POST /pqc/scan
Run Q-Day scan: inventory, Mosca risk, remediation backlog, handshake proof, report.
Developer portal
Assess cryptographic inventory, monitor drift on a schedule, and export independently verifiable evidence.
Last updated: 2026-06-09
Run Q-Day scan: inventory, Mosca risk, remediation backlog, handshake proof, report.
Poll live scan job status and timeline.
Download migration report as json, csv, cbom, pdf, bundle, executive, board, or auditor formats.
Public verification endpoint for a scan's published proof bundle.
Return tenant identity, active role, and enabled feature entitlements.
List recent tenant scans with lifecycle status and report availability.
Create recurring scan or cloud-pull schedule with notifications.
GA liveness probe for platform uptime checks.
Viewer, operator, and admin role matrix.
401, 402, 403, 404, 413, 422, 429, 500, 503.
1. POST /pqc/scan (Idempotency-Key optional)
2. GET /pqc/scan/{scanId} until status=success
3. GET /pqc/report/{scanId}?format=pdf|json|cbom|bundle
4. GET /pqc/verify/{scanId} (public, no API key)
5. POST /tenant/scans/{scanId}/share for auditor passportScheduled scans via POST /tenant/schedules, drift alerts via tenant settings, and SIEM export via signed webhooks (webhooks guide).
Base URL: https://api.qtangl.com
Environments guide →Found an issue? Report documentation feedback