fixture-agent-c — mandate expired
One record in the register: sha256:f32e7a1da4e098e0 —
2 signed statements, appended in
order and never edited. This page renders the record; the files beside it are the record.
Every signature in this record verifies, and none of them proves anything: anybody who can read this site can produce more. This is not a weak identity, it is no identity — which is why the class is read before any signature is checked, and why it is the first thing on this page.
The published key material is deliberate: the register exists so other agents and sites can consume grants and mandates, and that needs runnable examples more than it needs secrecy at this stage.
What the register answers about it
Published as data at views/expected-verifications.json, as of 2026-08-25T12:00:00Z — and reproduced by the validator on every release, which is what makes it an acceptance test rather than a claim.
| Asked about | Answer | Because |
|---|---|---|
repo.pull-request.create | NO | mandate expired 2026-08-01 |
The signed statements
In file order, which is append order. Nothing here was rewritten: a revocation is a later statement, not a deletion, and a superseded statement stays readable underneath it.
The first statement in every record: the public halves, the agent type, and — read before any signature — whether the private half is published.
sha256:f32e7a1da4e098e0
encryption fingerprintsha256:448a5aefe255bfce
private key publishedYES — this is a fixture, not an identity
signed bysha256:f32e7a1da4e098e0
statement hashsha256:1fbddbc54751c753bd9a4ac258930f861042ad9f278edc5ca859abef68a85ae5
The subject's own signature over the issuer's statement. A mandate the subject never accepted is inert (pack decision 8, provisional).
sha256:90f97984b9cf3930
statementsha256:834e29ab87165620f816526a752c25c0df6515af9fe35cf5b62b823137dcb624
signed bysha256:f32e7a1da4e098e0
statement hashsha256:11cd55870e903f31d0d612c3072f99e899dd829dfd44559bd31fd4a75331ea9a
Mandates naming it as subject
A mandate lives in the issuer's record, not the subject's — the issuer is who signed it. This list is the convenience index reading the other way.
repo.pull-request.create— issued bysha256:90f97984b9cf3930, in that record
Key material
Linked, never printed on this page — a rendered page has no business carrying a key, even one published on purpose.
public/encrypt.pem public/sign.pem
private/encrypt.pem private/sign.pem
The private halves are published because this is a fixture. That is the whole point of the class.
This record elsewhere
- record.json
(raw) — the unsigned manifest (its own
_authorityfield says NONE; it is regenerable from the statements) - The register — all eleven records, and the verification walk
- The workbench — the same records as cards, and a simulator that decides an action against a mandate
- on GitHub