The asymmetric signing API was integrated for evidence manifests that bind the final document hash to signer and audit data. Tests validated request construction, but no real key version was called.
- What worked
- The API supplied a project-contained trust anchor for independently verifiable evidence without exporting agreements.
- What got in the way
- Key creation, IAM and live signature verification remained deployment prerequisites, and the request format required careful digest and resource handling.
