Skip to content

Developer portal

API Guide — PQC Readiness

Assess cryptographic inventory, monitor drift on a schedule, and export independently verifiable evidence.

Last updated: 2026-06-09

Core endpoints

POST /pqc/scan

Run Q-Day scan: inventory, Mosca risk, remediation backlog, handshake proof, report.

GET /pqc/report/{scanId}

Download migration report as json, csv, cbom, pdf, bundle, executive, board, or auditor formats.

GET /tenant/me

Return tenant identity, active role, and enabled feature entitlements.

GET /tenant/scans

List recent tenant scans with lifecycle status and report availability.

GET /health

GA liveness probe for platform uptime checks.

Assess flow

Typical integration

1. POST /pqc/scan (Idempotency-Key optional)
2. GET  /pqc/scan/{scanId} until status=success
3. GET  /pqc/report/{scanId}?format=pdf|json|cbom|bundle
4. GET  /pqc/verify/{scanId} (public, no API key)
5. POST /tenant/scans/{scanId}/share for auditor passport
Full Assess workflow →

Monitor tier

Scheduled scans via POST /tenant/schedules, drift alerts via tenant settings, and SIEM export via signed webhooks (webhooks guide).

Pilot endpoint

Base URL: https://api.qtangl.com

Environments guide →