Integration guides
Signing keys, API tokens, and agent state tend to end up copied into every service instance that needs them, where rotating one means redeploying all of them and nothing records who used what. A VTA holds that material instead and acts on the application’s behalf, with every call addressed by the application’s own DID and bounded by its role and context. Rotating or revoking access becomes a change on the VTA rather than a release, and every operation lands in one audit trail. Sign application payloads without exposing your keys →
Choose the guide that matches what you are building.
Shared setup: most guides in this section start with the same one-time bootstrap:
- Create a context.
- Provision an app identity with the
applicationrole. - Authenticate at runtime with the credential.
New to VTA? Start with Sign application payloads without exposing your keys, which also covers minting a signing key.
Glad to hear it! Please tell us how we can improve more.
Sorry to hear that. Please tell us how we can improve.
Thank you for sharing your feedback so we can improve your experience.