pki.sgit.ai / packs / registry-mvp / keys-and-signatures

13 — Keys and signatures

PackThe Registry MVP: Open Data, A Single Operator, LLM Sessions First RoleA key belongs to whatever can keep a secret — everything else is signed by something that can Date20 August 2026 · draft-1 + change control OriginSite agent, this repo Sourceraw markdown · on GitHub

Summary

Which things in this design get keypairs, and why the answer is fewer than proposed. Two principles adopted: a secret is defined by expectation, not by content (which explains the estate's existing key rules in one line, and needs the intention recorded at issue, because a deliberate publication and a leak are indistinguishable afterwards); and a signature's value comes entirely from the scarcity of the private half. One proposal declined — per-object keypairs with the private half published — because it leaves a hash wearing a signature's clothes, defeats its own stated use, and would make C3's fixture flag true on every row. A flag that is always true is a column, not evidence, so declining the proposal is what preserves C3 rather than conservatism.

Key concepts

Key ideas

Read the document

📄 Pack document · 13__keys-and-signatures.md · rendered from the raw markdown (the source of truth)