pki.sgit.ai / documents / keys-and-signatures

A Secret Is Defined By Expectation And A Signature By Scarcity

TypeArchitecture brief Versionv0.33.61 Date20 August 2026 AuthorDinis Cruz (project lead) and collaborators LicenceCC BY 4.0 Sourceraw markdown · view on GitHub

Summary

A brief that adopts a proposal's opening principle and its closing pattern and rejects the proposal in between, and says so rather than smoothing the difference. The principle: a secret is defined by expectation rather than by content, which explains read-keys-yes and write-keys-never in one line and sorts key material by intention rather than by class — with the qualification that the intention has to be recorded at issue, since a deliberate publication and a leak are indistinguishable afterwards. The rejection: publishing a private half destroys the integrity it was meant to supply, because a signature's value comes entirely from scarcity, so what is left is a hash wearing a signature's clothes — worse than a hash, because a verifier checks it, succeeds, and concludes something false. And the closing pattern, promoted to the governing rule: an instance generates its own keypair and a project key endorses it, so a key belongs to whatever can keep a secret and everything else is signed by something that can.

Key concepts

Key ideas

On this site

Became document 13 of the registry MVP pack. It reinforces the fixture flag rather than amending it: the flag survives precisely because per-object published keys are declined.

Read the document

📄 Original document · v0.33.61 · 20 August 2026 · rendered from the raw markdown (the source of truth)