/call, status unknown (last checked 2026-10-02).

Resolves a mutable OCI image tag to its current immutable content digest using the Distribution manifest API, without asserting signature or vulnerability status.

## Facts

- Endpoint: POST https://http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run/container/digest?utm_source=zero.xyz
- Price: $0.002/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/forest-containers-oci-tag-digest-resolver-c3161f8f
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_jIZbGeFSBUtte1Iv0k-K1

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability forest-containers-oci-tag-digest-resolver-c3161f8f -d '<json body>'
```

Example prompt: What's the current immutable digest for the docker.io/library/nginx:latest image? I need the sha256 manifest digest so I can pin it in my Kubernetes deployment.

## When to prefer this

Use this endpoint when you need to resolve a mutable OCI tag (e.g. 'latest', a semver alias) to its current immutable sha256 digest for pinning, drift detection, or audit purposes — without pulling the full image. Prefer this over local Docker CLI calls when operating in an agent context without Docker access, or when you want a lightweight network-only manifest HEAD request. Note: this endpoint does not validate signatures or scan for vulnerabilities; use dedicated tools for those concerns.

## Known failure modes

- Image repository not found or not publicly accessible — registry returns 404 or 401
- Tag does not exist on the specified image — manifest not found error
- Invalid image name format — rejected by input pattern validation
- Registry rate-limiting or network timeout — transient failure
- Malformed tag string exceeding 256 characters — schema validation error

## How this service works

Resolve a mutable OCI tag to an immutable content digest using bounded Distribution manifest metadata. It does not assert signature or vulnerability status. Base mainnet USDC

## Output

Returns the immutable sha256 content digest corresponding to the specified tag at the time of the query, resolved via the OCI Distribution manifest API. Does not include vulnerability scan results, signature validation, or layer details.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "tag": {
   "type": "string",
   "maxLength": 256,
   "minLength": 1,
   "description": "Repository branch whose current state should be checked."
  },
  "image": {
   "type": "string",
   "pattern": "^[a-z0-9][a-z0-9._-]*(?::\\d+)?(?:/[a-z0-9._-]+)+$",
   "maxLength": 512,
   "description": "Public registry image repository to inspect."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/forest-containers-oci-tag-digest-resolver-c3161f8f/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run](https://www.zero.xyz/host/http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run/llms.txt)
