European Commission - EBSI / EBSI Intigriti


Target Policy
https://app.intigriti.com/api/core/researcher/programs/ebsi/ebsi
Structured Scope
  • Asset Identifier
    Asset Type
    Max Severity
  • Timestamp API

    Following endpoints of the [Timestamp API](https://api-pilot.ebsi.eu/docs/apis/timestamp/latest#/) are considered in-scope:

    1. [GET List hash algorithms](https://api-pilot.ebsi.eu/docs/apis/timestamp/latest#/operations/get-timestamp-v4-hash-algorithms)
    2. [GET Get a hash algorithm](https://api-pilot.ebsi.eu/docs/apis/timestamp/latest#/operations/get-timestamp-v4-hash-algorithms-hash-algorithm-id)
    3. [GET List timestamps](https://api-pilot.ebsi.eu/docs/apis/timestamp/latest#/operations/get-timestamp-v4-timestamps)
    4. [GET Get a timestamp](https://api-pilot.ebsi.eu/docs/apis/timestamp/latest#/operations/get-timestamp-v4-timestamps-timestampId)
    5. [GET List records](https://api-pilot.ebsi.eu/docs/apis/timestamp/latest#/operations/get-timestamp-v4-records)
    6. [GET Get a record](https://api-pilot.ebsi.eu/docs/apis/timestamp/latest#/operations/get-timestamp-v4-records-record-id)
    7. [GET List a record's versions](https://api-pilot.ebsi.eu/docs/apis/timestamp/latest#/operations/get-timestamp-v4-records-record-id-versions)
    8. [GET Get a version](https://api-pilot.ebsi.eu/docs/apis/timestamp/latest#/operations/get-timestamp-v4-records-record-id-versions-version-id)
    9. [POST JSON-RPC API](https://api-pilot.ebsi.eu/docs/apis/timestamp/latest#/operations/post-timestamp-v4-jsonrpc)

    Other
    medium
  • DID registry API

    Following endpoints of the [DID Registry API](https://api-pilot.ebsi.eu/docs/apis/did-registry/latest#/) are considered in-scope:

    1. [GET List identifiers](https://api-pilot.ebsi.eu/docs/apis/did-registry/latest#/operations/get-did-registry-v5-identifiers)
    2. [GET Get a DID document](https://api-pilot.ebsi.eu/docs/apis/did-registry/latest#/operations/get-did-registry-v5-identifier)
    3. [POST Perform actions in DID](https://api-pilot.ebsi.eu/docs/apis/did-registry/latest#/operations/get-did-registry-v5-actions)
    4. [POST JSON-RPC API](https://api-pilot.ebsi.eu/docs/apis/did-registry/latest#/operations/post-did-registry-v5-jsonrpc)

    Other
    medium
  • Authorisation API

    Following endpoints of the [Authorisation API](https://api-pilot.ebsi.eu/docs/apis/authorisation/latest#/) are considered in-scope:

    1. [POST Initiate a SIOP DID Auth request](https://api-pilot.ebsi.eu/docs/apis/authorisation/latest#/operations/post-authorisation-v2-authentication-requests)
    2. [POST Create a SIOP Session](https://api-pilot.ebsi.eu/docs/apis/authorisation/latest#/operations/post-authorisation-v2-siop-sessions)
    3. [POST Create an OAuth2 Session](https://api-pilot.ebsi.eu/docs/apis/authorisation/latest#/operations/post-authorisation-v4-oauth2-sessions)
    4. [GET OpenID Provider Metadata](https://api-pilot.ebsi.eu/docs/apis/authorisation/latest#/operations/get-v4-well-known-openid-config)
    5. [GET OpenID Provider's public keys](https://api-pilot.ebsi.eu/docs/apis/authorisation/latest#/operations/get-v3-jwks)
    6. [GET Presentation definition requirements](https://api-pilot.ebsi.eu/docs/apis/authorisation/latest#/operations/get-v3-presentation-definitions)
    7. [POST Token Endpoint](https://api-pilot.ebsi.eu/docs/apis/authorisation/latest#/operations/post-v3-token)

    Other
    medium
  • Trusted Issuers Registry API

    Following endpoints of the [Trusted Issuers Registry API](https://api-pilot.ebsi.eu/docs/apis/trusted-issuers-registry/latest#/) are considered in-scope:

    1. [GET List issuers](https://api-pilot.ebsi.eu/docs/apis/trusted-issuers-registry/latest#/operations/get-trusted-issuers-registry-v5-issuers)
    2. [GET Get an issuer](https://api-pilot.ebsi.eu/docs/apis/trusted-issuers-registry/latest#/operations/get-trusted-issuers-registry-v5-issuers-issuer)
    3. [GET List attributes](https://api-pilot.ebsi.eu/docs/apis/trusted-issuers-registry/latest#/operations/get-trusted-issuers-registry-v5-issuers-did-attributes)
    4. [GET Get an attribute](https://api-pilot.ebsi.eu/docs/apis/trusted-issuers-registry/latest#/operations/get-trusted-issuers-registry-v5-issuers-did-attributes-attributeid)
    5. [GET List revisions](https://api-pilot.ebsi.eu/docs/apis/trusted-issuers-registry/latest#/operations/get-trusted-issuers-registry-v5-issuers-did-attributes-attributeid-revisions)
    6. [GET List proxies](https://api-pilot.ebsi.eu/docs/apis/trusted-issuers-registry/latest#/operations/get-trusted-issuers-registry-v5-issuers-did-proxies)
    7. [GET Get a proxy](https://api-pilot.ebsi.eu/docs/apis/trusted-issuers-registry/latest#/operations/get-trusted-issuers-registry-v5-issuers-did-proxies-proxyid)
    8. [GET Get StatusList2021Credential](https://api-pilot.ebsi.eu/docs/apis/trusted-issuers-registry/latest#/operations/get-trusted-issuers-registry-v5-issuers-did-proxies-proxyid-path)
    9. [POST JSON-RPC API](https://api-pilot.ebsi.eu/docs/apis/trusted-issuers-registry/latest#/operations/post-ledger-v2-blockchains-besu)

    Other
    medium
  • Trusted Schemas Registry API

    Following endpoints of the [Trusted Schemas Registry API](https://api-pilot.ebsi.eu/docs/apis/trusted-schemas-registry/latest#/) are considered in-scope:

    1. [GET List schemas](https://api-pilot.ebsi.eu/docs/apis/trusted-schemas-registry/latest#/operations/get-trusted-schemas-registry-v3-schemas)
    2. [GET Get a schema](https://api-pilot.ebsi.eu/docs/apis/trusted-schemas-registry/latest#/operations/get-trusted-schemas-registry-v3-schema)
    3. [GET List a schema's revisions](https://api-pilot.ebsi.eu/docs/apis/trusted-schemas-registry/latest#/operations/get-trusted-schemas-registry-v3-schemas-revisions)
    4. [GET Get a schema revision](https://api-pilot.ebsi.eu/docs/apis/trusted-schemas-registry/latest#/operations/get-trusted-schemas-registry-v3-schema-revision)
    5. [GET List revision's metadata](https://api-pilot.ebsi.eu/docs/apis/trusted-schemas-registry/latest#/operations/get-trusted-schemas-registry-v3-schemas-revision-metadata-list)
    6. [GET Get metadata](https://api-pilot.ebsi.eu/docs/apis/trusted-schemas-registry/latest#/operations/get-trusted-schemas-registry-v3-schema-revision-metadata)
    7. [POST JSON-RPC API](https://api-pilot.ebsi.eu/docs/apis/trusted-schemas-registry/latest#/operations/post-trusted-schemas-registry-v3-jsonrpc)

    Other
    medium
  • Ledger API

    Following endpoints of the [Ledger API](https://api-pilot.ebsi.eu/docs/apis/ledger/latest#/) are considered in-scope:

    1. [POST Besu JSON-RPC API](https://api-pilot.ebsi.eu/docs/apis/ledger/latest#/operations/post-ledger-v3-blockchains-besu)

    Other
    medium
  • Trusted Policies Registry API

    Following endpoints of the [Trusted Policies Registry API](https://api-pilot.ebsi.eu/docs/apis/trusted-policies-registry/latest#/) are considered in-scope:

    1. [GET List policies](https://api-pilot.ebsi.eu/docs/apis/trusted-policies-registry/latest#/operations/get-policies)
    2. [GET Get a policy](https://api-pilot.ebsi.eu/docs/apis/trusted-policies-registry/latest#/operations/get-policy)
    3. [GET List users](https://api-pilot.ebsi.eu/docs/apis/trusted-policies-registry/latest#/operations/get-users)
    4. [GET Get a user](https://api-pilot.ebsi.eu/docs/apis/trusted-policies-registry/latest#/operations/get-user)
    5. [POST JSON-RPC API](https://api-pilot.ebsi.eu/docs/apis/trusted-policies-registry/latest#/operations/post-jsonrpc)

    Other
    medium
Tech Stack

Last Finished Scan:
Scan Name
Fleet
Finished
State
allkxss
10 months ago
Finished
  • Fleet: allkxss
  • Duration: 31 Seconds
  • Finished: 10 months ago