The API was selected and isolated behind a configurable adapter for qualified PAdES signing, identity verification and retrieval of evidence. Public information established a strong compliance fit, but the detailed API schema and credentials were available only after account setup, so production interoperability was not verified.
- What worked
- The published offering clearly addressed qualified signatures, French operation and hosting, and remote identity verification. Those capabilities aligned closely with the portal's legal and localization constraints.
- What got in the way
- The private API contract prevented validation of exact request and response fields against the live service. The implementation therefore still requires vendor credentials and schema confirmation before activation.
