QuantumShieldOpen workspace

Quantum Shield Developer Documentation

Quick start

Open /app, create a workspace and run an Ethereum or Base assessment. The pilot uses read-only public account data. Create a server-side API key in the API keys tab when you need an integration. Copy the workspace ID as well. A read key retrieves records; a write key also creates assessments and manages watchlists. Neither key grants administrator access.

The private hosted site requires a separate platform service credential for non-browser access. Do not treat an application API key as a way around private sharing. Keep both credentials on a trusted server. API access for external customers requires a deliberate production identity and access design before launch.

JavaScript SDK

Download the SDK package from /downloads/quantum-shield-sdk.zip. It has no runtime dependencies and includes TypeScript declarations. The package is local/private; it has not been published to npm.

import { QuantumShield } from './sdk/index.mjs';
const client = new QuantumShield({
  baseUrl: process.env.QUANTUM_SHIELD_URL,
  apiKey: process.env.QUANTUM_SHIELD_API_KEY,
  workspaceId: process.env.QUANTUM_SHIELD_WORKSPACE_ID,
  siteAccessToken: process.env.QUANTUM_SHIELD_SITE_ACCESS_TOKEN
});
const report = await client.assess('ethereum', '0x0000000000000000000000000000000000000000');
console.log(report.findings, report.coverage);

Never run this secret-bearing example in a browser. The SDK exposes assess, reports, report, watches, watch, check, pause, removeWatch, alerts, markRead and overview. It uses a 60-second request timeout and does not automatically retry mutations. If a timeout leaves the result uncertain, inspect report history before submitting again. See the machine-readable schema at /openapi.json.

Request contract

Every workspace request includes X-Workspace-Id. Server integrations additionally use Authorization: Bearer qs_.... Private Sites access additionally uses OAI-Sites-Authorization: Bearer .... Browser identity comes from platform sign-in, and browser mutations must have matching Origin. All mutation bodies are JSON. API errors return error.code and error.message.

Endpoints

Report meaning

The current method checks network identity, latest-block consistency, account bytecode, nonce and native balance. Code classifies a contract, an EIP-7702 delegation marker, or an externally owned/unused address. It does not audit bytecode. Nonce is an activity indicator; it does not prove that a public key has been recovered. A received-funds-only address or unused address is not certified safe. Reports keep public-key exposure and signing policy unknown rather than inventing a rating.

Findings include title, severity, evidence and recommendation. The report includes its methodology version, observation time, source block, coverage and limitations. It has no risk percentage. The map and illustrative report on the marketing page are demos, not live security intelligence.

Integration and payment status

Ethereum and Base are configured against shared public RPC for pilot use. Provider limits and availability may vary. Switch to a vetted service with agreed quotas before commercial use. Payments are deferred. Email delivery is not implemented. Automatic monitoring requires verified scheduler activation; manual checks are usable now. Quantum Vault, contract audit, signature recovery and full-history indexing are not implemented.

Operational setup

See the downloadable Operations guide for authentication boundaries, migrations, scheduler configuration, roles, error behavior and release gates. Use the Roadmap document for the commercial launch checklist. API credentials must never be committed, placed in query strings or included in support screenshots.