BẢO MẬT API

Xác thực, phân quyền và độ tin cậy của yêu cầu

Mỗi thao tác phải nêu rõ định danh client, ngữ cảnh người dùng, scope, liên kết tenant/RP và cơ chế bảo vệ transport/yêu cầu.

01

Các đường xác thực

PathUseControls
OAuth2 client credentialsService-to-serviceClient ID, scope, audience and rotation
OIDC user contextUser-delegated flowsSubject, authentication context and consent
mTLSHigh-assurance service identityCertificate chain, SAN and revocation
Signed requestSelected channelsTimestamp, nonce, body digest and key ID
WebAuthn assertionSigner approvalChallenge, origin, RP ID, credential and counters

02

Mô hình scope

ScopePurpose
signing.requestCreate/read signing requests
signing.approveSubmit/verify signer approval
signing.activateIssue or consume signature activation
signing.executeExecute approved signature operations
evidence.readRead evidence and verification results
evidence.renewRequest evidence renewal
admin.providersManage approved CA/provider routes

03

Quy tắc xử lý bí mật

  • No access tokens in URLs or logs.
  • Credential IDs and signer identifiers masked outside the trust boundary.
  • SAD values short-lived, purpose-bound and never returned to unauthorized clients.
  • mTLS private keys stored in approved key protection.
  • Webhook secrets rotated and versioned.