Ellipse Gradient for Header

JFrog Artifactory Integration Guide

Integrate JFrog Artifactory with enterprise systems through REST APIs, artifact transfers, AQL searches, and selected webhook events.

JFrog Artifactory integration options at a glance

JFrog Artifactory's primary integration mechanism is its REST API, which supports artifact uploads and downloads, repository and metadata operations, build information, properties, administration, and selected import or export scenarios. Artifacts are transferred through HTTP endpoints using repository paths, while Artifactory Query Language supports targeted searches across artifacts and metadata. Selected Artifactory and JFrog Platform events can generate webhooks, although coverage is event-specific. Current integrations should generally use scoped JFrog access tokens, with API keys and Basic Authentication retained only where required by legacy or configured environments. Martini can consume these APIs, receive webhook notifications through exposed APIs, schedule searches, transform data, and orchestrate downstream workflows.

Integration pointSupported by JFrog Artifactory?Common use casesHow Martini supports it
REST APIsYesArtifactory's primary programmatic interface supports repository administration, artifact operations, metadata, properties, builds, permissions, and supported import or export scenarios.Martini can consume the REST API, construct authenticated requests, map responses, orchestrate dependent calls, and expose a controlled API façade for enterprise consumers.
File and artifact APIsYesHTTP repository endpoints upload and download packages, container-related files, manifests, and other artifacts using repository keys and artifact paths.Martini workflows can transfer files, apply timeout and retry policies, validate checksums, and route artifacts to downstream systems.
AQL and metadata searchYesArtifactory Query Language searches artifacts and related metadata by repository, path, properties, names, and dates. It is useful for inventory and retention workflows.Martini can run scheduled or API-triggered searches, process bounded result sets, maintain watermarks, and write normalized inventory data to databases or applications.
Webhooks and outbound callbacksLimitedSelected Artifactory or JFrog Platform events, such as artifact deployment, build publication, or promotion, can generate notifications depending on edition and configuration.Martini can expose an API to receive notifications, validate and deduplicate them, then retrieve authoritative Artifactory state before continuing the workflow.
Bulk, asynchronous, or batch APIsLimitedSelected administrative, search, copy, move, import, export, and multi-item operations are available, but Artifactory is not a general-purpose bulk event-streaming API.Martini can partition work into bounded batches, control concurrency, checkpoint progress, and retry transient failures.
Build information and promotionYesBuild APIs support publishing and retrieving build metadata, associating artifacts with builds, and promoting or moving artifacts subject to repository and product configuration.Martini can validate approvals, properties, or external change records before invoking build, copy, move, or promotion operations.
AuthenticationYesJFrog access tokens are preferred for current API integrations. API keys and Basic Authentication may remain available in legacy or specifically configured environments.Martini can store tokens and credentials in secrets or secure environment configuration and apply the required authorization headers without embedding secrets in workflows.
Database and analytics accessLimitedAQL provides supported artifact and metadata search; direct access to Artifactory's internal database is not the recommended integration method. Xray and analytics APIs depend on separate products or configuration.Martini can consume supported search or product APIs and write results to an external database, without depending on internal Artifactory schemas.

How JFrog Artifactory exposes data and business events

JFrog Artifactory REST APIs

The Artifactory REST API is the primary integration surface for repository administration, artifact upload and download, metadata and properties, build information, searches, and selected promotion or configuration operations.

Martini implementation pattern

Martini implementation pattern: Martini consumes the relevant REST endpoint with a scoped access token, validates request and response data, transforms it into a canonical model, and coordinates follow-on calls or downstream writes in a workflow.

Implementation sequence

Authenticate with a scoped Artifactory access token
Build the repository path and request parameters from validated inputs
Call the Artifactory REST endpoint
Validate the HTTP response and returned identifiers
Map the response to the downstream data model
Persist the result and workflow checkpoint

Artifact Uploads and Downloads

Artifactory exposes repository paths for uploading and downloading packages, container-related files, manifests, and other binary artifacts. Package formats can impose different path and metadata conventions.

Martini implementation pattern

Martini implementation pattern: A workflow receives or retrieves the file, determines the target repository and validated path, transfers the content with suitable timeout and retry settings, and verifies the result through metadata or checksum information.

Implementation sequence

Receive or retrieve the source artifact
Validate the repository, package format, version, and path
Upload or download the artifact through the HTTP endpoint
Check the response and checksum information
Apply required artifact properties
Return the artifact location and transfer status

Artifactory Query Language

AQL searches artifacts and related metadata using criteria such as repository, path, properties, creation date, and modification date. It supports scheduled inventory, retention, and governance workflows.

Martini implementation pattern

Martini implementation pattern: A scheduled workflow submits a selective AQL query, processes results in bounded batches, maps them to an inventory or governance model, and records a watermark or stable identifier for repeat-safe processing.

Implementation sequence

Start the scheduled inventory workflow
Build a selective AQL query from configured criteria
Retrieve results in bounded pages or batches
Map artifact and property data to the target model
Write results to the database or governance application
Store the last successful watermark

JFrog Artifactory Webhooks

Artifactory supports webhook notifications for selected repository or platform events, including some artifact, build, or promotion changes depending on edition and configuration. Webhook coverage is not universal.

Martini implementation pattern

Martini implementation pattern: A Martini API receives and validates the notification, records an event key, retrieves the authoritative artifact or build state from Artifactory, and performs retry-safe downstream processing rather than relying only on the payload.

Implementation sequence

Receive the selected Artifactory event notification
Authenticate or validate the incoming request
Record and deduplicate the event identifier
Retrieve the current Artifactory resource
Apply business rules and map the result
Invoke downstream systems and acknowledge processing

Build Information and Promotion

Artifactory build APIs support publishing and retrieving build metadata and associating artifacts with builds. Copy, move, or promotion behavior depends on the repository model and related JFrog products.

Martini implementation pattern

Martini implementation pattern: A workflow checks build status, properties, approvals, or external change data before invoking the applicable Artifactory operation, then records the outcome for deployment and audit processes.

Implementation sequence

Receive a promotion request or start a scheduled check
Retrieve the build and associated artifact information
Validate approval, property, and repository rules
Invoke the applicable copy, move, or promotion operation
Verify the resulting repository state
Notify downstream deployment or governance systems

Common JFrog Artifactory integration patterns

Pattern 1: Publish CI/CD artifacts to Artifactory

When to use this pattern

Use this pattern when Jenkins, GitHub Actions, GitLab CI/CD, or Azure DevOps needs a governed publication process rather than direct, duplicated Artifactory calls. The workflow validates build metadata, uploads the artifact, applies properties, publishes build information, and returns a normalized result. Retry-safe checks prevent duplicate publication or unintended overwrites.

Integration direction
Jenkins or GitHub Actions
Martini
JFrog Artifactory
Example Mapping
JFrog Artifactory FieldCanonical FieldTarget Field
buildNamebuild.nameBuild name
buildNumberbuild.numberBuild number
artifactPathartifact.pathRepository artifact path
commitIdsource.commitIdArtifact property commit
Martini implementation pattern

Martini receives a build completion request through an API or workflow trigger, validates repository and path inputs, transfers the artifact through the Artifactory REST API, applies release and commit properties, publishes build information, and handles transient HTTP failures with bounded retries.

Martini capabilities used
  • API exposure
  • API consumption
  • workflows
  • data mapping
  • validation
  • business rules
  • error handling

Pattern 2: Promote approved artifacts between repositories

When to use this pattern

Use this pattern when artifacts must move from development to staging or release repositories only after approval, policy, or change-control checks. The workflow confirms the source artifact and build state, evaluates properties or an external approval, performs the applicable Artifactory copy, move, or promotion operation, and records the result.

Integration direction
ServiceNow
Martini
JFrog Artifactory
Example Mapping
JFrog Artifactory FieldCanonical FieldTarget Field
sourceRepopromotion.sourceRepositorySource repository
targetRepopromotion.targetRepositoryTarget repository
buildNumberbuild.numberBuild number
approvalStatusapproval.statusPromotion decision
Martini implementation pattern

Martini retrieves build and artifact metadata, applies repository and approval rules, calls the confirmed Artifactory operation, verifies the target state, and sends a controlled update to ServiceNow or the deployment process. Stable artifact paths and existence checks make retries idempotent.

Martini capabilities used
  • workflows
  • API consumption
  • data mapping
  • business rules
  • validation
  • error handling
  • reusable services

Pattern 3: Synchronize an Artifactory artifact inventory

When to use this pattern

Use this pattern for scheduled governance, retention, or inventory synchronization. Martini uses AQL or supported search APIs to identify artifacts by repository, path, property, or date, processes results in bounded batches, and writes normalized records to a database, warehouse, CMDB, or governance application.

Integration direction
JFrog Artifactory
Martini
PostgreSQL
Example Mapping
JFrog Artifactory FieldCanonical FieldTarget Field
repoartifact.repositoryrepository_key
pathartifact.pathartifact_path
createdartifact.createdAtcreated_at
propertiesartifact.propertiesproperties_json
Martini implementation pattern

A scheduled Martini workflow submits a selective AQL query, handles result limits, maps package-specific metadata into a canonical inventory model, upserts records using a stable repository-path or checksum key, and stores a watermark after successful processing.

Martini capabilities used
  • scheduling
  • workflows
  • API consumption
  • data mapping
  • database integration
  • business rules
  • monitoring

Pattern 4: Trigger downstream deployment from Artifactory events

When to use this pattern

Use this pattern when selected artifact deployment, build publication, or promotion events should start deployment, ticketing, security, or notification workflows. Because webhook coverage and payload detail vary, the event starts the process while Artifactory remains the source of truth.

Integration direction
JFrog Artifactory
Martini
Kubernetes
Example Mapping
JFrog Artifactory FieldCanonical FieldTarget Field
eventIdevent.idprocessing_key
repoKeyartifact.repositoryrepository
artifactPathartifact.pathimage_or_chart_reference
buildNumberbuild.numberdeployment.version
Martini implementation pattern

Martini receives the webhook through an exposed API, validates and deduplicates the event, retrieves current artifact or build details, applies deployment eligibility rules, and calls the target deployment or ticketing API. Failed downstream operations are retried without repeating completed Artifactory work.

Martini capabilities used
  • API exposure
  • webhook consumption
  • workflows
  • API consumption
  • validation
  • business rules
  • error handling

Applications commonly integrated with JFrog Artifactory

JFrog Artifactory commonly participates in software delivery, deployment, governance, and release workflows. Martini can coordinate Artifactory APIs and artifact transfers with the following named applications, while keeping authentication, mapping, validation, retries, and business rules in reusable workflows.

Application Scenario Direction Martini Pattern
Jenkins Publish build artifacts and build information to Artifactory, then retrieve approved dependencies or release artifacts. Jenkins → Martini → JFrog Artifactory Receive build completion data, validate build identifiers and artifact paths, upload or register artifacts through the Artifactory REST API, apply properties, and return publication status to Jenkins.
GitHub Actions Store packages, container images, and build outputs produced by GitHub-based pipelines in Artifactory. GitHub Actions → Martini → JFrog Artifactory Expose a Martini API or consume pipeline callbacks, validate repository and version information, transfer the artifact, publish build metadata, and apply retry-safe status handling.
GitLab CI/CD Publish and promote artifacts produced by GitLab pipelines and retrieve dependencies from Artifactory. GitLab CI/CD → Martini → JFrog Artifactory Orchestrate pipeline requests with Artifactory upload, metadata, property, and promotion operations while recording stable build and artifact identifiers for idempotency.
Azure DevOps Connect Azure Pipelines with Artifactory for artifact publication, dependency retrieval, and release promotion. Azure DevOps → Martini → JFrog Artifactory Use a Martini workflow to accept release information, call the relevant Artifactory endpoints, validate approvals or properties, and return a normalized release result to Azure DevOps.
Kubernetes Pull container images and Helm packages from Artifactory during application deployment. JFrog Artifactory → Martini → Kubernetes Use Artifactory metadata or webhook events to trigger deployment coordination, validate image or chart versions, and call the deployment system with a controlled, auditable release payload.
ServiceNow Create or update change, release, or configuration records when artifacts are promoted or deployed. JFrog Artifactory → Martini → ServiceNow Receive promotion or deployment results, map build and artifact identifiers to ServiceNow fields, apply change-control rules, and retry downstream updates without duplicating records.
JFrog Xray Retrieve vulnerability, license, and policy information for artifacts before promotion or deployment, subject to Xray licensing and API availability. JFrog Artifactory → Martini → JFrog Xray Retrieve the relevant artifact or build context, call confirmed Xray or JFrog Platform endpoints when enabled, evaluate policy results, and route approved or rejected artifacts accordingly.

How to build a JFrog Artifactory integration in Martini

Objective

Configure the Artifactory base URL, repository settings, and authentication without embedding credentials in workflow definitions.

Instructions in Martini

  • Use a dedicated Artifactory technical identity with minimum required permissions.
  • Prefer a scoped access token for new integrations.
  • Store tokens and environment-specific values in Martini secrets or secure configuration.
  • Configure TLS, timeout, and transfer settings for the deployment environment.

Objective

Select an event-driven, API-led, or scheduled entry point based on the required Artifactory operation and event coverage.

Instructions in Martini

  • Use a Martini API for CI/CD requests or supported Artifactory webhook notifications.
  • Use a scheduler for AQL inventory, retention, or reconciliation workflows.
  • Treat webhook notifications as triggers and retrieve authoritative Artifactory state.
  • Use stable event, build, artifact, or checksum identifiers for deduplication.

Objective

Call the appropriate Artifactory REST, artifact, build, metadata, or AQL endpoint and handle repository-specific paths.

Instructions in Martini

  • Validate repository keys, package formats, versions, and artifact paths before constructing requests.
  • Retrieve current artifact or build details when an event payload is incomplete.
  • Process large search results in bounded pages or batches.
  • Stream or otherwise control large artifact transfers according to Martini environment limits.

Objective

Coordinate Artifactory operations with approvals, databases, CI/CD platforms, deployment systems, and governance applications.

Instructions in Martini

  • Separate validation, retrieval, transformation, business rules, and downstream writes into maintainable workflow stages.
  • Use conditional routing for approval, policy, repository, or package-format decisions.
  • Persist checkpoints or watermarks after successful units of work.
  • Use reusable services for shared Artifactory request and response handling.

Objective

Convert Artifactory repositories, artifacts, properties, builds, and events into the target system's canonical model.

Instructions in Martini

  • Map repository and artifact paths to explicit canonical fields.
  • Preserve build names, build numbers, checksums, properties, and package-specific metadata where relevant.
  • Normalize optional fields and package-format differences.
  • Validate required fields before writing to downstream systems.

Objective

Enforce repository, approval, security, retention, and promotion policies before changing Artifactory or downstream state.

Instructions in Martini

  • Check artifact properties, build status, approvals, or external change records.
  • Prevent unauthorized repository writes and unintended overwrites.
  • Use checksum and existence checks to make publication and promotion retry-safe.
  • Keep Xray-dependent rules conditional on confirmed licensing and API availability.

Common JFrog Artifactory data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
RepositoriesRepresent local, remote, virtual, or federated locations that store or proxy artifacts and define repository-specific access and path behavior.CI/CD platforms, Kubernetes, deployment platforms, governance databasesMartini maps repository keys and types, validates allowed destinations, and uses repository-specific API paths for reads, writes, searches, and promotion operations.
ArtifactsRepresent binary packages, files, container images, manifests, and package-format content stored under repository paths.Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, KubernetesMartini transfers artifacts through HTTP endpoints, preserves identifiers and checksums where possible, and applies size, timeout, retry, and idempotency controls.
Artifact propertiesKey-value metadata classifying artifacts by release status, environment, ownership, commit, or promotion state.CI/CD systems, ServiceNow, governance databases, deployment platformsMartini reads, validates, adds, or removes properties as part of approval, promotion, inventory, and downstream notification workflows.
Builds and build informationCapture build names, numbers, modules, artifact relationships, and dependency information for traceability and release automation.Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps, ServiceNowMartini publishes or retrieves build information, correlates it with artifacts, and uses stable build identifiers to make retries safe.
Repository layoutsDefine how paths and module coordinates are structured for supported package formats such as Maven, npm, PyPI, Helm, or other repositories.Package managers, CI/CD platforms, deployment toolsMartini treats package-specific path and naming rules as configuration, validates versions and coordinates, and avoids assuming all artifacts behave like generic files.
ProjectsProvide logical administration and governance boundaries for repositories, users, resources, and permissions in JFrog Platform environments.Identity and governance applications, ServiceNow, administration workflowsMartini can consume project and permission APIs where authorized, apply scoped administrative rules, and avoid granting broader privileges than the workflow requires.

Authentication and security considerations

Use scoped access tokens

JFrog access tokens are the preferred authentication method for current API integrations. Martini should store tokens in secrets or secure environment configuration and apply them through authorization headers without exposing them in workflow logs, URLs, or error messages.

Limit permissions

Use a dedicated technical identity with only the repository and operation permissions required. Separate read-only, publishing, and administrative identities where practical, and avoid granting global administration rights to ordinary artifact workflows.

Protect transfers and paths

  • Keep TLS certificate validation enabled in production.
  • Validate repository keys, package formats, versions, and paths before constructing requests.
  • Preserve checksum information and verify successful uploads where possible.
  • Treat API keys and Basic Authentication as legacy or environment-specific options when access tokens are available.

Operational considerations for JFrog Artifactory integrations

Rate limits and concurrency

JFrog Cloud quotas, reverse proxies, storage, bandwidth, concurrent transfers, and Xray capacity can constrain integrations. Martini workflows should control concurrency and use retry backoff for transient failures.

Pagination and large searches

AQL and metadata searches may return large result sets. Use selective queries, bounded batches, pagination or result limits where available, and durable watermarks for scheduled processing.

Idempotency and webhooks

Artifact publication, promotion, and webhook handling should tolerate retries and duplicate delivery. Use immutable versioned paths, existence or checksum checks, stable build identifiers, and recorded event keys.

Version and package differences

Payloads and operations can vary by Artifactory version, product edition, repository type, and enabled JFrog modules. Test mappings against the target environment and handle optional fields and package-specific path conventions.

Transfer and schema testing

Large binaries require appropriate timeout and memory settings. Where possible, test API responses, repository layouts, permissions, checksums, failure responses, and downstream retry behavior before production deployment.

Why use Martini instead of scripts or point-to-point integrations?

Coordinate more than an HTTP call

Scripts can call Artifactory endpoints, but enterprise integrations also need validation, mapping, approvals, downstream updates, retries, deduplication, and operational visibility. Martini provides workflows and APIs for coordinating these responsibilities in one maintainable integration asset.

Separate configuration from logic

Base URLs, repositories, credentials, project settings, and environment-specific limits can be externalized from workflow logic. This supports repeatable deployments across JFrog Cloud, self-hosted, reverse-proxy, and environment-specific configurations.

Build reusable integration behavior

  • Consume REST APIs and expose controlled APIs for CI/CD or webhook entry points.
  • Reuse mappings, validation, authentication, and error-handling logic.
  • Combine scheduled AQL searches with event-driven processing.
  • Apply business rules before artifact promotion or downstream deployment.
  • Monitor workflow outcomes and retry transient failures without duplicating successful work.

Frequently asked questions

How can JFrog Artifactory be integrated with enterprise systems?

JFrog Artifactory is primarily integrated through its REST APIs and HTTP artifact endpoints. Enterprise workflows can upload and download artifacts, search with AQL, manage metadata and properties, publish build information, administer repositories, and perform supported promotion operations. Selected Artifactory or JFrog Platform events can also send webhooks.

Can Martini integrate with JFrog Artifactory?

Yes. Martini can consume JFrog Artifactory REST APIs, transfer artifacts through HTTP endpoints, execute supported AQL searches, receive selected webhook notifications through a Martini API, and orchestrate Artifactory with CI/CD, deployment, database, governance, and messaging systems.

Do I need a connector to integrate JFrog Artifactory with Martini?

No dedicated JFrog Artifactory connector is required. Martini can integrate using Artifactory's confirmed native mechanisms, including REST APIs, artifact upload and download endpoints, AQL, selected webhooks, and access-token authentication.

Is there any extra Lonti cost to integrate JFrog Artifactory with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate JFrog Artifactory. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from JFrog, cloud infrastructure, network services, or other third-party systems based on subscription, usage, and deployment model.

Which JFrog Artifactory integration methods should new projects use?

New projects should generally use the Artifactory REST API and HTTP artifact endpoints, authenticated with scoped access tokens. AQL is useful for inventory and governance searches, while selected webhooks can provide event triggers. API keys are legacy where supported, and no confirmed Artifactory GraphQL or SOAP API is identified in the supplied research.

Are JFrog Artifactory webhooks available for event-driven integrations?

Artifactory supports webhooks for selected repository or JFrog Platform events, but coverage depends on the event, edition, and configuration. Martini can receive the notification, validate and deduplicate it, and retrieve current artifact or build details so the webhook payload is not treated as the sole source of truth.

How does Martini synchronize Artifactory artifacts and metadata?

Martini can run API-led or scheduled workflows that retrieve artifact, property, repository, or build data through REST APIs and AQL. The workflow maps the data to a canonical model, writes it to a target system, and uses watermarks, stable identifiers, checksums, or upsert logic to avoid repeated processing.

How are errors, retries, duplicates, and large transfers handled?

Martini workflows can validate inputs, apply bounded retries with backoff for transient HTTP failures, log workflow context, and route permanent failures for review. Idempotency can use immutable paths, existence and checksum checks, stable build identifiers, and webhook event keys. Large files require appropriate timeout, memory, streaming, and concurrency settings.