Skip to content

Prototype: fictional data, not a real service

Demo with made-up data. Do not enter real details: anyone can use this demo.

polder.tech · developer portal for platforms (mock)

Voorbeeldplatform · sandbox

Linking with polder.tech (mock)

API reference

Two directions: what you publish and polder.tech fetches, and what you may request yourself.

YOU PUBLISH/.well-known/jwks.jsonP-1

Issuer key set

Who calls whom
You publish, polder.tech fetches on a fixed timer.
Shape
JWKS with one Ed25519 key per platform (alg: EdDSA, kid like voorbeeldplatform-2026-09).
Never carries
Keys or URLs per worker.
curl -s https://issuer.voorbeeldplatform.example/.well-known/jwks.json
YOU PUBLISH/status/listP-2

Status list

Who calls whom
You publish one list for all codes; polder.tech always fetches the whole list.
Shape
Token Status List, 1 bit per index (valid or not), random indices and decoys.
Never carries
Anything that differs per requester. polder.tech never fetches a single index.
curl -s https://issuer.voorbeeldplatform.example/status/list -H 'Accept: application/statuslist+jwt'
POST/conformance/credentialP-3

Issue a code to every active worker

Who calls whom
You show the code in your app at a step every worker passes. In the sandbox this endpoint checks that your code is well-formed; no account is created.
Shape
Compact JWS, typ: polder-elig+jws, with iss, platform, jurisdiction, active, seg.city, pseud, status.idx, jti, iat, exp (14 days).
Never carries
Name, phone, e-mail, birth date, your worker ID in clear.
curl -s -X POST https://sandbox.polder.tech/v0/conformance/credential \
  -H 'Authorization: Bearer pt_sbx_••••••••' \
  -H 'Content-Type: application/json' \
  -d '{"token":"eyJhbGciOiJFZERTQSIsInR5cCI6InBvbGRlci1lbGlnK2p3cyJ9..."}'
GET/platform/complianceC-1

Evidence of your own duties

Who calls whom
You request it, only for your own platform.
Shape
Four yes/no proofs: channel offered, issuance conformant, status list fresh, availability.
Never carries
Any usage figure. The server refuses any number that looks like usage.
curl -s 'https://sandbox.polder.tech/v0/platform/compliance?platform=voorbeeldplatform' \
  -H 'Authorization: Bearer pt_sbx_••••••••'
GET/platform/evidence-packC-2

Download the evidence pack for the platform

Who calls whom
You download it, for your own file. The regulator gets a separate pack.
Shape
PDF with only: channel offered, codes issued, availability and the non-access attestation. Plus DPIA summary, ‘what we can see’, lawful-access policy and status-list sync log.
Never carries
Reports or moderation figures, not even as bands (those are only in the evidence pack for the regulator). Content, names or use per worker.
curl -s -o evidence-pack.pdf 'https://sandbox.polder.tech/v0/platform/evidence-pack?platform=voorbeeldplatform' \
  -H 'Authorization: Bearer pt_sbx_••••••••'

Sandbox key

pt_sbx_••••••••

This key belongs to Voorbeeldplatform and only works in the sandbox. It identifies your platform, never a worker.

About this screen · C2
Requirements
R-NA-6R-NA-7R-NA-10R-NA-11R-NA-12R-LK-11
Mocked in this prototype

Mock: there is no sandbox. The key is fake, ‘New key’ makes a random string and ‘Copy curl’ only puts the command on the clipboard. The code-conformance endpoint is not in spec/18.

In the real design

The cards follow spec/18 §4: the platform publishes key set, status list and the code for every active worker; polder.tech fetches. The platform may only request C-1 and C-2; no usage figures, no per-worker request (D-004, D-032, D-049 open). C-2 is the evidence pack for the platform: no reports or moderation figures (K-062).