Trusted SIC signing
Request, approval, WebAuthn, activation, routing, signing, ASiC and evidence.
Open →QUANTUMSAFE API CENTER
The HTML documentation explains business purpose, state transitions, authorization, idempotency, callbacks, evidence and failure behavior. OpenAPI YAML/JSON and Postman are export formats—not the primary user journey.
01
Request, approval, WebAuthn, activation, routing, signing, ASiC and evidence.
Open →OAuth2/OIDC, mTLS, scopes, request signatures and tenant/RP identity.
Open →Signing states, cancellation, expiry, retry and partial verification.
Open →Subscription, signature validation, delivery, replay and retry.
Open →RFC 9457 problem details, rate limits, timeouts and retries.
Open →cURL, Java 21, C#, JavaScript and Python.
Open →Browser-local mock explorer with safe sample data.
Open →OpenAPI YAML/JSON, Postman and legacy architecture skeleton.
Open →02
| Control | Contract |
|---|---|
| Authorization | OAuth2 scope and/or mTLS identity by operation |
| X-Correlation-Id | End-to-end diagnostic and evidence correlation |
| Idempotency-Key | Required for create/activation/signing/packaging operations |
| X-Request-Timestamp | Freshness control where signed requests are enabled |
| X-Request-Signature | Optional/required by channel policy |
| traceparent | Distributed tracing without exposing sensitive payloads |
| application/problem+json | RFC 9457-style error response |