{"keys":[{"kty":"OKP","crv":"Ed25519","x":"BRXGcGHl5M3TxgtRDTHUnGp34Iq7uIr5qzcbla9IZ4c","kid":"kc_XB65l8SUJpjQ","use":"sig","alg":"EdDSA","x_protocol_attestation":{"registry_kid":"xpr_sig_rplFlZ9XKQZW","signature":"Jl9nF1PT8hZhOq8YJ8X1UV7aLC0M6AZZ75AVHc9WRF38YOw1Oa7R4oYI0b_y-6kc0ucYuHJZ9PcoyizIg9g_DA","publisher":"sektor-387-ux-test","key_created_at":"2026-09-09T19:35:52Z","attested_at":"2026-09-09T19:37:36Z","covers":["alg","created_at","kid","public_key","publisher"],"registry_keys_url":"https://x-protocols.com/.well-known/x-protocol/registry-keys.json"}}],"x_protocol_chain":{"how_to_verify":"Pin the registry root out of band. Verify each registry signing key's root_signature at registry_keys_url, then verify a key's x_protocol_attestation signature with the registry key named by its registry_kid, over the SHA-256 of the canonical JSON of the fields it lists in `covers`. Build those fields from THIS key, except `publisher` and `created_at`, which a JWK has no room for and the attestation carries as `publisher` and `key_created_at`. Note `alg` is the KEY algorithm and a JWK publishes it as `crv` (Ed25519); a JWK's own `alg` is the JWS algorithm identifier (EdDSA) and is a different value. A key with no attestation chains to nothing: its signatures are verifiable, but the registry is not telling you whose they are. An attestation binds a key to a PUBLISHER; it says nothing about whether that publisher is verified -- read _authority for that."}}
