# SReverse complete workflow demonstration

This is a synthetic local API. It contains no customer code, APK secret or live service credential.

The same workflow is provided as a Python client, TypeScript client and Postman collection:

1. Log in and receive a short-lived access token plus a refresh token.
2. Rotate the refresh token.
3. Encrypt a lookup body with AES-256-GCM.
4. Sign the exact HTTP body with HMAC-SHA-256.
5. Send the request and parse the decrypted result.
6. Confirm that a bad signature returns a structured error.

## Run it

Requirements: Bun, Python 3 and the Python `cryptography` package.

```sh
bun server.ts
python3 client.py
bun client.ts
```

Import `sreverse-demo.postman_collection.json` into Postman while the local server is running. Run the collection in order.

The keys and credentials are public test values. Never use them outside this demonstration.
