Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC
GitLab CI/CD website screenshot

GitLab CI/CD

GitLab CI/CD is the built-in continuous integration, delivery and deployment platform for GitLab. The CI/CD surface area within GitLab's REST API v4 covers pipelines, jobs, pipeline schedules, pipeline triggers, runners, agents, releases, environments, deployments, package and container registries, and the security/dependency scanners. GitLab also exposes a GraphQL API.

agent ready

Limited machine-readable signal and partial portal coverage — documentation a human can read, but little a machine or agent can consume without scraping.

Kin Score

API Evangelist profiles GitLab CI/CD the way a machine reads it — 109 machine-readable artifacts across 98 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.

Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — GitLab CI/CD scores 40.2/100 (thin), with a separate agent-readiness read of 48/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.

Kin Score

This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 40.2/100 · thin
Contract Quality 9.4 / 25
Developer Ergonomics 4.3 / 20
Commercial Clarity 11.6 / 20
Operational Transparency 6.8 / 13
Governance 0.0 / 12
Discoverability 8.0 / 10
Agent readiness — 48/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3

How we profile GitLab CI/CD

Each block below is one kind of artifact we hold for GitLab CI/CD. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.

APIs 98

Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.

Individual APIs this provider publishes, each with its own machine-readable definition.

GitLab GraphQL API

GitLab's GraphQL API at /api/graphql. Many CI/CD entities (Pipeline, CiJob, CiRunner, MergeRequest pipelines) are exposed via GraphQL queries and mutations.

GitLab CI/CD access_requests API

Operations related to access requests

GitLab CI/CD access_tokens API

Operations about access_tokens

GitLab CI/CD agents API

Operations about agents

GitLab CI/CD alert_management API

Operations about alert_managements

GitLab CI/CD applications API

Operations about applications

GitLab CI/CD attestations API

Operations about attestations

GitLab CI/CD audit_events API

Operations about audit_events

GitLab CI/CD avatars API

Operations about avatars

GitLab CI/CD award_emoji API

Operations about award_emoji

GitLab CI/CD badges API

Operations about badges

GitLab CI/CD batched_background_migrations API

Operations about batched_background_migrations

GitLab CI/CD branches API

Operations about branches

GitLab CI/CD broadcast_messages API

Operations about broadcast_messages

GitLab CI/CD chaos API

Operations about chaos

GitLab CI/CD ci_catalog API

Operations about ci_catalogs

GitLab CI/CD ci_jobs API

Operations about ci_jobs

GitLab CI/CD ci_lint API

Operations related to linting a CI config file

GitLab CI/CD ci_resource_groups API

Operations to manage job concurrency with resource groups

GitLab CI/CD ci_runners API

Operations about ci_runners

GitLab CI/CD ci_triggers API

Operations about ci_triggers

GitLab CI/CD ci_variables API

Operations related to CI/CD variables

GitLab CI/CD cluster_agents API

Operations related to the GitLab agent for Kubernetes

GitLab CI/CD clusters API

Operations related to clusters

GitLab CI/CD commit_statuses API

Operations about commit_statuses

GitLab CI/CD commits API

Operations about commits

GitLab CI/CD container_registry API

Operations related to container registry

GitLab CI/CD custom_attributes API

Operations about custom_attributes

GitLab CI/CD database_dictionary API

Operations about database_dictionaries

GitLab CI/CD dependency_proxy API

Operations to manage dependency proxy for a groups

GitLab CI/CD deploy_resources API

Operations about deploy_resources

GitLab CI/CD draft_notes API

Operations about draft_notes

GitLab CI/CD environments API

Operations related to environments

GitLab CI/CD error_tracking API

Operations about error_trackings

GitLab CI/CD events API

Operations about events

GitLab CI/CD feature_flags API

Operations related to feature flags

GitLab CI/CD features API

Operations related to managing Flipper-based feature flags

GitLab CI/CD files API

Operations about files

GitLab CI/CD freeze_periods API

Operations related to deploy freeze periods

GitLab CI/CD geo API

Operations related to Geo

GitLab CI/CD gitlab_pages API

Operations about gitlab_pages

GitLab CI/CD glql API

Operations about glqls

GitLab CI/CD group_import_and_export API

Operations about group_import_and_exports

GitLab CI/CD groups API

Operations about groups

GitLab CI/CD hooks API

Operations about hooks

GitLab CI/CD imports API

Operations about imports

GitLab CI/CD instance API

Operations about instances

GitLab CI/CD integrations API

Operations related to integrations

GitLab CI/CD internal_operations API

Operations about internal_operations

GitLab CI/CD invitations API

Operations about invitations

GitLab CI/CD issues API

Operations about issues

GitLab CI/CD jira_connect_subscriptions API

Operations related to JiraConnect subscriptions

GitLab CI/CD job_artifacts API

Operations about job_artifacts

GitLab CI/CD jobs API

Operations about jobs

GitLab CI/CD keys API

Operations about keys

GitLab CI/CD ldap API

Operations about ldaps

GitLab CI/CD markdown API

Operations about markdowns

GitLab CI/CD members API

Operations about members

GitLab CI/CD merge_request_approvals API

Operations about merge_request_approvals

GitLab CI/CD merge_requests API

Operations related to merge requests

GitLab CI/CD metadata API

Operations related to metadata of the GitLab instance

GitLab CI/CD metric_images API

Operations about metric_images

GitLab CI/CD metrics API

Operations about metrics

GitLab CI/CD migrations API

Operations about migrations

GitLab CI/CD ml_model_registry API

Operations related to Model registry

GitLab CI/CD namespaces API

Operations about namespaces

GitLab CI/CD offline_transfers API

Operations about offline_transfers

GitLab CI/CD organizations API

Operations about organizations

GitLab CI/CD packages API

Operations about packages

GitLab CI/CD pipeline_schedules API

Operations about pipeline_schedules

GitLab CI/CD pipelines API

Operations about pipelines

GitLab CI/CD plan_limits API

Operations related to plan limits

GitLab CI/CD project_import API

Operations related to importing projects

GitLab CI/CD project_snapshots API

Operations about project_snapshots

GitLab CI/CD project_templates API

Operations about project_templates

GitLab CI/CD project_topics API

Operations about project_topics

GitLab CI/CD projects API

Operations related to projects

GitLab CI/CD projects_job_token_scope API

Operations about projects_job_token_scopes

GitLab CI/CD protected_branches API

Operations about protected_branches

GitLab CI/CD protected_tags API

Operations about protected_tags

GitLab CI/CD pypi_packages API

Operations related to PyPI packages

GitLab CI/CD releases API

Operations related to releases

GitLab CI/CD remote_mirrors API

Operations about remote_mirrors

GitLab CI/CD repositories API

Operations about repositories

GitLab CI/CD resource_events API

Operations about resource_events

GitLab CI/CD runners API

Operations about runners

GitLab CI/CD search API

Operations about searches

GitLab CI/CD secure_files API

Operations about secure_files

GitLab CI/CD snippets API

Operations about snippets

GitLab CI/CD submodules API

Operations about submodules

GitLab CI/CD suggestions API

Operations related to suggestions

GitLab CI/CD tags API

Operations about tags

GitLab CI/CD terraform API

Operations about terraforms

GitLab CI/CD unleash API

Operations about unleashes

GitLab CI/CD usage_data API

Operations about usage_data

GitLab CI/CD users API

Operations about users

GitLab CI/CD web_commits API

Operations about web_commits

GitLab CI/CD wikis API

Operations about wikis

Scroll within the panel for all 98 ·

Open Collections 1

Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

GitLab API

OPEN COLLECTION

GraphQL 1

Where a provider ships GraphQL, the schema is the contract. We profile it alongside the REST surface so the whole interface is legible in one place.

GraphQL schemas published by this provider.

GitLab CI/CD GraphQL API

GitLab's GraphQL API at /api/graphql. Many CI/CD entities (Pipeline, CiJob, CiRunner, MergeRequest pipelines) are exposed via GraphQL queries and mutations.

GRAPHQL

Pricing Plans 1

Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.

Published pricing tiers and plan structures.

Rate Limits 1

Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.

Documented rate limits and quota policies.

Gitlab Ci Rate Limits

10 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.

Cost, billing, and metering signals for API financial operations.

JSON Structure 1

JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.

JSON Structure definitions describing this provider's data shapes.

Gitlab Ci Structure

0 properties

JSON STRUCTURE

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Gitlab Ci Authentication

apiKey · 2 schemes

SECURITY

Gitlab Ci Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Gitlab Ci Vulnerability Disclosure

Hackerone · security.txt · contact published

SECURITY

Gitlab Ci Trust Center

SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS, GDPR, CSA STAR

SECURITY

Agentic Access 1

An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.

Recommended x-agentic-access execution contracts for AI agents.

Gitlab Ci Agentic Access

1125 operations · 627 acting · 22 human-in-the-loop

1125 operations · 627 acting

AGENTIC

Resources

Every other property we hold for GitLab CI/CD — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Build 1

SDKs, sample code, and the tooling you integrate with

Operate 2

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

← All providers · Data indexed from github.com/api-evangelist/gitlab-ci · machine-readable index on apis.io