pki.sgit.ai / registry / record

fixture-agent-a — valid, accepted mandate

One record in the register: sha256:df2bb4d93af69e6a — 2 signed statements, appended in order and never edited. This page renders the record; the files beside it are the record.

FIXTURE — the private half of this keypair is published in this repository.

Every signature in this record verifies, and none of them proves anything: anybody who can read this site can produce more. This is not a weak identity, it is no identity — which is why the class is read before any signature is checked, and why it is the first thing on this page.

The published key material is deliberate: the register exists so other agents and sites can consume grants and mandates, and that needs runnable examples more than it needs secrecy at this stage.

What the register answers about it

Published as data at views/expected-verifications.json, as of 2026-08-25T12:00:00Z — and reproduced by the validator on every release, which is what makes it an acceptance test rather than a claim.

Asked aboutAnswerBecause
repo.pull-request.createYESvalid mandate, accepted, issuer is a root

The signed statements

In file order, which is append order. Nothing here was rewritten: a revocation is a later statement, not a deletion, and a superseded statement stays readable underneath it.

identity 2026-08-25T09:00:00Z rendered & raw → the signed file

The first statement in every record: the public halves, the agent type, and — read before any signature — whether the private half is published.

agent typellm-session labelfixture-agent-a — valid, accepted mandate signing fingerprintsha256:df2bb4d93af69e6a encryption fingerprintsha256:23adfc16615b50ef private key publishedYES — this is a fixture, not an identity signed bysha256:df2bb4d93af69e6a statement hashsha256:ff8e696d1a61f3b8dc852c93281f2718822da37f7c2e130577a8a804c72b5a1b
acceptance 2026-08-25T09:20:00Z rendered & raw → the signed file

The subject's own signature over the issuer's statement. A mandate the subject never accepted is inert (pack decision 8, provisional).

acceptsa mandate in record sha256:90f97984b9cf3930 statementsha256:e572d490272cc517d3fe0783193b539c06bb9f06bf19334ca02619a926e7c45d signed bysha256:df2bb4d93af69e6a statement hashsha256:3dc5fb9c633c78e7ce630655857e0edc2541f05bfb373d323845315155281e6e

Mandates naming it as subject

A mandate lives in the issuer's record, not the subject's — the issuer is who signed it. This list is the convenience index reading the other way.

Key material

Linked, never printed on this page — a rendered page has no business carrying a key, even one published on purpose.

public/encrypt.pem public/sign.pem
private/encrypt.pem private/sign.pem

The private halves are published because this is a fixture. That is the whole point of the class.

This record elsewhere