--- title: WaveSign API emoji: 🔏 colorFrom: blue colorTo: indigo sdk: docker pinned: false --- # WaveSign API Private API space — not publicly accessible. All endpoints (except `/health`) require an `Authorization: Bearer ` header matching the `WS_API_KEY` environment variable configured for this Space. ## Endpoints - `GET /health` — liveness check, no auth required - `POST /sign` — sign an image or PDF; returns a ZIP containing the signed file and `sig.json` - `POST /verify` — verify a previously signed file against its `sig.json`; returns a JSON result