{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "schema": "summit.decrec.signing-public-key-registry.v1",
  "service": "https://decrec.summitcognitive.ai",
  "generated_at": "2026-08-25T05:15:00Z",
  "private_key_material_allowed": false,
  "keys": [
    {
      "key_id": "sha256:776d85c1dd13e223a690d7afd51cc5c272f36286921af7adcfcf5023f9203b0b",
      "algorithm": "Ed25519",
      "public_key_spki_der_base64": "MCowBQYDK2VwAyEA0l8ksb0nlKRq7C1EIMNXALB6iV3OcVQ9ncD8OrtlIMQ=",
      "spki_sha256": "776d85c1dd13e223a690d7afd51cc5c272f36286921af7adcfcf5023f9203b0b",
      "status": "retired",
      "sequence_start": 1,
      "sequence_end": 1463,
      "first_verified_receipt": {
        "receipt_id": "rcpt_gh-BrianCLong-summit-pr-35342-cea6992_mq7208ce",
        "chain_sequence": 1,
        "generated_at": "2026-06-09T19:49:44.133Z"
      },
      "provenance": [
        {
          "kind": "release_evidence",
          "source": "Recovered signer for chain sequences 1-1463. This public key verifies the Ed25519 signatures on the 1,397 signed receipts in that range; the current active key does not. Falsifiable: fetch any receipt with chain_sequence <= 1463 via /v1/receipts/{id} and verify its signature against this key. Within the range, sequence 1429 was signed by the active key sha256:9bd4ac8f, and 59 receipts (sequences 1099-1157) plus 6 with unavailable artifacts carry no signature to check.",
          "observed_at": "2026-08-25T05:00:00Z"
        },
        {
          "kind": "release_evidence",
          "source": "Private half recovered from the production host signing-key store; public half published here. Its key file predates the range's genesis receipt (2026-06-09). These signatures were present in the public ledger and reported as historical_key_unavailable by /v1/chain/audit before recovery, so this is the recovered signer of record, not a re-signing. What is cryptographically proven is that this key produced these signatures; that it was the original historical signer is inferred from that, not provable from a signature alone.",
          "observed_at": "2026-08-25T05:05:00Z"
        }
      ]
    },
    {
      "key_id": "sha256:9bd4ac8f0c0eef8a96be6fcc47a0fc0d0f5f176170a29aa7206b06daa32285cc",
      "algorithm": "Ed25519",
      "public_key_spki_der_base64": "MCowBQYDK2VwAyEAA/KA4S81ngCsicIKeNKYBgZVw502hV6I4Ma0T8/NURc=",
      "spki_sha256": "9bd4ac8f0c0eef8a96be6fcc47a0fc0d0f5f176170a29aa7206b06daa32285cc",
      "status": "active",
      "sequence_start": 1464,
      "sequence_end": null,
      "first_verified_receipt": {
        "receipt_id": "rcpt_gh-BrianCLong-summit-pr-36301-4c462ab_mrcujjyc",
        "chain_sequence": 1464,
        "generated_at": "2026-07-09T01:47:08.103Z"
      },
      "provenance": [
        {
          "kind": "public_https_endpoint",
          "source": "https://decrec.summitcognitive.ai/v1/keys/server",
          "observed_at": "2026-07-22T18:45:00Z"
        },
        {
          "kind": "verified_backup_member",
          "source": "decrec-state-20260708T023001Z.tar.gz:./signing-key.pub.pem",
          "observed_at": "2026-07-22T18:56:00Z"
        },
        {
          "kind": "verified_backup_member",
          "source": "decrec-state-20260709T023001Z.tar.gz:./signing-key.pub.pem",
          "observed_at": "2026-07-22T18:56:00Z"
        }
      ]
    }
  ],
  "coverage_gaps": []
}