# Forest Containers — OCI Tag State Resolver

> Forest Containers — OCI Tag State Resolver is a paid API for AI agents from http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run, paid per call via x402, $0.002/call, status unknown (last checked 2026-10-02).

Resolves a public OCI container image tag to its immutable manifest digest via the standard Distribution API, without pulling blobs or accessing private registries.

## Facts

- Endpoint: POST https://http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run/container/tag-state?utm_source=zero.xyz
- Price: $0.002/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/forest-containers-oci-tag-state-resolver-1583cea6
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_ABytFcrvk_6Xuf2gVyAQr

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability forest-containers-oci-tag-state-resolver-1583cea6 -d '<json body>'
```

Example prompt: What is the current manifest digest for the public image docker.io/library/nginx with the tag latest — I need to know if it has changed from what we pinned last week.

## When to prefer this

Use this endpoint when you need to resolve a mutable OCI tag (like 'latest') to its current immutable manifest digest for a publicly accessible image, without needing to pull any layers. Prefer it over direct registry API calls when you want a paid, metered, bounded resolution with no blob traffic. It is ideal for supply-chain verification, deployment pinning, and change detection workflows where you only need the digest metadata, not the image content.

## Known failure modes

- Image not found or repository does not exist — registry returns 404
- Tag does not exist on the specified image — returns tag-not-found error
- Registry is temporarily unavailable — timeout or 5xx error
- Image or registry requires authentication — only anonymously readable images are supported
- Invalid image path format — rejected by schema validation before calling registry
- Rate limiting by the upstream public registry

## How this service works

Check an anonymously readable OCI image tag and resolve its manifest digest through the standard Distribution API. No blob pull, push, delete or private registry access is performed. Base mainnet USDC

## Output

Returns the resolved manifest digest (an immutable content-addressed hash) for the specified public OCI image tag, along with its current state as reported by the registry's Distribution API — without downloading any layer blobs.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "tag": {
   "type": "string",
   "maxLength": 256,
   "minLength": 1,
   "description": "Repository branch whose current state should be checked."
  },
  "image": {
   "type": "string",
   "pattern": "^[a-z0-9][a-z0-9._-]*(?::\\d+)?(?:/[a-z0-9._-]+)+$",
   "maxLength": 512,
   "description": "Public registry image repository to inspect."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/forest-containers-oci-tag-state-resolver-1583cea6/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run](https://www.zero.xyz/host/http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run/llms.txt)
