Skip to content

Source hashes ​

Compute the hashes nixpkgs records for a source without a local Nix installation. The endpoint fetches the artifact it is given and returns the SRI hash, or for Go projects the vendor hash. Every operation is a POST with a JSON body and a Content-Length header; any other method answers 405.

POST /api/v1/prefetch/:operation
OperationBodyWhat it computes
hash{ "owner", "repo", "rev" }The fetchFromGitHub hash for a GitHub, GitLab or Codeberg revision.
tarball{ "url", "validate": true }The hash of a tarball at a URL.
patch{ "url" }The hash of a patch file at a URL.
batch{ "packages": [ ... ] }Several hash requests in one call.
vendor-hash{ "owner", "repo", "rev" }The Go vendorHash for a revision.
vendor-hash-analyze{ "owner", "repo", "rev" }Reads go.mod and returns the module list and a session key for chunked computation.
vendor-hash-chunk{ "sessionKey", "chunkIndex", "modules", "goModInfo" }Fetches one chunk of modules for a session.
vendor-hash-finalize{ "sessionKey", "totalChunks", "goModInfo", "totalModules", "originalRev" }Combines the chunks into the vendor hash.

Only GitHub, GitLab and Codeberg URLs are accepted. The endpoint fetches whatever it is given, so the allowlist is what stops it being used to reach arbitrary hosts.

Response ​

Fields vary by operation. The source-hashing operations share these:

json
{
  "hash": "sha256-...",
  "owner": "curl",
  "repo": "curl",
  "rev": "curl-8_4_0",
  "correctedRev": "curl-8_4_0"
}
FieldMeaning
hashThe SRI hash nixpkgs would record. Null when the operation determined none is needed; note says why.
vendorHashThe Go module vendor hash. Null means the module has no dependencies, not that the computation failed.
revThe revision fetched.
correctedRevPresent when the supplied revision was a tag that resolved to a different spelling (v1.2.3 against 1.2.3).
modulesHow many Go modules were vendored.
noteWhy a null hash is the correct answer rather than a missing one.

Limits ​

Prefetch runs on its own rate-limit bucket, and the vendor-hash chunk operations on another, because a large Go project needs a hundred or more chunk calls. See rate limits for what is enforced. A body over 1 MB answers 413; a POST without Content-Length answers 411.

Vendor hashes are not verified builds

The vendor hash this endpoint computes has not been checked against go mod vendor on every project shape. Treat it as a candidate to confirm with a build rather than a value to commit unread.