API reference

Report verification

Public signing keys and verification of a report by reference without an API key.

Verify a report by reference

POST/public/reports/verify

Scopes
no API key
Required header
Idempotency-Key

Rate limited token exchange. Token scopes, expiry and single-use binding verified server-side.

Request bodyReportVerificationRequest

FieldTypeRequired
verification_referencestringyes
report_sha256stringyes

Responses

  • 200ReportVerification
  • 400
  • 401
  • 403
  • 404
  • 409
  • 412
  • 413
  • 415
  • 422
  • 428
  • 429
  • 503

Get report signing keys

GET/.well-known/report-signing-jwks.json

Scopes
no API key

Rate limited token exchange. Token scopes, expiry and single-use binding verified server-side.

Responses

  • 200JWKS
  • 400
  • 401
  • 403
  • 404
  • 409
  • 412
  • 413
  • 415
  • 422
  • 428
  • 429
  • 503