✍ CODE SIGN

Artifact Signing

Supply chain artifact signing: ECDSA P-256 signatures on files, commits and container images. ECDSA P-256 is classical cryptography — not post-quantum.

Quick Example

curl -X POST https://sign-api.qntyx.io/keys/generate \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"key_name": "release-key"}'

API Base URL

https://sign-api.qntyx.io

Endpoints

MethodPathDescription
POST/keys/generateGenerate a signing key
POST/sign/fileSign an artifact — body: artifact_hash, artifact_name, key_id (also /sign/commit, /sign/container, /sign/batch)
POST/verify/hashVerify an artifact by hash — body: artifact_hash (or GET /verify/{signature_id})
GET/stats/Dashboard statistics

Authentication

All endpoints require a bearer token. See Authentication for details.

Dashboard

Manage this product visually at app-sign.qntyx.io

Marketing Page

Learn more at sign.qntyx.io