Skip to content

List a package's versions, newest first: each with its id (ver_…), name (the version, or for a container image its digest), digest, size_in_bytes, download_count, tags, media_type, platforms, published_by and created_at.

GET/workspaces/{workspace}/packages/{package_type}/{package_name}/versions

With state deleted, its deleted versions that can still be restored, with deleted_at, deleted_by and purge_at: for the package’s admins only.

A container image’s versions are its manifests, named by digest; every other package’s by version. download_count counts pulls and downloads of the version itself, approximately. With state=deleted, the deleted versions that can still be restored, for the package’s admins.

  • Authentication: Optional. Public data can be read without a token; send one to see what is private.
  • MCP tool: package with action versions, and the same inputs
  • Scope: An access token needs packages:read.
Name Type Required Description
workspace string Yes The workspace’s slug, e.g. “flagon-io”.
package_type string Yes The registry: container (also docker), npm, cargo, maven, nuget, rubygems or composer. One of container, npm, cargo, maven, nuget, rubygems, composer.
package_name string Yes The package’s name without the workspace: web for g1t.sh/acme/web, web/worker for an image with more parts, group:artifact for Maven.
Name Type Required Description
state string No active (the default), or deleted: deleted versions that can still be restored. One of active, deleted.
curl https://api.g1t.sh/workspaces/acme/packages/container/web/versions \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

[
{
"id": "ver_01kq9c5f7h9k1m3p5r7t9v1x3z",
"name": "sha256:9b2e4d6f8a0c1e3b5d7f9a2c4e6b8d0f1a3c5e7b9d2f4a6c8e0b1d3f5a7c9e2b",
"digest": "sha256:9b2e4d6f8a0c1e3b5d7f9a2c4e6b8d0f1a3c5e7b9d2f4a6c8e0b1d3f5a7c9e2b",
"size_in_bytes": 48211932,
"download_count": 611,
"tags": [
"latest",
"v1.4.0"
],
"media_type": "application/vnd.oci.image.index.v1+json",
"artifact_type": null,
"subject": null,
"platforms": [
"linux/amd64",
"linux/arm64"
],
"published_by": "ana",
"created_at": "2026-10-08T14:05:20.000Z",
"deprecated": null,
"deleted_at": null,
"deleted_by": null,
"purge_at": null
}
]

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
422 invalid The input is not valid. message says which field and why.