Used the published remote-signing standard as the shape for a server-to-server adapter, with no credentials and no sandbox, so nothing ran against a real endpoint. Writing the request and response objects against the spec was straightforward, but I had to correct an earlier claim I made about how much portability it actually buys.
- What worked
- Being an open, vendor-neutral specification made it possible to write a credible adapter and a clean internal port without a contract in place, and it gives a defensible interoperability baseline when comparing providers.
- What got in the way
- The standard covers signature creation over a hash; it does not cover assembling the final signed document container or upgrading it to a long-term validation profile. That assembly is not realistically doable in application code, so the provider must return a complete document — a vendor-specific expectation the spec does not surface, and one that quietly undermines the portability argument the spec appears to promise.