QNSI

Platform capability

Developer Platform & Secure Delivery

Integrate QNSI through first-party SDKs, REST, CLI, MCP, WebSockets, browser patterns, source scanning, code signing, and secure build-pipeline surfaces.

Buyer outcome

Let application and platform teams adopt governed cryptography through stable interfaces without embedding algorithm lifecycle decisions throughout the codebase.

Published SDKs · operation support varies by service

For Developers · Platform engineering · DevSecOps · Security architecture

Evidence boundary

TypeScript, Python, Rust, JVM/Android, Go, and MCP distribution surfaces are published or documented. Package availability does not prove every SDK method, backend route, cryptographic effect, audit effect, or deployment behavior.

Capability map

What developer platform covers

Each item is a source-backed or deployment-bounded capability, not an implied certification or universal runtime guarantee.

TypeScript/Node, Python, Go, Rust, and JVM/Android SDK surfaces
REST API and OpenAPI documentation
QNSI CLI with local source-code discovery
MCP tools for tenant-scoped engineering operations
WebSocket and event-stream integration
Browser reference architecture, code-signing, and build-pipeline patterns

Operating model

How the capability fits into an accountable workflow

01

Choose the interface

Select the supported SDK, REST, CLI, MCP, browser, or event-stream surface for the workload.

02

Authenticate and scope

Bind the client to a tenant, identity, audience, entitlement, and least-privilege operation set.

03

Call a governed service

Use stable resource identifiers while server-side policy selects permitted operations and algorithms.

04

Test negative paths

Verify authorization failures, downgrade rejection, rotation, revocation, retry, audit, and unavailable-service behavior.

Integration & assurance

Connect the capability, then verify the exact boundary

Integration surfaces

TypeScript/NodePythonGoRustJVM/AndroidMCPRESTWebSockets

Frequently asked questions

Developer Platform questions

Does every SDK expose every backend operation?

No. The packages share wire contracts and common service clients, but language, version, backend route, entitlement, and deployment support can differ. Verify the published package version and exact operation required.

Is the browser SDK proof of production PQC transport?

No. A browser package or reference architecture does not prove the public edge negotiated a PQC or hybrid group. Transport claims require an observed handshake and deployment-specific evidence.

Next step

Evaluate the capability against your actual environment

Start with the public evidence, then scope the exact services, integrations, custody, deployment, and assurance required. QNSI will not convert source presence into a production claim without evidence.