Is Parmana's signing key stored securely?
Is Parmana's signing key stored securely?
Today it’s a PEM file on disk, read by
FileKeyProvider, the only implemented key
provider. There’s a live incident on record: an earlier committed key was publicly
exposed and is permanently compromised (rotated 2026-07-05). KMS/HSM custody is
designed but not built, see Cryptography and
Roadmap.Which SDK should I use?
Which SDK should I use?
Either — both are [AVAILABLE] and actively maintained. Python’s models are generated
from the same TypeScript domain types the server uses, drift-guarded in CI; the
TypeScript SDK’s models are hand-maintained but spot-checked against the real schemas.
Both raise a typed exception per HTTP status and are tested against a real running
server, not just mocks. The TypeScript package is private and not published to a
registry (
@parmana/sdk in typescript/package.json, install from a local path or git
reference); Python installs with pip install -e ./python. See Python
SDK and TypeScript SDK.Can I use Go / Java / .NET?
Can I use Go / Java / .NET?
Not via an SDK, none exists. Call the REST API directly;
it’s 14 small, documented routes. See Other Languages.
Does Parmana support post-quantum signatures?
Does Parmana support post-quantum signatures?
Yes, ML-DSA-65 (FIPS 204), selectable via
PRIMARY_SIGNATURE_PROVIDER=dilithium3, real and
tested. Requires Node ≥ 24. Its signatures are randomized, not deterministic, don’t
build tooling that assumes otherwise. See Cryptography.What does 'replay' actually do?
What does 'replay' actually do?
Two different things share the name, and neither is what you might assume. See
Replay, this is worth reading in full before relying on either.
Is there an 'Execution Permit'?
Is there an 'Execution Permit'?
Not anymore, under that name. An early prototype used it; it was deleted the same
session it was replaced by the current
SignedExecutionAuthorization + Execution
Gateway architecture, which is what actually ships. See Glossary.Is this API authenticated?
Is this API authenticated?
Yes. Every route except
/health, /ready, /openapi.yaml, and /documentation
requires a bearer key and fails closed with a 401 if it’s missing or wrong
(createCallerAuthenticator.ts, commit 5c688b4). See
Authentication. This is a separate question from
whether the underlying business action was authorized, see
Security for that boundary.