GitHub
TransversePATH CROSSWAY

API reference

ATTESTATIONS

Connector attestations, signed by Path Global — what makes a Crossway answer more than a connector's word.

LIVE — PIP-0014.

Private access. The Crossway API is operated by Path Global. Access is closed and granted per client and per registry, on request at pathglobal.finance. Requests are signed as in Authentication, under a key issued by Path Global, and sent from your server only.

https://api.pathglobal.finance/crossway/v1

Every Crossway answer names the connector that read the registry and the attestation that connector holds. Verify both. See the spec.


GET /attestations/{reference}

Unauthenticated. The read is the check: revocation is checked here, never cached.

{
  "type": "crossway.connector_attestation",
  "reference": "att_9kq3m7vx2pf8",
  "connector": "pathglobal-br-01",
  "registry": "pix.dict",
  "operations": ["sonar", "resolver", "payee_check"],
  "access": "authorised_participant",
  "issued_at": "2026-10-01T00:00:00Z",
  "expires_at": "2027-04-01T00:00:00Z",
  "status": "active",
  "kid": "pg_root_2026_01",
  "signature": "…"
}

GET /.well-known/crossway-keys

Path Global's published keys: the root key that signs attestations, and each connector's answer key. Same format as a PATH operator's published keys.

Verifying an answer

  1. Verify the answer's signature under the connector key named by kid.
  2. Read the attestation named by attestation. Verify it under the root key.
  3. Check that status is active, expires_at is in the future, and that registry and operations cover the answer you hold.
  4. Any failure: discard the answer.

Errors

CodeStatusMeaning
crossway.attestation.revoked410Revoked. Discard every answer that names it
crossway.attestation.not_found404No such attestation

On this page