🏛 CA

Certificate Authority

A private certificate authority for internal TLS and mTLS. Issues Ed25519 certificates; each CA key is labelled with what seeded it (QuantumRand, or the OS CSPRNG if QuantumRand was unavailable). CSR submission, issuance, revocation, CRL and OCSP.

Ed25519 is classical cryptography — this is not post-quantum. Most web browsers do not accept Ed25519 certificates, so use it for internal services, not public websites. There is no ACME support (certbot will not work).

Quick Example

curl -X POST https://ca-api.qntyx.io/certificates/issue \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json"

API Base URL

https://ca-api.qntyx.io

Endpoints

MethodPathDescription
POST/certificates/issueIssue a certificate
GET/certificates/List certificates
POST/csr/submitSubmit a CSR
POST/revoke/{serial}Revoke a certificate
GET/stats/Dashboard statistics

Authentication

All endpoints require a bearer token. See Authentication for details.

Dashboard

Manage this product visually at app-ca.qntyx.io

Marketing Page

Learn more at ca.qntyx.io