The API was integrated behind an OAuth-backed adapter for ordered QES sessions, final signed-document retrieval, and signature-count checks. The documentation exposed the required workflow, but vendor-specific identifiers, commercial provisioning, and exact production configuration still require an approved account.
- What worked
- The documented concepts supported multiple signers, explicit predecessor dependencies, callbacks, PAdES output, and audit evidence, which closely matched the workflow.
- What got in the way
- No live account or credentials were available, so authentication, provider configuration, and real signing behavior could not be exercised or rated for reliability.
