Stay organized with collections
Save and categorize content based on your preferences.
Cards QR uses HTTPS (TLS) for transport layer security.
Transport layer encryption with HTTPS
All API endpoints must be served using HTTPS with TLS 1.2 or higher. API
clients must have common name (CN) checking turned on and the server's CN or
wildcards must match the hostname.
We strongly recommend using a certificate issued under a root certificate
included in the
Mozilla CA certification program
to reduce the level of maintenance necessary to keep this connection healthy.
However, if necessary, we do allow partners to issue self-signed certificates
that we can trust.
Cipher suites
The server must support at least one of these cipher suites and should not
support cipher suites outside of the following set:
ECDHE-ECDSA-AES128-GCM-SHA256
ECDHE-RSA-AES128-GCM-SHA256
ECDHE-ECDSA-CHACHA20-POLY1305
ECDHE-RSA-CHACHA20-POLY1305
ECDHE-ECDSA-AES128-SHA256
ECDHE-RSA-AES128-SHA256
All rights reserved. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2024-12-03 UTC.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2024-12-03 UTC."],[[["Cards QR utilizes HTTPS with TLS 1.2 or higher for secure transport layer encryption across all API endpoints."],["API clients must enable common name (CN) checking to ensure the server's CN or wildcards align with the hostname."],["While using a Mozilla CA certification program-issued certificate is strongly recommended, self-signed certificates can be used if necessary, but Google will require immediate replacement upon revocation."],["Servers must support at least one of the specified cipher suites (ECDHE-ECDSA-AES128-GCM-SHA256, ECDHE-RSA-AES128-GCM-SHA256, ECDHE-ECDSA-CHACHA20-POLY1305, ECDHE-RSA-CHACHA20-POLY1305, ECDHE-ECDSA-AES128-SHA256, ECDHE-RSA-AES128-SHA256) for secure communication."]]],["Cards QR utilizes HTTPS with TLS 1.2 or higher for secure data transport. API endpoints must use HTTPS, with clients enabling common name (CN) checking, matching the server's CN or wildcards to the hostname. Using certificates from the Mozilla CA program is recommended, though self-signed certificates are permitted. The server must support, and exclusively use, one of the listed cipher suites (e.g., ECDHE-ECDSA-AES128-GCM-SHA256). If a certificate is revoked, a replacement must be provided promptly.\n"]]