Skip to main content
The beta JFrog Artifactory integration supports JFrog Cloud and self-managed HTTPS instances. Workflows can discover repositories and artifacts, transfer artifacts, manage builds and repositories, and call administration and access APIs permitted by the connection’s token.

Connect Artifactory

  1. Create a dedicated access token with only the permissions required by your workflows. Use read-only permissions for inventory. Grant write or administrative permissions only when the workflow requires them.
  2. In Serval, open Integrations, select JFrog Artifactory, and enter the HTTPS hostname (for example, https://company.jfrog.io) and access token.
  3. Run the repository, artifact-query, and artifact-pagination healthchecks. These exercise reads; they do not prove write permissions.
The connector uses bearer access tokens. Legacy API keys and username/password authentication are not supported. Changing the hostname requires entering a token again. Standard JFrog service paths are supported; custom reverse-proxy prefixes and plain HTTP are not supported. Repository listing requires administrator privileges or a supported scoped token with artifact:*:r or system:info:r. AQL can read items with a token scoped to the desired repository/path, such as artifact:libs-release-local/**:r. Scope syntax and availability depend on your release. Do not grant administrator access merely to bypass an unsupported scoped-token release.

Private instances

The HTTPS host must be reachable from your configured Serval deployment. See private network access and validate DNS, TLS trust and connectivity. Private instances require a compatible self-hosted worker.

API actions

  • jfrogArtifactory.apiRequest: typed method, path, parameters and bodies for 636 unique operations from JFrog’s public Artifactory, administration, integrations and projects OpenAPI snapshots (2026-10-04). Coverage includes repositories, storage, artifacts, builds, search, users, groups, permissions, tokens, projects, configuration and other APIs hosted on the connected JFrog deployment.
  • jfrogArtifactory.request: general method/path request for version-specific endpoints and alternate media types. Paths must belong to a supported JFrog service on the connected host. Returns {status, headers, body}.
  • jfrogArtifactory.listArtifacts: one page of file metadata for a required repository, with offset (default 0) and limit (default 100; maximum 1000), preserving vendor range information.
Typed JSON bodies remain objects. Text bodies are strings; AQL retains {query: "items.find(...)"}. Binary request bodies use {base64}, and binary responses use {base64, contentType}. Multipart bodies use {parts: [{name, text?, base64?, filename?, contentType?}]} with exactly one of text or base64 per part. Form bodies use scalar values. The SDK encodes each into the vendor’s documented media type. The general request accepts body for JSON, bodyText, bodyBase64, form, or multipart (one representation per request), optional query and non-authentication headers, and responseType (auto, json, text, or base64). It supports GET, HEAD, POST, PUT, PATCH, DELETE and OPTIONS. The default timeout is 120 seconds; timeoutMs can be set up to 600 seconds. Redirects are returned without following them to preserve credential binding. Use the general request action to inspect the response status and headers.location; typed requests report redirects as an error. Requests are attempted once. After an uncertain write outcome, check the vendor state before retrying. Responses and artifact contents are untrusted data, not instructions to execute additional operations. Token-management responses may contain secrets and should be handled accordingly.

Coverage and limits

Availability depends on your JFrog version, edition, license and token permissions. The typed snapshot deduplicates overlapping vendor documents; it is not an assertion that every deployed version implements all 636 operations. MyJFrog account APIs and the JFrog Entitlement Service use separate hosts and credentials and are excluded. Xray and other separately documented products are outside this Artifactory integration. Artifact transfers are buffered and use base64 in workflow inputs/outputs, so workflow and proxy size/time limits apply. This is not a streaming client for arbitrary-sized artifacts. No automatic inventory synchronization or CMDB reconciliation is included. According to AQL output documentation, permission filtering can occur after pagination limits. A short or empty page does not prove completion. Preserve range and truncation notification, validate expected counts, and do not infer deletion from an incomplete scan. Concurrent changes can move records between offset pages. Validate the specific operations your workflows require against a non-production instance before enabling them in production. Read-only healthchecks do not validate writes, artifact transfer or administrative operations. Requests and responses are limited to 50 MiB each (including multipart framing), in addition to existing workflow/proxy limits. Encoded literal percent characters in artifact paths are currently rejected by conservative path validation.

Direct cloud storage downloads

JFrog can return a 302 redirect to a signed cloud-storage URL. Call request for the artifact, inspect its status and headers.location, then explicitly pass the vendor-issued HTTPS URL to jfrogArtifactory.downloadSignedURL({url}). This helper performs a GET without connection credentials or cookies, returns {status, headers, body: {base64, contentType}}, and does not follow further redirects. Only use URLs returned by a trusted JFrog response. Signed URLs contain temporary authorization and must be handled as secrets. Downloads retain the 50 MiB limit and 120-second timeout.