{"valid":true,"store_identity":{"name":"SCVD General Store","what":"A human-run general store selling small signed goods to autonomous agents, paid over x402 in USDC on Base, Polygon, or Solana. Also a free conformance desk that checks any issuer's x402 offers and receipts, including stores it competes with.","homepage":"https://scvd.store","verify":"Anyone can check this artifact without asking us and without an account: https://scvd.store/api/verify/{id}, free and permanent. The signing key is at https://scvd.store/.well-known/scvd-signing-key, and the offline verifier is MIT-licensed. The conformance desk is POST https://scvd.store/api/conformance/v1 — send any issuer's x402 signed offer or receipt, ours or not.","rights":"You own what you bought outright and owe this store no credit for it. This block is here so the artifact can explain itself to whoever holds it next, not because attribution is required — see /rights."},"certificate":{"cert_id":"cert_4dww28dx5j","item":"hello","patron_number":1,"date":"2026-07-22T16:16:11.933Z","name":"First Customer"},"signature":"9a4cd68cbea168345fe6537ecb9351d0a8aaed027b4e6c3fff249f9bb7c533f023b9b3eb224149766caf67e06ee61b1201c8d13ce9440ac103dd27b037796201","public_key":"d98ebec640489852c7076aee66615705200971e7d32c54964e173aea3d37e1af","signed_by":{"public_key":"d98ebec640489852c7076aee66615705200971e7d32c54964e173aea3d37e1af","status":"retired","retired_on":"2026-07-31","announcement_id":"handover_1","means":"Signed with a key this store used to publish and has since retired. That is expected on an artifact issued before the handover — and whether THIS artifact was is not left to reassurance: its own date is checked against the key's published service window and the verdict reported beside this field as service_window. Inside the window, retirement does not weaken the signature: the key remains published in key_history precisely so artifacts signed under it stay attributable to this store, and the handover itself is signed by the retiring key and verifiable at its own URL. Dated AFTER the window, the artifact is the exact shape a stolen retired key produces, and service_window says so in those words.","service_window":{"status":"in_service","in_window":true,"in_service_from":"2026-07-22","retired_on":"2026-07-31","artifact_dated":"2026-07-22T16:16:11.933Z","means":"dated 2026-07-22, inside this key's published service window (2026-07-22 to 2026-07-31, inclusive — an artifact dated on the retirement day itself is the expected shape of a handover's last honest signatures)"}},"algorithm":"ed25519","signed_payload":"{\"cert_id\":\"cert_4dww28dx5j\",\"item\":\"hello\",\"patron_number\":1,\"date\":\"2026-07-22T16:16:11.933Z\",\"name\":\"First Customer\"}","artifact_hash":"184f937e87d0a6ba881ea0bc6523890a6994f6566c58e561e2e931721e469eb6","signature_covers":"signed_payload is the exact UTF-8 string this signature covers. What this store signs, who holds the key and whose word you are taking is declared per artifact class at /attestation, including where the trust model is the weakest available. Check it yourself: ed25519_verify(utf8(signed_payload), hex_to_bytes(signature), hex_to_bytes(public_key)). Then compare the fields inside signed_payload against the artifact above — if a field is shown but absent from signed_payload, the signature does not cover it, and this response says so out loud rather than leaving you to discover it. The key is also at /.well-known/scvd-signing-key, so you never have to take ours from this response.","signature_jcs":null,"signature_jcs_covers":"No RFC 8785 signature: this artifact was minted before 2026-08-18, when the store began dual-emitting JCS alongside its declared-field-order discipline. The primary signature above is complete on its own; the JCS signature is interop, not authority.","note":"Genuine article. Signed by the store itself."}