API reference · testnet
Quantum Core interfaces
Quantum Core runs on your machine and sends nothing over the network: it has no web API. Its interfaces are the release files it installs from, its command line and its report formats. This page states what each one guarantees.
Release files
Static files on https://functorfund.com/quantum/releases/. The installer uses exactly these.
| Path | Content |
|---|---|
latest.txt | The current version, e.g. 0.5.1 |
v{version}/quantum-scan-{os}-{arch} | The binary. os: darwin, linux. arch: arm64, x86_64 (macOS); x86_64, aarch64 (Linux, static) |
v{version}/checksums.txt | SHA-256 of every binary of that version |
v{version}/checksums.txt.mldsa65.sig | ML-DSA-65 (FIPS 204) signature of checksums.txt |
release-mldsa65.pub.pem | The release public key. The installer pins its own copy and refuses any other |
../install.sh | The installer: curl -fsSL https://functorfund.com/quantum/install.sh | sh |
Verify a download yourself
Needs OpenSSL 3.5 or later (ML-DSA support).
V=$(curl -fsSL https://functorfund.com/quantum/releases/latest.txt)
B=https://functorfund.com/quantum/releases
curl -fsSLO $B/v$V/checksums.txt -fsSLO $B/v$V/checksums.txt.mldsa65.sig -fsSLO $B/release-mldsa65.pub.pem
curl -fsSLO $B/v$V/quantum-scan-linux-x86_64
openssl pkeyutl -verify -rawin -pubin -inkey release-mldsa65.pub.pem \
-in checksums.txt -sigfile checksums.txt.mldsa65.sig # Signature Verified Successfully
shasum -a 256 -c checksums.txt --ignore-missing # quantum-scan-linux-x86_64: OK
Command line
Flags and suppressions: command line reference. The exit codes are the contract CI systems rely on:
| Code | Meaning |
|---|---|
| 0 | Scan completed; no threshold set, or not exceeded |
| 1 | Usage error or scan failure |
| 2 | Scan completed and the --fail-on threshold was exceeded |
Report formats
| Format | Flag | Standard | Version field |
|---|---|---|---|
| JSON | --format json | Quantum Core's own schema | schema_version (currently 1.0) |
| SARIF | --format sarif | OASIS SARIF 2.1.0 | version |
| CBOM | --format cbom | CycloneDX 1.6 (ECMA-424), validated against the official schema in every test run | specVersion |
| Markdown | --format markdown | for people, not for parsing | — |
Field-by-field description: output formats.
Stability rules
- Patch releases (0.5.x) never change a flag, an exit code or a report field.
- New report fields may appear in any minor release. Parsers must ignore unknown fields.
- Removing or renaming a JSON field, or changing its meaning, raises
schema_version's major number and is listed in the release notes one minor release ahead. - Exit codes 0, 1 and 2 keep their meaning for the life of the product.
- Every release is signed with the same ML-DSA-65 key. A key change would be announced on News with the new key's fingerprint, and the old installer would refuse the new key by design.
Generated from the node's source code by tools/api-docs.mjs; examples are real responses from https://api.functorfund.com. Questions: Telegram. Changes: News.