Developer portal
GET /pqc/scenarios
List PQC scan scenarios (bank, gov contractor, healthcare).
GET /pqc/scenariosAuth: API key required
Summary
List PQC scan scenarios (bank, gov contractor, healthcare).
Example
Response
{
"status": "success",
"scenarios": [
{
"id": "bank-tls-inventory",
"title": "Regional bank TLS inventory",
"summary": "Board mandate to inventory RSA/ECDSA exposure across customer-facing TLS before 2030 NIST deadlines.",
"target": {
"domain": "api.regionalbank.example",
"ports": [
443,
8443
],
"persona": "CISO, regional bank",
"organization": "Regional Bank Holdings",
"mandate": "NSM-10 / NIST IR 8547 PQC migration program"
},
"manualBaseline": {
"inventoryWeeks": 8,
"assetsFound": 42,
"quantumVulnerable": 38,
"readinessScore": 18,
"summary": "Spreadsheet inventory from Q1 is already stale; shadow APIs were missed."
},
"fixtureAssetIds": [
"tls-api-bank",
"tls-auth-bank",
"jwks-oidc",
"ssh-bastion",
"email-mx",
"code-sign-legacy",
"discovery-ct-api"
]
},
{
"id": "gov-contractor-cmmc",
"title": "Gov contractor CMMC readiness",
"summary": "FedRAMP/CMMC assessor requires cryptographic inventory with remediation backlog before contract renewal.",
"target": {
"domain": "portal.defense-prime.example",
"ports": [
443,
22
],
"persona": "Compliance lead, defense contractor",
"organization": "Defense Prime Integrator",
"mandate": "CMMC Level 2 / CNSA 2.0 alignment"
},
"manualBaseline": {
"inventoryWeeks": 6,
"assetsFound": 28,
"quantumVulnerable": 24,
"readinessScore": 22,
"summary": "Manual SSP spreadsheet; no JWKS or SSH host key coverage."
},
"fixtureAssetIds": [
"tls-api-bank",
"jwks-oidc",
"ssh-bastion",
"code-sign-legacy"
]
},
{
"id": "healthcare-insurer-hndl",
"title": "Healthcare insurer HNDL exposure",
"summary": "Legal and security teams stress-test harvest-now-decrypt-later risk on long-retained PHI transport encryption.",
"target": {
"domain": "member.healthshield.example",
"ports": [
443,
25,
993
],
"persona": "CISO, healthcare insurer",
"organization": "HealthShield Mutual",
"mandate": "HIPAA + board Q-Day readiness"
},
"manualBaseline": {
"inventoryWeeks": 10,
"assetsFound": 55,
"quantumVulnerable": 51,
"readinessScore": 15,
"summary": "Third-party email and legacy signing keys not in last inventory cycle."
},
"fixtureAssetIds": [
"tls-auth-bank",
"email-mx",
"jwks-oidc",
"code-sign-legacy",
"discovery-ct-api"
]
}
]
}Try it live
Paste your tenant API key to call the live API with your credentials. Leave blank to use the public sandbox key when configured, or click “Show example response” for the static fixture below.
Response
| Field | Type | Required | Description |
|---|---|---|---|
| status | "success" | Yes | Operation result. |
| scenarios[] | ScanScenario[] | Yes | Demo scan personas with targets and manual baselines. |
| scenarios[].id | string | No | Scenario slug for POST /pqc/scan. |
| scenarios[].target | ScanTarget | No | Default domain, ports, and persona. |
| scenarios[].manualBaseline | ManualBaseline | No | Spreadsheet-era baseline for scoreboard comparison. |
| scenarios[].fixtureAssetIds | string[] | No | Asset ids included when useFixture is true. |
Errors
| Code | Meaning | Typical cause | Suggested fix |
|---|---|---|---|
| 400 | Bad request | Malformed JSON or missing required headers. | Validate Content-Type and JSON syntax before retrying. |
| 401 | Unauthorized | Missing or invalid API key in Authorization, x-api-key, or query param. | Send Bearer <key> or x-api-key with a valid tenant token. |
| 402 | Payment required | Feature not included in current entitlements (e.g. Monitor schedules, remediation automate). | Upgrade via billing portal or contact sales for enterprise tier. |
| 403 | Forbidden | Valid key but insufficient role (viewer attempting write) or wrong admin key. | Use operator or admin role key; check RBAC matrix. |
| 404 | Not found | Scan, schedule, share link, or resource id does not exist or expired. | Verify id and tenant scope; share links expire per expiresHours. |
| 413 | Payload too large | CBOM ingest or upload exceeds size limit. | Split large CBOM documents or use cloud pull integration. |
| 422 | Unprocessable entity | Invalid payload shape, unsupported scenario, or infeasible constraints. | Fix field errors in response detail; relax constraints and retry. |
| 429 | Too many requests | Per-key rate limit exceeded (default 300 requests per minute) or public endpoint limit. | Backoff with jitter; cache results; request higher limit for production. |
| 500 | Internal server error | Unexpected backend failure; includes requestId in response. | Retry with exponential backoff; contact support with requestId if persistent. |
| 503 | Service unavailable | Persistence disabled, auth DB unreachable, or admin API not configured. | Retry shortly; schedules require Postgres persistence enabled. |
| 501 | Not implemented | Problem type not yet supported on live solver path (routing, allocation). | Use type schedule for live jobs, or follow Labs roadmap. |
See the full errors reference.
Found an issue? Report documentation feedback