boostbob 解读 TapeAPI 请求签名与容器机制boostbob Explains TapeAPI Request Signing and Containers
boostbob 发帖解读 TapeAPI 的工作流程:提供常规 API 接口服务的一方,需在 NFT 电路的容器里写入 manifest 文件,说明接口访问地址与密钥对中的公钥,私钥保留在自己的 API 服务器上;调用方 TapeAPI/SDK 的参数是 NFT 电路 ID 与实际 API 请求 body 参数,会对请求编号并签名,后端 TapeAPI/server 验证请求并对响应结果签名,SDK 再验证响应签名,确认是电路所配置的 API 且与每次请求一一对应。他称此前一直没看懂 TapeAPI 在做什么。boostbob posted an explainer on how TapeAPI works: a party offering a regular API service must write a manifest file into the NFT circuit's container stating the API access address and the public key of a key pair, while the private key stays on its own API server. The caller's TapeAPI/SDK takes the NFT circuit ID and the actual API request body as parameters, numbers and signs the request; the backend TapeAPI/server verifies the request and signs the response, and the SDK then verifies the response signature to confirm it comes from the API configured in the circuit and matches each request. He said he had not understood what TapeAPI did before.