Developer portal
Data formats
PQC scan payloads, CycloneDX CBOM exports, ingest shapes, and webhook fields — before you integrate Assess, Monitor, and Convert.
Last updated: 2026-06-10
POST /pqc/scan request
GAStart a cryptographic inventory scan. Use fixture mode for deterministic demos; set useFixture false and provide target for live TLS discovery.
| Field | Type | Required | Description |
|---|---|---|---|
| scenarioId | string | No | Pre-built scan profile (TLS inventory, handshake proof, standards crosswalk). e.g. bank-tls-inventory |
| useFixture | boolean | No | When true, returns deterministic demo data without external network calls. e.g. true |
| target | string | null | No | Hostname or domain for live scans when useFixture is false. e.g. api.example.com |
| depth | string | null | No | Discovery depth hint: standard or extended chain walk. e.g. standard |
| seed | integer | No | Fixture randomness seed for reproducible demo output. e.g. 1234 |
| bundleSessionId | string | null | No | Optional session id when uploading a bundle via POST /pqc/upload-bundle first. |
Fixture scan (quickstart)
{
"scenarioId": "bank-tls-inventory",
"useFixture": true,
"seed": 1234
}- Send Idempotency-Key header on POST for safe retries.
- Schema: /docs/reference/schemas#pqc-scan-request
PQC scan response & report JSON
GAPoll GET /pqc/scan/{scanId} until status is complete, then fetch GET /pqc/report/{scanId}. The report embeds assets, Mosca scoring, and optional signature block.
| Field | Type | Required | Description |
|---|---|---|---|
| status | string | No | Job state: running, success, or error. e.g. success |
| scanId | string | No | Stable identifier for report, verify, and tenant history. e.g. scan-abc123 |
| assets[] | array | No | Discovered cryptographic assets with algorithm, host, vulnerability status. |
| mosca | object | No | HNDL timeline scoring: data shelf-life vs migration horizon (X + Y > Z). |
| scoreboard | object | No | Readiness summary counts by algorithm family and priority tier. |
| signature | object | No | ML-DSA-65 block with contentHash — verify independently at /verify. |
- Report formats: ?format=json|csv|cbom|pdf|bundle|executive|board|auditor
- Schema: /docs/reference/schemas#pqc-scan-response
CycloneDX CBOM export
GAGET /pqc/report/{scanId}?format=cbom returns CycloneDX 1.6 with cryptographic-asset components. Qtangl properties use the qtangl: namespace for scan provenance.
| Field | Type | Required | Description |
|---|---|---|---|
| bomFormat | string | No | Always CycloneDX for Qtangl exports. e.g. CycloneDX |
| specVersion | string | No | CycloneDX spec version. e.g. 1.6 |
| metadata.properties[] | array | No | qtangl:scanId, qtangl:scenarioId, qtangl:readinessScore, qtangl:targetDomain. |
| components[] | array | No | type cryptographic-asset entries with qtangl:algorithm, qtangl:keySize, qtangl:vulnerabilityStatus. |
| components[].properties[] | array | No | Host, port, kind (tls, code_signing, etc.), standards mapping tags. |
Sample ungated CBOM
- Import into CMDB/GRC via POST /pqc/cbom/ingest or tenant integrations.
- See CBOM aggregator guide for multi-source merge.
POST /pqc/cbom/ingest request
PilotPush an external CycloneDX document into the tenant CBOM aggregator. Include sourceLabel and verificationStatus for provenance.
| Field | Type | Required | Description |
|---|---|---|---|
| document | object | No | Full CycloneDX BOM JSON document. |
| sourceLabel | string | No | Human-readable source name (cloud provider, CLM, manual import). e.g. aws-kms-import |
| verificationStatus | string | No | verified | imported | unverified-source — affects conflict resolution weight. e.g. imported |
Minimal ingest body
{
"document": { "bomFormat": "CycloneDX", "specVersion": "1.6", "components": [] },
"sourceLabel": "manual-cmdb-export",
"verificationStatus": "imported"
}- Schema: /docs/reference/schemas#pqc-cbom-ingest-request
SIEM webhook v2 payload
GAMonitor tier webhooks emit drift and scan-complete events. Payload includes scan metadata, delta summary, and verify URL.
| Field | Type | Required | Description |
|---|---|---|---|
| event | string | No | Event type: scan.complete, drift.detected, remediation.verified, etc. e.g. drift.detected |
| scanId | string | No | Reference scan for report and verify links. |
| verifyUrl | string | No | Public verify link auditors can open without API credentials. |
| delta | object | No | Added/removed/changed assets since prior scan in scope. |
- HMAC-SHA256 signature in X-Qtangl-Signature header.
- Full spec: /docs/integrations/siem-webhook-v2
Report format query parameter
| Field | Type | Required | Description |
|---|---|---|---|
| format=json | query | No | Full machine-readable report for integrations. |
| format=cbom | query | No | CycloneDX CBOM export with qtangl: provenance properties. |
| format=pdf | query | No | Human-readable signed audit packet. |
| format=bundle | query | No | ZIP evidence bundle (report, CBOM, verify metadata). |
| format=csv | query | No | Flat asset table for spreadsheet workflows. |
Method honesty
Found an issue? Report documentation feedback