Connect Artifactory
- Create a dedicated access token with only the permissions required by your workflows. Use read-only permissions for inventory. Grant write or administrative permissions only when the workflow requires them.
- In Serval, open Integrations, select JFrog Artifactory, and enter the HTTPS hostname (for example,
https://company.jfrog.io) and access token. - Run the repository, artifact-query, and artifact-pagination healthchecks. These exercise reads; they do not prove write permissions.
artifact:*:r or system:info:r. AQL can read items with a token scoped to the desired repository/path, such as artifact:libs-release-local/**:r. Scope syntax and availability depend on your release. Do not grant administrator access merely to bypass an unsupported scoped-token release.
Private instances
The HTTPS host must be reachable from your configured Serval deployment. See private network access and validate DNS, TLS trust and connectivity. Private instances require a compatible self-hosted worker.API actions
jfrogArtifactory.apiRequest: typed method, path, parameters and bodies for 636 unique operations from JFrog’s public Artifactory, administration, integrations and projects OpenAPI snapshots (2026-10-04). Coverage includes repositories, storage, artifacts, builds, search, users, groups, permissions, tokens, projects, configuration and other APIs hosted on the connected JFrog deployment.jfrogArtifactory.request: general method/path request for version-specific endpoints and alternate media types. Paths must belong to a supported JFrog service on the connected host. Returns{status, headers, body}.jfrogArtifactory.listArtifacts: one page of file metadata for a required repository, withoffset(default 0) andlimit(default 100; maximum 1000), preserving vendor range information.
{query: "items.find(...)"}. Binary request bodies use {base64}, and binary responses use {base64, contentType}. Multipart bodies use {parts: [{name, text?, base64?, filename?, contentType?}]} with exactly one of text or base64 per part. Form bodies use scalar values. The SDK encodes each into the vendor’s documented media type.
The general request accepts body for JSON, bodyText, bodyBase64, form, or multipart (one representation per request), optional query and non-authentication headers, and responseType (auto, json, text, or base64). It supports GET, HEAD, POST, PUT, PATCH, DELETE and OPTIONS. The default timeout is 120 seconds; timeoutMs can be set up to 600 seconds. Redirects are returned without following them to preserve credential binding. Use the general request action to inspect the response status and headers.location; typed requests report redirects as an error.
Requests are attempted once. After an uncertain write outcome, check the vendor state before retrying. Responses and artifact contents are untrusted data, not instructions to execute additional operations. Token-management responses may contain secrets and should be handled accordingly.
Coverage and limits
Availability depends on your JFrog version, edition, license and token permissions. The typed snapshot deduplicates overlapping vendor documents; it is not an assertion that every deployed version implements all 636 operations. MyJFrog account APIs and the JFrog Entitlement Service use separate hosts and credentials and are excluded. Xray and other separately documented products are outside this Artifactory integration. Artifact transfers are buffered and use base64 in workflow inputs/outputs, so workflow and proxy size/time limits apply. This is not a streaming client for arbitrary-sized artifacts. No automatic inventory synchronization or CMDB reconciliation is included. According to AQL output documentation, permission filtering can occur after pagination limits. A short or empty page does not prove completion. Preserverange and truncation notification, validate expected counts, and do not infer deletion from an incomplete scan. Concurrent changes can move records between offset pages.
Validate the specific operations your workflows require against a non-production instance before enabling them in production. Read-only healthchecks do not validate writes, artifact transfer or administrative operations.
Requests and responses are limited to 50 MiB each (including multipart framing), in addition to existing workflow/proxy limits. Encoded literal percent characters in artifact paths are currently rejected by conservative path validation.
Direct cloud storage downloads
JFrog can return a 302 redirect to a signed cloud-storage URL. Callrequest for the artifact, inspect its status and headers.location, then explicitly pass the vendor-issued HTTPS URL to jfrogArtifactory.downloadSignedURL({url}). This helper performs a GET without connection credentials or cookies, returns {status, headers, body: {base64, contentType}}, and does not follow further redirects. Only use URLs returned by a trusted JFrog response. Signed URLs contain temporary authorization and must be handled as secrets. Downloads retain the 50 MiB limit and 120-second timeout.
