Project

qopanza

0.0
The project is in a healthy, maintained state
Post-quantum cryptography (ML-KEM, ML-DSA) and cryptographic discovery from Ruby.
2005
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026
 Dependencies

Development

~> 5.0
 Project Readme

Qopanza SDKs

Official client libraries for the Qopanza API — post-quantum cryptography and cryptographic discovery.

Encrypt and sign with the NIST standards (ML-KEM-768, ML-DSA-65, SLH-DSA-SHA2-128S) without holding the key material yourself, and scan your own code and live sites for the cryptography that a quantum computer will eventually break.

Install

Language Install Registry
Python pip install qopanza PyPI
TypeScript / JavaScript npm install qopanza npm
Go go get github.com/isingomajoel2023/qopanza-sdks/go/qopanza —
Rust cargo add qopanza crates.io
Java com.qopanza:qopanza Maven Central
C# / .NET dotnet add package Qopanza.Sdk NuGet
Ruby gem install qopanza RubyGems
PHP composer require qopanza/sdk Packagist
C++ CMake, see cpp/ —

Go has no registry by design: go get fetches straight from this repository. C++ has no dominant one, so it builds from source.

For AI coding agents: the MCP server

mcp-server/ is not a client library but a tool server for Claude Code, Cursor, Windsurf and Claude Desktop. It lets the agent scan an app for exposed secrets and apply the fixes itself.

claude mcp add qopanza -e QOPANZA_API_KEY=qsk_... -- npx -y qopanza-mcp

Published on npm as qopanza-mcp. Agents that run in the cloud — Lovable, Replit — cannot launch npx, and connect to the hosted server at https://api.qopanza.com/mcp with the same API key instead. Setup for every agent is in its README.

Getting started

pip install qopanza
from qopanza import QopanzaClient

client = QopanzaClient(api_key="qsk_...")

# Encrypt without ever handling the key
sealed = client.encrypt(b"card number, health record, anything")
assert client.decrypt(sealed) == b"card number, health record, anything"

# Find the cryptography you already have
report = client.scan_repository(".")
for finding in report.findings:
    print(finding.severity, finding.algorithm, finding.location)

Every SDK follows the same shape. Each directory has its own README with the idiomatic version for that language.

Get an API key at qopanza.com — the free tier needs no card.

What each SDK does and does not do

Does: key encapsulation and signatures against the NIST post-quantum standards, hybrid classical+PQC modes, cryptographic inventory, repository and live-site scanning, and the remediation plan that goes with a finding.

Does not: implement the cryptography itself. These are clients. The primitives run server-side against liboqs, which is the point — a client library that shipped its own implementation of ML-KEM would be asking you to trust our C, and you should not have to.

Versioning

Each SDK is versioned independently. Below 1.0.0 the interface may change between minor versions; the release notes say so when it does.

Contributing

Issues and pull requests are welcome. The SDKs are generated against docs/openapi.json and hand-finished, so a report of an endpoint that does not round-trip correctly is especially useful.

Security issues do not belong in a public issue. Email security@qopanza.com — we will confirm within one working day.

Licence

Apache-2.0. See LICENSE.

© Gsente LLC