qub for developers
qub for developers
The HTTP API is versioned under /api/v1; its OpenAPI document currently reports API version 1.0.0. Three integration paths are supported:
- HTTP API — the complete external surface is generated from operations marked
x-audience: externalin /api/v1/openapi.json. Public operations need no credentials; browser writes use Cloudflare Turnstile; Builder calls useAuthorization: Bearer qub_sk_…./api/v1/uploadaccepts locally sealed bytes, while/api/v1/sealis an explicitly trusted server-side plaintext path. - MCP server —
tools/qub-mcpis a local Rust binary for create/read/status operations. It seals locally and publishes private wrapped qubs. Publishing is disabled by default;create_qubrequires bothQUB_API_KEYandQUB_MCP_ALLOW_CREATE=true. Reads take either the full fragment-bearing delivery URL ortx_idpluskey_base64url. - Embed —
<qub-embed src="https://qub.social/c/<tx_id>#<key>">renders the live countdown and reveal inline. Public qubs use the samesrcform without a fragment. Use the pinned loader/embed/v1.js;/embed.jsis only the moving alias.
Portable .qub bundles verify content integrity, drand-round binding, and signatures offline. Proving that ciphertext existed by a particular time additionally requires a verified permanent-storage transaction or anchored transparency-log proof.
See llms.txt for the agent-oriented summary, llms-full.txt for the concatenated documentation bundle, and the rendered OpenAPI reference for schemas and responses.