
QUANTUMDESK
Post-quantum crypto API · Solana launches · not audited
C:\\QUANTUM\\DOCS
API documentation
Generated from the endpoints that actually exist. Private keys and shared secrets are never returned.
| GET | /api/v1/health | Live self-test (ML-DSA-65 sign/verify, ML-KEM-768 roundtrip). | available |
| GET | /api/v1/algorithms | Supported algorithms and per-operation status. | available |
| POST | /api/v1/signatures/verify | { algorithm, message, signature, publicKey } (base64) → { valid } | available |
| POST | /api/v1/kem/encapsulate | { algorithm: "ML-KEM-768", publicKey } → { cipherText, sharedSecretFingerprint } | available |
| POST | /api/v1/keys | Create a server-held key | planned |
| POST | /api/v1/signatures/sign | Sign with a server-held key | planned |
| POST | /api/v1/kem/decapsulate | Decapsulate with a server-held key | planned |
| GET | /api/v1/usage | Per-project usage | planned |
- 400 INVALID_BODY — not JSON or over 64 KB
- 400 VALIDATION_ERROR — unknown algorithm or non-base64 field
- 400 INVALID_PUBLIC_KEY — wrong ML-KEM-768 key size (must be 1184 bytes)
- 503 — health self-test failed
- Every response carries a requestId (also in the x-request-id header).
- Planned endpoints need API keys and encrypted key storage; they return nothing until built. No HSM is used. No independent audit has been done.
curl -X POST https://desktop95.fun/api/v1/signatures/verify \
-H "Content-Type: application/json" \
-d '{"algorithm":"ML-DSA-65","message":"aGVsbG8=","signature":"<b64>","publicKey":"<b64>"}'import { ml_dsa65 } from "@noble/post-quantum/ml-dsa.js";
const b64 = (b) => btoa(String.fromCharCode(...b));
const { publicKey, secretKey } = ml_dsa65.keygen();
const msg = new TextEncoder().encode("hello");
const sig = ml_dsa65.sign(msg, secretKey);
const r = await fetch("/api/v1/signatures/verify", { method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({ algorithm: "ML-DSA-65", message: b64(msg), signature: b64(sig), publicKey: b64(publicKey) }) });
console.log(await r.json()); // { valid: true, requestId, ms }import requests
r = requests.get("https://desktop95.fun/api/v1/algorithms")
print(r.json())