Skip to main content

Verifiable Credentials REST (testbed)

The package itself ships no server. The pqc.rustykey.me testbed wraps these loaders in Next.js route handlers so you can produce W3C VC data-integrity proofs over HTTP.

All endpoints are server-side (runtime: "nodejs") JSON.

POST /api/pqc/vc/sign

One-shot: fresh keypair → canonicalize → hash → proof.

FieldTypeDescription
documentobjectUnsecured W3C credential payload
algorithmstringSee table below
dataset_canonicalization"rdfc" | "jcs"RDF Dataset Canonicalization or JSON Canonicalization Scheme

Algorithms: SQIsign-L1 / L3 / L5, mldsa44, falcon512, slhdsa128 / 192 / 256.

curl -X POST https://pqc.rustykey.me/api/pqc/vc/sign \
-H "Content-Type: application/json" \
-d '{
"document": { "@context": ["https://www.w3.org/ns/credentials/v2"], "type": ["VerifiableCredential"] },
"algorithm": "slhdsa128",
"dataset_canonicalization": "rdfc"
}'

POST /api/pqc/vc/proof

Lower-level pipeline / BYO keys:

  • Proof pipelineunsecuredDocument, family (sqisign | mldsa | falcon | slhdsa), level (l1 | l3 | l5), canonicalization (rdfc | jcs), plus publicKeyHex / secretKeyHex
  • Sign-onlyhashDataHex + family/level/keys

:::note Parameter shapes differ between endpoints /sign takes a single algorithm string (e.g. mldsa44, SQIsign-L1), whereas /proof takes family and level separately (e.g. family: "mldsa", level: "l1"). Generate a keypair with PUT /api/pqc/vc/proof (below) first, then paste publicKeyHex / secretKeyHex into the pipeline call. :::

curl -X POST https://pqc.rustykey.me/api/pqc/vc/proof \
-H "Content-Type: application/json" \
-d '{
"unsecuredDocument": { "@context": ["https://www.w3.org/ns/credentials/v2"], "type": ["VerifiableCredential"] },
"family": "slhdsa",
"level": "l1",
"canonicalization": "jcs",
"publicKeyHex": "PASTE_FROM_KEYGEN",
"secretKeyHex": "PASTE_FROM_KEYGEN"
}'

PUT /api/pqc/vc/proof

Keygen: { "family": "slhdsa", "level": "l1" }publicKeyHex / secretKeyHex.

curl -X PUT https://pqc.rustykey.me/api/pqc/vc/proof \
-H "Content-Type: application/json" \
-d '{ "family": "slhdsa", "level": "l1" }'

Selective Disclosure (sqisign1-sd-2024)

Interactive UI: https://pqc.rustykey.me/#vc-di-quantum-resistant-sd

Completes the W3C VC-DI Quantum-Resistant SD appendix for SQIsign-I. HMAC salts / saltedHashes / mandatoryHash / labelMap are the shared Category‑1 common outputs (same as ML-DSA / Falcon / SLH). Only the SQIsign-specific proofHash, signature, and CBOR proofValues are suite-private.

Responses are byte-stable: the JSON fields below are the exact strings proposed for the draft examples (no regeneration on each request).

One curl for W3C reviewers (copy-paste)

Paste this into a terminal. The JSON body is large; that is intentional — it contains the full suggested appendix examples so reviewers can confirm byte-for-byte equality against a proposed draft edit.

curl -sS 'https://pqc.rustykey.me/api/pqc/vc/sd?cryptosuite=sqisign1-sd-2024' | jq .

(jq is optional; omit | jq . if you only want the raw JSON.)

Equivalent POST (same golden payload via action: "appendix"):

curl -sS -X POST https://pqc.rustykey.me/api/pqc/vc/sd \
-H "Content-Type: application/json" \
-d '{"cryptosuite":"sqisign1-sd-2024","action":"appendix"}' | jq .

JSON → draft example map

Response fieldMaps to draft
table13 / appendix.table13Table 13 cryptosuite row (sqisign1-sd-2024, SQIsign-I, 148)
proofHash / appendix.example34ProofHashExample 34 SD Base Hashing proofHash (64 hex)
signature / appendix.example40SignatureExample 40 PQC Signatures entry (296 hex / 148 bytes)
baseDocumentExample 37A Base VC (includes proof.proofValue)
derivedDocumentExample 43A Derived VC (includes proof.proofValue)
baseProofValue / derivedProofValueStandalone multibase u… strings (same as the documents’ proof.proofValue)
matchesGolden.*Always true for this GET/appendix path (fixtures, not live re-sign)

Optional extractors (still one request):

# Example 34 proofHash only
curl -sS 'https://pqc.rustykey.me/api/pqc/vc/sd?cryptosuite=sqisign1-sd-2024' \
| jq -r '.proofHash'

# Example 40 signature only
curl -sS 'https://pqc.rustykey.me/api/pqc/vc/sd?cryptosuite=sqisign1-sd-2024' \
| jq -r '.signature'

# Full Base / Derived VCs (Examples 37A / 43A)
curl -sS 'https://pqc.rustykey.me/api/pqc/vc/sd?cryptosuite=sqisign1-sd-2024' \
| jq '.baseDocument, .derivedDocument'

GET /api/pqc/vc/sd

QueryDescription
cryptosuitesqisign1-sd-2024 (default), mldsa44-sd-2024, slhdsa128-sd-2024, or falcon512-sd-2024

POST /api/pqc/vc/sd

FieldTypeDescription
cryptosuitestringSame values as GET
action"appendix" | "issue-base" | "derive" | "verify"Default appendix. Use appendix (or GET) for the byte-stable W3C check; other actions run the live pipeline and may set matchesGolden from recomputation.