ANNEX IISupplementary provisions
ANNEX II 1. REQUIREMENTS FOR ELECTRONIC SIGNATURES OR SEALS APPLIED TO THE INFORMATION MADE AVAILABLE ON REGISTERED WALLET-RELYING PARTIES REFERRED TO IN ARTICLE 3 — JavaScript Object Notation (‘JSON’); — IETF 7515 for JSON Web Signatures. 2. REQUIREMENTS ON THE SINGLE COMMON API REFERRED TO IN ARTICLE 3 (1) The single common API shall: (a) be a REST API, supporting JSON as a format and signed in accordance with the relevant requirements specified in Section 1; (b) allow any requestor, without prior authentication, to search and request complete lists to the register, for information about registered wallet-relying parties, allowing for partial matches based on defined parameters including, where applicable, the official or business registration number of the wallet-relying party, the name of the wallet-relying party or the information referred to in Article 8, paragraph 2, point (g) and Annex I points 12, 13, 14 and 15; (c) ensure that replies to requests referred to in point (b) that match at least one wallet-relying party shall include one or more statements on information about registered wallet-relying parties and information according to Annex I, current and historic wallet-relying party access certificates and wallet-relying party registration certificates but exclude the contact information in Annex I point 4; (d) be published as an OpenAPI version 3, together with the appropriate documentation and technical specifications ensuring interoperability across the Union; (e) provide security functions, including security by default and by design, to ensure the availability and integrity of the API and the availability of information through it. (2) The statements referred to in point (c) shall be expressed under the form of electronically signed or sealed JSON files, with a format and structure in accordance with the requirements on electronic signatures or seals set out Section 1.