{"statement":"This store's signing infrastructure produced and signed this document at issued_at. That proves the Worker runs and the key signs — infrastructure liveness, nothing more. The keeper fields carry a separate fact, one this store already acts on: his last provable visit to the counter, against the same presence window the shutter uses to refuse human-labor purchases when nobody is provably there.","issued_at":"2026-10-10T14:10:11.270Z","client_nonce":null,"keeper_last_seen":"2026-10-10T13:06:01.623Z","keeper_within_presence_window":true,"presence_window_hours":48,"signature":"f7d0e6c6ab037cede7e9c1bba6e426f5d8986d114cec8cec2661d29d3dbfcee5d9d0df0d8315ad5a01325aa613f8b87ab68f9f5a868f5021844ef2230c6da105","public_key":"8c22f61add201ecefa75c5d027371b64bed3c0ff739056a7b255f8322ffcb550","algorithm":"ed25519","signed_payload":"{\"statement\":\"This store's signing infrastructure produced and signed this document at issued_at. That proves the Worker runs and the key signs — infrastructure liveness, nothing more. The keeper fields carry a separate fact, one this store already acts on: his last provable visit to the counter, against the same presence window the shutter uses to refuse human-labor purchases when nobody is provably there.\",\"issued_at\":\"2026-10-10T14:10:11.270Z\",\"client_nonce\":null,\"keeper_last_seen\":\"2026-10-10T13:06:01.623Z\",\"keeper_within_presence_window\":true,\"presence_window_hours\":48}","how_to_fail_closed":"Fetch this document fresh; never cache it as evidence. It is computed and signed per request, so three signals carry all the meaning: (1) the fetch FAILS — treat the issuer as unreachable and fail closed; (2) keeper_within_presence_window is FALSE — the human half of this store is not provably present, which is exactly when the store itself refuses human-labor purchases, so weight human-dependent promises accordingly; (3) the signature does not verify against the key at /.well-known/scvd-signing-key — treat everything as compromised. A missing beacon is a signal; an old copy of one is not evidence of anything.","anti_replay":"If you need proof this beacon was minted for YOUR request and not replayed from an earlier one, fetch with ?nonce=<a random value you just generated> and check that client_nonce in the signed payload equals what you sent. A signature covering your fresh nonce could not have been produced before you chose it, which defeats a captured-and-replayed beacon during an outage. Without a nonce this document is a cacheable statement and should not be treated as proof of this-instant liveness.","what_this_does_not_prove":"That the keeper is alive or well — an automated signature cannot know that, and this one does not claim it. It proves the infrastructure signs and reports when the keeper last provably stood at the counter. The distinction between those is the same self_signed honesty /attestation applies to everything else here.","key_history":"https://scvd.store/.well-known/scvd-signing-key","succession_protocol":"https://scvd.store/attestation"}