API reference
ATTESTATIONS
Connector attestations, signed by Path Global — what makes a Crossway answer more than a connector's word.
LIVE — PIP-0014.
Private access. The Crossway API is operated by Path Global. Access is closed and granted per client and per registry, on request at pathglobal.finance. Requests are signed as in Authentication, under a key issued by Path Global, and sent from your server only.
https://api.pathglobal.finance/crossway/v1Every Crossway answer names the connector that read the registry and the attestation that connector holds. Verify both. See the spec.
GET /attestations/{reference}
Unauthenticated. The read is the check: revocation is checked here, never cached.
{
"type": "crossway.connector_attestation",
"reference": "att_9kq3m7vx2pf8",
"connector": "pathglobal-br-01",
"registry": "pix.dict",
"operations": ["sonar", "resolver", "payee_check"],
"access": "authorised_participant",
"issued_at": "2026-10-01T00:00:00Z",
"expires_at": "2027-04-01T00:00:00Z",
"status": "active",
"kid": "pg_root_2026_01",
"signature": "…"
}GET /.well-known/crossway-keys
Path Global's published keys: the root key that signs attestations, and each connector's answer key. Same format as a PATH operator's published keys.
Verifying an answer
- Verify the answer's signature under the connector key named by
kid. - Read the attestation named by
attestation. Verify it under the root key. - Check that
statusisactive,expires_atis in the future, and thatregistryandoperationscover the answer you hold. - Any failure: discard the answer.
Errors
| Code | Status | Meaning |
|---|---|---|
crossway.attestation.revoked | 410 | Revoked. Discard every answer that names it |
crossway.attestation.not_found | 404 | No such attestation |