How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Venafi CodeSigning HSM API

This API allows you to request digital signing of software and manage signing, authentication, and encryption keys.This API requires the CyberArk Code Sign Manager product.

Venafi CodeSigning HSM API is one of 58 APIs that Venafi publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include CodeSigning HSM API. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.

This API exposes 10 operations across 10 paths, and defines 22 schemas. It is described by OpenAPI 3.2.0, at version 26.1.1.

Requests are made against 3 base URLs: /, https://REPLACEdnsnameME/, https://{dnsname}/.

10 operations 10 paths 22 schemas 1 GET9 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
26.1.1
Base URL
https://api.venafi.cloud
Authentication
HTTP Bearer
Resource Areas
1

Authentication & Security 1

Venafi CodeSigning HSM API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (AccessToken). By default, every request must be authenticated.

Paths & Operations 10

Across 10 paths, the API surfaces 10 operations — 1 GET, 9 POST. Each is listed below with its method, path, parameters, and response codes.

CodeSigning HSM API 10

This API allows you to request digital signing of software and manage signing, authentication, and encryption keys. This API requires the CyberArk Code Sign Manager product.

POST
/vedhsm/api/signjwt
Signs JSON Web Token
Venafi_Web_Hsm_HsmAPI_HandleSignJWT body → 200403400401
GET
/vedhsm/api/IsHsm
Verify HSM Server Info
Venafi_Web_Hsm_HsmAPI_IsAuthServer → 200403400401
POST
/vedhsm/api/sign
Sign Data
Venafi_Web_Hsm_HsmAPI_HandleSign body → 200403400401
POST
/vedhsm/api/decrypt
Decrypts Data
Venafi_Web_Hsm_HsmAPI_HandleDecrypt body → 200403400401
POST
/vedhsm/api/derive
Derives a Key
Venafi_Web_Hsm_HsmAPI_HandleDerive body → 200403400401
POST
/vedhsm/api/getgpgpublickey
Get GPG public key
Venafi_Web_Hsm_HsmAPI_HandleGetGpgPublicKey body → 200403400401
POST
/vedhsm/api/storeobject
Stores a key within an environment
Venafi_Web_Hsm_HsmAPI_HandleStoreObject body → 200403400401
POST
/vedhsm/api/getchain
Get Certificate Chain
Venafi_Web_Hsm_HsmAPI_HandleGetChain body → 200403400401
POST
/vedhsm/api/getobjects
Get Objects
Venafi_Web_Hsm_HsmAPI_HandleGetAll body → 200403400401
POST
/vedhsm/api/csctelemetry
Code Sign Client Telemetry
Venafi_Web_Hsm_HsmAPI_HandleTelemetry body → 200403400401

Schemas 22

The contract defines 22 schemas that model the data the API accepts and returns. The most detailed are Web_Hsm_HsmCryptoRequest_sign (14 properties), Web_Hsm_HsmTelemetryRequest (7 properties), Web_Hsm_HsmStoreRequest_storeobject (6 properties), Web_Hsm_HsmObjectRequest_getobjects (6 properties). Each schema is shown below with its type and property counts.

Web_Hsm_HsmJWTResponse_signjwt
object
2 properties
Web_Hsm_HsmCryptoRequest_decrypt
object
2 properties 2 required
Web_Hsm_HsmObjectResponse_getobjects
object
5 properties
Web_Hsm_HsmCryptoRequest_sign
object
14 properties 6 required
Web_Hsm_HsmCryptoResponse
object
Data object for a cryptographic operation response.
5 properties
Web_Hsm_HsmJWTRequest_signjwt
object
5 properties 5 required
Web_Hsm_HsmStoreRequest_storeobject
object
6 properties 6 required
Web_Hsm_HsmBaseResponse_IsHsm
object
4 properties
Web_SDK_Authentication_OAuthError
object
REST OAuth Error Response
2 properties
Web_Hsm_HsmGpgResponse_getgpgpublickey
object
4 properties
Core_Cryptography_Cryptoki_CryptokiObjectType
integer
0: Data 1: Certificate 2: PublicKey 3: PrivateKey 4: SecretKey 5: HwFeature 6: DomainParameters 7: Mechanism 8: OtpKey
Web_Hsm_HsmObjectRequest_getobjects
object
6 properties
Web_Hsm_HsmCryptoRequest_derive
object
3 properties 3 required
Core_Cryptography_Cryptoki_CryptokiKeyType
integer
0: RSA RSA Asymmetric Key 1: DSA DSA (Digital Signature Algorithm) Asymmetric Key 2: DH The Diffie-Hellman Asymmetric Key 3: EC EC (Elliptic-Curve) Asymmetric…
Web_Hsm_HsmObjectResponse_getchain
object
3 properties
Web_Hsm_HsmTelemetryRequest
object
Data object for sending code sign client telemetry.
7 properties
Web_Hsm_HsmTelemetryResponse
object
Data object for a telemetry submission response.
2 properties
Web_Hsm_HsmGpgRequest_getgpgpublickey
object
2 properties 1 required
Web_Hsm_HsmObjectRequest_getchain
object
1 property
Web_Hsm_HsmCryptoResponse_decrypt
object
4 properties
Web_Hsm_HsmCryptoResponse_derive
object
4 properties
Web_Hsm_HsmStoreResponse
object
Data object for an object retrieval response.
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

venafi-codesigning-hsm-api-api-openapi.yml Raw ↑

Other APIs Venafi publishes across the network.

Venafi Access Management APIs API
Venafi AlgorithmSelector APIs API
Venafi Application API
Venafi Authentication Server APIs API
Venafi Certificate Approvals API
Venafi Certificate Auto-renewal Monitoring API
Venafi Certificate Discovery API
Venafi Certificate Expiration Reports API
Venafi Certificate Import API
Venafi Certificate Installations API
Venafi Certificate Inventory Monitoring API
Venafi Certificate Management APIs API
Where this information came from

This is an independent, third-party profile of Venafi CodeSigning HSM API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.