# AX Check: support.fortanix.com
Checked 2026-10-05.

Docs and quickstart are solid; pricing is nowhere to be found
Homepage, llms.txt, quickstart, CLI and API docs all resolve cleanly. No pricing page exists — all three sessions had to infer enterprise/quote-based pricing instead of reading it.

## Onboarding needs a login

## Coding sessions
All three independent sessions completed and found working docs, CLI install steps, and API references. None found a live pricing page: each guessed quote-based enterprise pricing with a free trial, and one confirmed the pricing URL returns a 404.

### DeepSeek V4.1 Flash
[View public run](https://agents.withgauge.com/p/runs/16c57baa-c859-4e7c-90ca-d94e5e052961) · [Read transcript](https://www.ax-check.com/support.fortanix.com/sessions/deepseek.json)
README Pricing section states enterprise/quote-based cost with explicit assumptions: monthly subscription, minimum 1-year term, 30-day trial, metered crypto operations, separate on-prem/marketplace licensing.
#### End-to-end onboarding
- **Onboarding needs a login**: Agent found a real Fortanix DSM developer workflow (hosted REST API at region endpoints like eu.smartkey.io, official Python SDK 'sdkms') and wrote a working example. It confirmed wiring reached the live API (bogus key returned real server-side 400, unauthenticated calls returned 401). But no actual DSM account/API key was obtained in-session — DSM requires human sign-up with email verification plus manual API key creation in the UI. No authenticated operation (key create, encrypt/decrypt) ever ran against the real service.
  Event 175:

  ```text
  sdkms.v1.rest.ApiException: (400)
  Reason: Bad Request
  ...
  HTTP response body: invalid id in Basic header
  ```
  Event 186:

  ```text
  I cannot run the example end-to-end because I have no Fortanix DSM account or API key, and DSM provides no self-serve way for me to create one.
  ```
  Event 98:

  ```text
  Fortanix offers a free trial for Fortanix DSM SaaS. Set up a free trial to access the Fortanix DSM portal
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No self-serve API credentials for DSM SaaS**: Fortanix DSM requires a human to sign up for a trial (work email, email verification, reCAPTCHA) and then manually create an application + API key inside the web UI. There is no programmatic or anonymous way to obtain a key, so the agent could not authenticate and could not run its example end-to-end. This is expected product behavior (enterprise security product), not a defect.
  Event 98:

  ```text
  Perform the following steps to sign up for a free trial on Fortanix DSM SaaS application:
  
  1. Go to the Fortanix website using URL: `https://www.fortanix.com`.
  ```
  Event 186:

  ```text
  I cannot run the example end-to-end because I have no Fortanix DSM account or API key, and DSM provides no self-serve way for me to create one.
  ```
- **Legacy sdkms.fortanix.com hostname no longer resolves**: The agent's first environment probe tried the old documented SDK default host and DNS lookup failed outright, forcing extra research to find the current smartkey.io endpoints. This is a product/documentation drift issue (stale hostname in historical SDK code/docs), not an agent error, though it added investigation steps before the correct endpoint was found.
  Event 30:

  ```text
  curl: (6) Could not resolve host: sdkms.fortanix.com
  HTTP 000
  ```
  Event 42:

  ```text
  sdkms.fortanix.com           NXDOMAIN
  ```
- **TLS verification failed against default certifi bundle**: Running the example against the live eu.smartkey.io endpoint initially failed with a certificate verification error because the Python SDK's urllib3 client used the bundled certifi CA store, which didn't validate the server's chain. Switching to the OS system CA bundle resolved it. This is sandbox/environment friction (CA store mismatch), not a Fortanix product defect, and was fully recovered.
  Event 158:

  ```text
  urllib3.exceptions.MaxRetryError: HTTPSConnectionPool(host='eu.smartkey.io', port=443): Max retries exceeded with url: /sys/v1/session/auth (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1000)')))
  ```
  Event 167:

  ```text
  using /etc/ssl/certs/ca-certificates.crt
  status 401 b'Unauthorized access'
  ```

#### Suggested Changes
- **Update or remove the stale sdkms.fortanix.com default endpoint reference**: The Go SDK's documented/coded default endpoint host sdkms.fortanix.com returns NXDOMAIN; the real default is apps.smartkey.io (per client.go) with region hosts like eu.smartkey.io. Point SDK docs and any remaining references to the current smartkey.io region URLs so new developers don't waste time chasing a dead hostname, and verify by curling the documented default endpoint after the change.
  Event 30:

  ```text
  curl: (6) Could not resolve host: sdkms.fortanix.com
  HTTP 000
  ```
  Event 69:

  ```text
  DefaultAPIEndpoint string = "https://apps.smartkey.io"
  ```
- **Publish a visible pricing page for DSM SaaS**: Direct pricing URLs (www.fortanix.com/pricing, .../data-security-manager/pricing) 404, and the product page has no pricing section; only a 'minimum 1-year term' and 'metered operations' billing model is documented, with no concrete figures. Add a pricing page linked from the DSM product page so prospective developers can estimate cost without contacting sales; verify by checking the page renders a price or cost range instead of the current 404.
  Event 29:

  ```text
  HTTP 404
  ```
  Event 82:

  ```text
  https://www.fortanix.com/pricing                                       HTTP 404
  https://www.fortanix.com/products/data-security-manager/pricing        HTTP 404
  ```

### Kimi K3
[View public run](https://agents.withgauge.com/p/runs/299825c8-9498-4637-891f-bb55b9823dc8) · [Read transcript](https://www.ax-check.com/support.fortanix.com/sessions/kimi.json)
Final output gives pricing as subscription/contact-sales tiered by keys/ops/modules with a ~30-day free trial, explicitly flagged as 'from general knowledge — not verifiable against a live account here' after confirming no public pricing page (404 at seq 41).
#### End-to-end onboarding
- **Onboarding needs a login**: The agent never obtained Fortanix credentials and never reached an authenticated product operation. It found no Fortanix env vars, confirmed the hosted DSM API endpoints (amer.smartkey.io, eu.smartkey.io, smartkey.io) return 502 from the sandbox's egress proxy, and concluded a free-trial signup with email verification was required but not completable in-session. No create/query operation against the real product was ever attempted.
  Event 15:

  ```text
  PI_GATEWAY_API_KEY=***
  ---
  .
  ..
  .cache
  .gauge
  .pi
  .tmp
  repo
  
  ```
  Event 30:

  ```text
  Unauthorized access
  HTTP/2 502 
  server: mitmproxy 12.2.3
  content-type: text/html
  
  
  ```
  Event 43:

  ```text
  Even if the endpoint were reachable, DSM requires an account. Signup is a free trial via email verification, which I can't complete from here, and there are no Fortanix credentials in the environment.
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **Hosted DSM API endpoints blocked by sandbox egress proxy**: The sandbox's network proxy (mitmproxy) returns 502 Unauthorized for all Fortanix DSM SaaS hosts (amer.smartkey.io, eu.smartkey.io, smartkey.io, dsm.fortanix.com), while pypi.org, github.com, and fortanix.com marketing pages pass through fine. This is a test-environment network restriction, not a product defect — the product API itself was never actually exercised to confirm it works.
  Event 22:

  ```text
  amer.smartkey.io: 502
  eu.smartkey.io: 502
  smartkey.io: 502
  dsm.fortanix.com: 000 FAIL
  ```
  Event 30:

  ```text
  Unauthorized access
  HTTP/2 502 
  server: mitmproxy 12.2.3
  content-type: text/html
  
  
  ```
- **No Fortanix account or API key available**: No Fortanix credentials existed in the environment, and creating an account requires a free-trial signup with email verification that the agent could not complete autonomously. This stopped any authenticated SDK usage before it could start.
  Event 12:

  ```text
  env | grep -iE 'fortanix|sdkms|dsm|api'
  ```
  Event 43:

  ```text
  Signup is a free trial via email verification, which I can't complete from here, and there are no Fortanix credentials in the environment.
  ```

#### Suggested Changes
- **Fix the broken /pricing page link**: Requesting https://www.fortanix.com/pricing returns a 404 'Page not found'. Restore or redirect this URL (or link pricing info from the main platform page at /platform/data-security-manager) so visitors researching cost don't hit a dead end. Verify by curling the URL and confirming a 200 with actual pricing content.
  Event 37:

  ```text
  404 | Fortanix Page not found Sorry, something went wrong. You might have typed the address incorrectly or the link may be broken.
  ```

### Qwen 3.8 Max
[View public run](https://agents.withgauge.com/p/runs/8fc5d1a7-7579-45f3-bc7d-5f2d9f076c29) · [Read transcript](https://www.ax-check.com/support.fortanix.com/sessions/qwen.json)
Final output states pricing is 'Not public', quote-based enterprise subscription, citing the 404 on fortanix.com/pricing (confirmed via curl at seq 21/25) and noting it could not verify a self-serve price — assumptions are named even though a hard number isn't given.
#### End-to-end onboarding
- **Onboarding needs a login**: Agent never obtained real Fortanix credentials. It installed the official 'sdkms' PyPI SDK and wrote a working example script, but running it required a FORTANIX_API_KEY that only a human can get by creating an App in the Fortanix DSM web UI. The agent used a dummy key placeholder, which failed at DNS resolution before any auth could even be attempted, and explicitly says it needs the user to supply a real key plus network egress.
  Event 97:

  ```text
  No credentials. Fortanix requires an account; the API key comes from creating an "App" in the DSM web UI and granting it group access. There's no anonymous/self-service path I can complete from a shell.
  ```
  Event 95:

  ```text
  urllib3.exceptions.MaxRetryError: HTTPSConnectionPool(host='sdkms.fortanix.com', port=443): Max retries exceeded with url: /crypto/v1/keys (Caused by NameResolutionError("HTTPSConnection(host='sdkms.fortanix.com', port=443): Failed to resolve 'sdkms.fortanix.com' ([Errno -2] Name or service not known)"))
  ```
  Event 97:

  ```text
  No network path. This sandbox can't reach Fortanix's API endpoints — DNS fails for `sdkms.fortanix.com` and `*.smartkey.io` (their regional SaaS endpoints return 502/fail to resolve).
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No self-service way to get a Fortanix DSM API key**: Fortanix DSM requires creating an account and an 'App' through the web UI to obtain an API key before any SDK call can authenticate. This is normal product behavior (not a defect) but it is a hard stop for an unattended agent session with no human to click through account/app creation.
  Event 97:

  ```text
  the API key comes from creating an "App" in the DSM web UI and granting it group access. There's no anonymous/self-service path I can complete from a shell.
  ```
- **Sandbox network cannot resolve Fortanix's hosted API endpoints**: DNS lookups for sdkms.fortanix.com and all regional smartkey.io endpoints failed or returned 502s, while only the marketing site resolved. This is a test-environment limitation (network egress), confirmed when the example script died on NameResolutionError rather than an auth error.
  Event 8:

  ```text
  curl: (6) Could not resolve host: sdkms.fortanix.com
  000
  200
  
  ```
  Event 14:

  ```text
  sdkms.fortanix.com       000
  us.smartkey.io           000
  asia.smartkey.io         000
  api.fortanix.com         000
  www.fortanix.com         200
  
  ```
  Event 95:

  ```text
  Failed to resolve 'sdkms.fortanix.com' ([Errno -2] Name or service not known)
  ```
- **SDK Configuration API mismatch required a code fix**: Agent error (minor, self-corrected): the agent initially called Configuration(host=API_URL) based on common SDK conventions, but the installed sdkms package's Configuration takes no constructor args and exposes host as a settable attribute instead. The agent diagnosed this via introspection and patched the script successfully, so this was not an unresolved blocker.
  Event 83:

  ```text
  TypeError: Configuration.__init__() got an unexpected keyword argument 'host'
  ```
  Event 91:

  ```text
  config = Configuration()
  +40     config.host = API_URL
  ```

#### Suggested Changes
- **Publish a public pricing page instead of a 404 at /pricing**: Fetching https://www.fortanix.com/pricing returned a 404, forcing the agent to report pricing as entirely sales-gated with no self-serve tiers. Adding a real pricing page (or redirecting to one) at that path would let evaluators and prospective developers see cost before talking to sales; verify by curling www.fortanix.com/pricing and confirming a 200 with actual tier/price content.
  Event 25:

  ```text
  404 https://www.fortanix.com/pricing
  ```
- **List the PyPI 'sdkms' package name on the product's developer docs**: The agent had to guess package names (fortanix-sdkms, fortanix-dsm, pyfortanix all 404'd on PyPI) before stumbling on the correctly-named 'sdkms' package via a broader npm/pypi search. Clearly naming the exact PyPI install command (e.g. 'pip install sdkms') on the quickstart/docs page would save this trial-and-error; verify by checking that pip install <documented-name> succeeds on the first try.
  Event 15:

  ```text
  ERROR: No matching distribution found for fortanix-sdkms
  ERROR: Could not find a version that satisfies the requirement fortanix-sdkms (from versions: none)
  ```
  Event 32:

  ```text
  fortanix-sdkms   404
  sdkms            200
  fortanix-dsm     404
  pyfortanix       404
  fortanix         404
  ```

### Task given to each agent
Help me build a simple example using Fortanix. Tell me how pricing works, and briefly tell me whether this product will be easy for you to manage. Let me know if you get blocked. If this product has no developer workflow you can act on, say so plainly and stop. Stay light: use the hosted product through its SDK or API. Do not start local service stacks or wait for long-running commands; if the quickstart requires either, say so plainly and stop.

No product credentials were supplied and no purchases were authorized.

## Score: A · 100/100 (provisional)
Grades come from completed site checks. Coding sessions and skipped checks do not affect the score.

### Clarity
- **Pass** — Homepage answers Markdown requests

  ```text
  Homepage returned text/plain Markdown (200) when requested with text/markdown accept header.
  ```

- **Pass** — llms.txt provides an actionable documentation index

  ```text
  llms.txt (200) lists extensive docs with .md links, quickstarts, SDK, CLI and API references.
  ```

- **Pass** — llms.txt provides navigation guidance

  ```text
  llms.txt organizes docs under a v1 heading with titled, grouped documentation links.
  ```

- **Pass** — llms.txt mentions offered API, MCP, and skills

  ```text
  llms.txt links API docs, SDKs, CLI, and DSM Accelerator webservice surfaces.
  ```

- **Pass** — A compact guide representation exists

  ```text
  llms.txt and .md pages provide a compact Markdown representation of the docs.
  ```

- **Pass** — A focused guide is directly retrievable

  ```text
  Quickstart .md is directly retrievable with concrete SaaS and on-prem first steps.
  ```

- **Pass** — Equivalent instructions fit a token budget

  ```text
  Quickstart Markdown is 1049 tokens, well under the 8000-token budget.
  ```

- **Pass** — Product-docs links survive format changes

  ```text
  Homepage Markdown supported; docs links like /docs/quickstart persist across representations.
  ```

- **Pass** — The compact guide is independently actionable

  ```text
  Quickstart gives concrete steps: free trial signup, pre-install requirements, on-prem/cloud install, downloads.
  ```

- **Pass** — Install and next-step links resolve

  ```text
  Fetched quickstart and its install/next-step pages returned HTTP 200.
  ```


### Onboarding
- **Pass** — Docs lead to a relevant quickstart

  ```text
  llms.txt and quickstart index lead to Fortanix DSM Quickstart with SaaS and on-prem deployment steps.
  ```

- **Pass** — Installation commands are extractable

  ```text
  CLI doc gives installable sdkms-cli with commands; EM-CLI shows 'cargo install em-cli'.
  ```

- **Pass** — Code examples are available without interaction

  ```text
  CLI page shows inline bash examples for login, key creation, import, and encryption.
  ```

- **Pass** — Prerequisites and auth boundaries are explicit

  ```text
  CLI doc states user vs app auth, API key login, and pre-installation requirements.
  ```


### Pricing
- **Skipped** — Pricing is readable without interaction

  ```text
  No pricing page fetched; only the Fortanix documentation homepage was retrieved.
  ```

- **Skipped** — Prices are stated, not gated

  ```text
  No pricing page fetched; no prices stated in the fetched documentation homepage.
  ```

- **Skipped** — Pricing units and limits are explicit

  ```text
  No pricing page fetched; pricing units and limits not present in evidence.
  ```

- **Pass** — Agents identify pricing and its assumptions

  ```text
  3 of 3 sessions were judged on pricing; 0 fell short. DeepSeek V4.1 Flash: README Pricing section states enterprise/quote-based cost with explicit assumptions: monthly subscription, minimum 1-year term, 30-day trial, metered crypto operations, separate on-prem/marketplace licensing. Kimi K3: Final output gives pricing as subscription/contact-sales tiered by keys/ops/modules with a ~30-day free trial, explicitly flagged as 'from general knowledge — not verifiable against a live account here' after confirming no public pricing page (404 at seq 41). Qwen 3.8 Max: Final output states pricing is 'Not public', quote-based enterprise subscription, citing the 404 on fortanix.com/pricing (confirmed via curl at seq 21/25) and noting it could not verify a self-serve price — assumptions are named even though a hard number isn't given. This behavioural item does not affect the fast grade.
  ```


### Activation
- **Pass** — An API reference or OpenAPI spec is reachable

  ```text
  llms.txt links 'DSM API Documentation' and 'DSM REST APIs' pages for the Fortanix DSM REST interface.
  ```

- **Skipped** — An MCP server is documented and well-formed

  ```text
  No MCP server documentation appears in the fetched Fortanix support pages or llms.txt index.
  ```

- **Pass** — A CLI install path is documented

  ```text
  sdkms-cli page documents install/download, login, and many commands; em-cli installs via cargo.
  ```

- **Skipped** — SDK packages resolve on their registries

  ```text
  No registry lookup result for a Fortanix SDK or CLI package was supplied.
  ```

- **Skipped** — Agent skills are published

  ```text
  No agent skills are documented in the fetched Fortanix support pages or llms.txt.
  ```



[Full report data](https://www.ax-check.com/support.fortanix.com/report.json)
