Skip to content

Identity

Identity material and, more importantly, whether the issuer still stands behind it. A certificate is minted for ten years and its parent signature never expires, so possession proves nothing about current standing — only the status endpoint does.

GET /api/certificate/{id}

One identity's public certificate

Unauthenticated

Callable with no credential.

Parameters

Name In Required Notes
id path yes

Responses

Status Meaning
200 The identity's public material.
404 No such resource, or the caller may not see it.

Response fields

Field Type Notes
id string
name string
certificate string
fingerprint string
parentSignature string
domainAtIssue string The domain this identity was issued under.

GET /api/identities/{fingerprint}/status

Whether the issuer still stands behind an identity

Unauthenticated

Callable with no credential.

This server's signed, timestamped answer about one fingerprint. It is the piece a certificate cannot carry, and the only thing that distinguishes a current holder from one who was removed.

The answer is signed by the root key rather than trusted on TLS alone: the caller has already pinned that key through DNS, so the statement needs no separate trust in this endpoint and a proxy cannot rewrite it.

The payload is a JSON envelope whose first field is type: identity-status-v1. That separator is load-bearing — without it, a signature over a bare fingerprint would itself be a forged parent signature, and this endpoint would be a signing oracle.

unknown is not revoked. A restored backup answers unknown about identities that are perfectly valid, and a verifier must not treat the two the same.

Parameters

Name In Required Notes
fingerprint path yes Lowercase hex SHA-256 fingerprint.

Responses

Status Meaning
200 A signed assertion. Cacheable for exactly as long as the signature claims validity, so a cache can never outlive the statement in it.
400 Refused, with a named reason.
429 Too many attempts. Password gates, probes and challenges are limited per client, so a slug cannot be brute-forced.

Response fields

Field Type Notes
payload string Base64url JSON. Its first field is type: identity-status-v1, which is what stops the endpoint being a signing oracle.
signature string Root key signature over the payload.

POST /api/verify-peer

Walk another server's trust chain

Auth: ApiKey, Session

Asks this server to verify a peer domain end to end — DNS TXT, served root key, and the peer's own answer about the identity's standing.

Request body

application/json

Field Type Notes
domain string

Responses

Status Meaning
200 The verdict.
429 Too many attempts. Password gates, probes and challenges are limited per client, so a slug cannot be brute-forced.

GET /api/challenges/{scope}/{slug}

Issue a handshake nonce

Unauthenticated

Callable with no credential.

Returns a single-use nonce to sign when a share or request requires a proven identity. The signature is submitted with the resolve or the response; a spent nonce is refused.

Parameters

Name In Required Notes
scope path yes Which kind of grant the challenge is for.
slug path yes

Responses

Status Meaning
200 A nonce to sign.
429 Too many attempts. Password gates, probes and challenges are limited per client, so a slug cannot be brute-forced.