{"schema":"pe-verification-keys.v1","issuer":"did:web:governor.solarly.ai","keys":[{"kid":"pe-gov-v1-1b5dc5ee8e1f0a0c","kty":"OKP","crv":"Ed25519","alg":"EdDSA","use":"sig","x":"SOUDRTW4-rjotr9YeuUwuBO2rxPrkDOvRvmv4iUgGgo","fingerprint":"1b5dc5ee8e1f0a0cfe7c34f28f8d3b1d624df9bd7df15e52f40b2c7ca3430983","status":"active"}],"signingDomain":"pe-governor/proof/v1","message":"signature covers `pe-governor/proof/v1\\n` + canonical key-sorted JSON of the proof payload","envelope":"proof.payloadHash is the SHA-256 of that exact signing message and must be verified before the signature; proof.keyId, payload.keyId and the key id derived from the published fingerprint must all match","payloadSchemas":["pe-policy-authorization.v1","pe-policy-receipt.v1"],"boundary":"A signed authorization states what the owner's policy permits. It is not a compliance certificate, underwriting, an on-chain proof, or venue-native enforcement.","rotation":"Set PE_GOVERNOR_SIGNING_SEED to a dedicated 32-byte production key. The kid and fingerprint change on rotation; re-read this endpoint before verifying."}