Proposal: a Ledger API Proxy run on top of Canton Ledger API to provide authentication and audit trail (RFP 25, Identity and Access Control and RFP 27, Security Monitoring, Auditability and Evidence)
Development Fund Proposal Submission
Proposal file:
/rfps/security-assurance-incident-readiness/2026-09-Upflam-LedgerShield.md
Applicant
Organization:
Author / Primary Contact:
- Vinh v@upflam.com | Github: https://github.com/v9n
Champion:
@akashgaurav @beezybarg
Proposal Classification
Proposal Type:
- RFP-aligned proposal
- Individual initiative
RFP Category:
- RFP 25: Identity and Access Control
- RFP 27: Security Monitoring, Auditability and Evidence
Label:
- node-deployment-operations
- canton-api
- rfp-25:identity-access-control
- rfp-27:security-monitoring
Funding & Timeline
Total Funding Request:
1,650,000 CC
Project Duration:
3 months for development, 6 months for community outreach and ecosystem adoption
Maximum Amount:
1,650,000 CC
Maximum Duration:
9 monthes
Summary
LedgerShield is a Canton Ledger API Proxy run on top of Ledger API, providing an additional layer of access token issuer and deep granularity permission control without manually issueing OIDC app or access token and store an audit log of all the request again it queryable in a DuckDB database
Any operator can choose to run this on top of their ledger and re-configure their app to point to this proxy, reduce operation overhead in providing Ledger API access and have full visibility into an auditlog of activities against and API key
Who benefits
Every participant operator benefits, without a node upgrade. Institutional deployments benefit most, because separation of duties and per-credential audit are compliance requirements for them.
Both service provider and node operator benefit because how quick it's to share Ledger API access.
How adoption is drive
By reducing this friction to gain access to Ledger API, we believe it will drive adoption. Once people see how quickly and safely they can expose or share Ledger API access, while at the same time gaining access to an audit log, they will do it more. For example, a validator can quickly share a read-only credential with a third-party indexer, which is a common need in accounting and private data exploring.
Development will also be easier and safer. Devs, engineers, and contractors can easily get scoped, limited access to help debug and work on the validator.
Today, many validators download and run those accounting/explorer tools inside their infrastructure. That increases friction and lowers adoption. By making it safe to expose Ledger API to the outside, operators don't need to run these tools themselves, and service providers can onboard validators quicker.
Submission Checklist
- Full proposal file is included in this PR
- Organization and primary contact identified
- Champion identified or
Needs Championselected - RFP / roadmap alignment identified, if applicable
- Total funding request provided
- Project duration provided
- Proposal is within any RFP maximum amount
- Proposal is within any RFP maximum duration
- Milestones and milestone funding are defined in the proposal
- Acceptance criteria are based on ecosystem value
- Architectural alignment is addressed