DCC Boxed DUIS Signing Tool API

An open-source HTTP API published by Smart DCC Limited for signing and validating DUIS (DCC User Interface Specification) XML messages. Two operations — POST /sign adds an XML digital signature to a Base64-encoded unsigned DUIS request (with an optional preserveCounter flag), and POST /verify validates the signature on a DUIS response and strips it. The tool ships with the ZAZ1 test SMKI certificates used by DCC Boxed and also performs XSD validation. It runs locally as a self-hosted server; Smart DCC operates no public hosted instance.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/dcc-boxed-duis-signing-tool-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

dcc-boxed-duis-signing-tool-openapi.yml Raw ↑
# Copyright (c) 2026 Smart DCC Limited
# Licensed under GPL-3.0

openapi: 3.0.3
info:
  title: DCC Boxed DUIS Signing Tool API
  description: HTTP API for signing and validating DUIS XML messages
  version: 1.0.0
  contact:
    name: Smart DCC Limited
  license:
    name: GPL-3.0
    url: https://www.gnu.org/licenses/gpl-3.0.html

servers:
  - url: http://localhost:8080
    description: Local development server

paths:
  /sign:
    post:
      summary: Sign a DUIS request
      description: Signs a DUIS XML message and returns the signed XML with digital signature
      operationId: signMessage
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - message
              properties:
                message:
                  type: string
                  format: byte
                  description: Base64-encoded unsigned DUIS XML message
                  example: PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz4...
                preserveCounter:
                  type: boolean
                  description: Optional. When true, preserves the original counter in the DUIS request. When false or omitted, overwrites with System.currentTimeMillis()
                  default: false
                  example: true
      responses:
        '200':
          description: Successfully signed message
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    format: byte
                    description: Base64-encoded signed DUIS XML message with digital signature
                    example: PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz4...
        '400':
          description: Bad request - invalid XML or signing error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '405':
          description: Method not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'

  /verify:
    post:
      summary: Verify a DUIS response
      description: Validates a signed DUIS XML message and returns the unsigned XML
      operationId: verifyMessage
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - message
              properties:
                message:
                  type: string
                  format: byte
                  description: Base64-encoded signed DUIS XML message with digital signature
                  example: PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz4...
      responses:
        '200':
          description: Successfully verified message
          content:
            application/json:
              schema:
                type: object
                properties:
                  message:
                    type: string
                    format: byte
                    description: Base64-encoded validated DUIS XML message without digital signature
                    example: PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz4...
        '400':
          description: Bad request - invalid signature or validation error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '405':
          description: Method not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'

components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
          description: Error message
        errorCode:
          type: string
          description: Exception class name