# API reference

The API reference is generated from the OpenAPI 3.1 specification and lists authentication requirements, inputs, outputs and errors for each operation. The signing, certificate and encryption guides explain the sequence of calls before the endpoint details.

## Get the OpenAPI spec

Download the [OpenAPI specification](/docs/openapi.json), or import `https://securysign.com/docs/openapi.json` using **Import → Link** in Postman or **Import → URL** in Insomnia.

To generate a TypeScript client, run:

```bash
npx @openapitools/openapi-generator-cli generate \
  -i https://securysign.com/docs/openapi.json -g typescript-fetch -o ./securysign-client
```

## Try the API in your browser

The [API explorer](https://securysign.com/api/swagger) supports interactive requests. Choose **Authorize → signIn → Authorize** for operations on a signed-in account, or enter the approved RP client ID and secret under **rpBasic** for identity verification. Open an operation and select **Try it out** to enter its inputs.

## Base URLs

| Environment | API base | OpenID Connect (OIDC) issuer |
|---|---|---|
| Production | `https://securysign.com/api` | `https://securysign.com/auth/realms/signa` |
| Sandbox | `https://signa.dev.securysign.com/api` | `https://idp.dev.securysign.com/realms/signa` |

MIMI enrolment uses `https://mimi.ke` as its production issuer. A staging client is available from SecurySign on request.

Requests and responses use JSON unless an operation specifies another content type. Application API errors have an `error` field; OIDC token endpoints use the protocol's error fields. See [Credentials](#/docs/core-concepts#credentials) for authentication details and [Errors and rate limits](#/docs/errors) for recovery steps.
