Artifact Signing
Supply chain artifact signing: ECDSA P-256 signatures on files, commits and container images. ECDSA P-256 is classical cryptography — not post-quantum.
curl -X POST https://sign-api.qntyx.io/keys/generate \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"key_name": "release-key"}'
https://sign-api.qntyx.io
| Method | Path | Description |
|---|---|---|
POST | /keys/generate | Generate a signing key |
POST | /sign/file | Sign an artifact — body: artifact_hash, artifact_name, key_id (also /sign/commit, /sign/container, /sign/batch) |
POST | /verify/hash | Verify an artifact by hash — body: artifact_hash (or GET /verify/{signature_id}) |
GET | /stats/ | Dashboard statistics |
All endpoints require a bearer token. See Authentication for details.
Manage this product visually at app-sign.qntyx.io
Learn more at sign.qntyx.io