---
title: "Upload provenance statement"
method: POST
path: "/scopes/{scope}/packages/{package}/versions/{version}/provenance"
---

# Upload provenance statement

`POST /scopes/{scope}/packages/{package}/versions/{version}/provenance`

Uploads a provenance statement for a package version

## Path parameters

- `scope` string, required — The name of a scope. This must not be @ prefixed.
- `package` string, required — The name of a package.
- `version` string, required — A semantic version.

## Request body

- ProvenanceStatementRequest
  - `bundle` object, required — The SLSA provenance bundle.

## Response `204`

OK, no content

## Other responses

- `400` — Invalid request / Invalid provenance
- `401` — Unauthorized
- `403` — User is not authorized to publish

## Changes

- **2026-02-06** `0c4e8d8a5c2a` — 1 info
  - endpoint added
- **2024-02-28** `f8d3b912d946` — 1 breaking
  - api path removed without deprecation

[Change history](https://skmtc.dev/jsr-io/apis/jsr-api/changes/scopes/:scope/packages/:package/versions/:version/provenance/post.md)

---

[API](https://skmtc.dev/jsr-io/apis/jsr-api.md) · [All operations](https://skmtc.dev/jsr-io/apis/jsr-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/jsr-io/jsr-api/revisions/abb153728b13/schema)
