# imgauth — API di attestazione opere digitali > Digital-work attestation and proof-of-existence service operated by Spazio Genesi ETS, an Italian > non-profit. The client computes a SHA-256 fingerprint locally and sends only the 64-hex hash — file > bytes never leave the device. The service binds the fingerprint to a server-side timestamp, signs it > (HMAC), issues a PAdES B-LT signed PDF certificate carrying an RFC 3161 timestamp, and anchors the > fingerprint in Bitcoin through OpenTimestamps across four calendars. Verification is free and unlimited > for anyone, and the proof of existence never expires. The service positions itself explicitly as a > NON-QUALIFIED attestation under eIDAS 2.0. The API contract is in Italian by design — do not translate > the field names. Generated by API Evangelist from the provider's published contract and docs; the > provider does not serve an llms.txt of its own (2026-08-11). ## APIs - [imgauth REST API](https://imgauth.spaziogenesi.org): 18 operations, OpenAPI 3.0.3, engine 1.34.1. Attestation, verification, certificate retrieval, OpenTimestamps proofs, embeddable badges, public status telemetry and the agent device flow. - [imgauth Remote MCP Server](https://attest-mcp-remote.it-e3f.workers.dev/mcp): hosted Streamable HTTP MCP server, protocol 2025-06-18, 8 tools. Four are public (service_status, check_anchor, verify_attestation, lookup_certificate); four need a credential (authorize, complete_authorization, attest_hash, create_certificate_pdf). ## Specs - [OpenAPI 3.0.3](https://imgauth.spaziogenesi.org/openapi.json): the live contract, served from the API host root. - [security.txt](https://imgauth.spaziogenesi.org/.well-known/security.txt): RFC 9116, served on the API and docs hosts. ## Docs - [Developer documentation](https://attestazione.spaziogenesi.org/en/developer/): auth, tiers, MCP, CLI, GitHub Action. - [Interactive API reference](https://attestazione.spaziogenesi.org/docs/): Swagger UI with try-it-out. - [CLI](https://attestazione.spaziogenesi.org/en/developer/cli/): sg-attest, npx or standalone binaries for six platforms. - [API keys](https://attestazione.spaziogenesi.org/en/developer/keys/): self-service issuance after email verification. - [Changelog](https://attestazione.spaziogenesi.org/changelog/): dated, Italian and English. - [Status](https://attestazione.spaziogenesi.org/status/): 90-day history, backed by three public JSON endpoints. - [Security policy and responsible disclosure](https://attestazione.spaziogenesi.org/sicurezza/) - [Trust Center](https://trust.spaziogenesi.org/): compliance map, ADRs, subprocessors, open Trust Score. - [Terms and tiers](https://attestazione.spaziogenesi.org/en/condizioni/): retention guarantees per tier. - [Integrations showcase](https://attestazione.spaziogenesi.org/integrazioni/) ## How an agent should use this - Compute the SHA-256 locally (`sha256sum `). NEVER pass file bytes or base64 as tool arguments — the server does not accept them on the agent path. - Verification needs no credential. Attestation does: run the device flow (`authorize`, then `complete_authorization`) or send `Authorization: Bearer sg_k_...`. - A credential only bypasses the anti-bot challenge and applies your tier quota. Per-IP rate limits (60/60s, and 10/60s on certificate PDF generation) apply either way. - There is no idempotency key. Re-posting the same fingerprint issues a NEW attestation; retrieval resolves the oldest. Do not blind-retry a timed-out attestation. - Errors return `{"error": ""}` — branch on the HTTP status, not on the message. - Declared metadata (titolo, autore, anno, note) is bound into the signature. To verify later, resupply all fields exactly as printed. ## Source - [GitHub — imgauth engine (AGPL-3.0)](https://github.com/SPAZIO-GENESI/imgauth) - [GitHub — remote MCP server (MIT)](https://github.com/SPAZIO-GENESI/attest-mcp-remote) - [npm — @spazio-genesi/attest-mcp](https://www.npmjs.com/package/@spazio-genesi/attest-mcp): MCP server + sg-attest CLI, v0.4.1 (2026-07-24). - [GitHub Action — attest-action](https://github.com/SPAZIO-GENESI/attest-action)