{"valid":true,"handover":{"handover_id":"handover_1","outgoing_public_key":"d98ebec640489852c7076aee66615705200971e7d32c54964e173aea3d37e1af","incoming_public_key":"8c22f61add201ecefa75c5d027371b64bed3c0ff739056a7b255f8322ffcb550","announced":"2026-07-31T17:37:13.214Z","reason":"One ed25519 key has signed everything this store has issued since 2026-07-22. It was generated, pushed into a Cloudflare Worker secret, and no copy was kept — not as a decision, but because nobody thought that far ahead yet. Worker secrets are write-only, which is right, and is why there was nothing to retrieve when we sat down on 2026-07-31 to write a paper-backup procedure. Nothing was broken by that. The key worked; every artifact signed under it verifies and always will. What did not exist was any way to survive losing it. So this store is handing over to a key that was written on paper before it signed anything, under the succession protocol published at /attestation, while there are eight settlements behind this counter instead of eight thousand. Building the handover produced the key history this announcement is filed in — and, along the way, the discovery that a signature matching none of our published keys used to be reported as valid with nothing saying so. Filed on /corrections with a date, like everything else we have got wrong.","protocol_url":"https://scvd.store/attestation"},"signature":"8e10570e14ac6ebac86e51839b77ddf6fd8e2b77f1dcb19d3a4a0e304b1cfe8cfa8aeabd7c75e208b490efbb640cdad4f1e080d12315b353db5d53dc50b3930c","public_key":"d98ebec640489852c7076aee66615705200971e7d32c54964e173aea3d37e1af","signed_by":{"public_key":"d98ebec640489852c7076aee66615705200971e7d32c54964e173aea3d37e1af","status":"retired","retired_on":"2026-07-31","announcement_id":"handover_1","means":"Signed with a key this store used to publish and has since retired. That is expected on an artifact issued before the handover — and whether THIS artifact was is not left to reassurance: its own date is checked against the key's published service window and the verdict reported beside this field as service_window. Inside the window, retirement does not weaken the signature: the key remains published in key_history precisely so artifacts signed under it stay attributable to this store, and the handover itself is signed by the retiring key and verifiable at its own URL. Dated AFTER the window, the artifact is the exact shape a stolen retired key produces, and service_window says so in those words.","service_window":{"status":"in_service","in_window":true,"in_service_from":"2026-07-22","retired_on":"2026-07-31","artifact_dated":"2026-07-31T17:37:13.214Z","means":"dated 2026-07-31, inside this key's published service window (2026-07-22 to 2026-07-31, inclusive — an artifact dated on the retirement day itself is the expected shape of a handover's last honest signatures)"}},"algorithm":"ed25519","signed_payload":"{\"handover_id\":\"handover_1\",\"outgoing_public_key\":\"d98ebec640489852c7076aee66615705200971e7d32c54964e173aea3d37e1af\",\"incoming_public_key\":\"8c22f61add201ecefa75c5d027371b64bed3c0ff739056a7b255f8322ffcb550\",\"announced\":\"2026-07-31T17:37:13.214Z\",\"reason\":\"One ed25519 key has signed everything this store has issued since 2026-07-22. It was generated, pushed into a Cloudflare Worker secret, and no copy was kept — not as a decision, but because nobody thought that far ahead yet. Worker secrets are write-only, which is right, and is why there was nothing to retrieve when we sat down on 2026-07-31 to write a paper-backup procedure. Nothing was broken by that. The key worked; every artifact signed under it verifies and always will. What did not exist was any way to survive losing it. So this store is handing over to a key that was written on paper before it signed anything, under the succession protocol published at /attestation, while there are eight settlements behind this counter instead of eight thousand. Building the handover produced the key history this announcement is filed in — and, along the way, the discovery that a signature matching none of our published keys used to be reported as valid with nothing saying so. Filed on /corrections with a date, like everything else we have got wrong.\",\"protocol_url\":\"https://scvd.store/attestation\"}","artifact_hash":"1b4d418f5e7fcc37bf197861a8974940bfcce81763a095ecf8506bb8a35579bd","signature_covers":"signed_payload is the exact UTF-8 string this signature covers. What this store signs, who holds the key and whose word you are taking is declared per artifact class at /attestation, including where the trust model is the weakest available. Check it yourself: ed25519_verify(utf8(signed_payload), hex_to_bytes(signature), hex_to_bytes(public_key)). Then compare the fields inside signed_payload against the artifact above — if a field is shown but absent from signed_payload, the signature does not cover it, and this response says so out loud rather than leaving you to discover it. The key is also at /.well-known/scvd-signing-key, so you never have to take ours from this response.","what_this_is":"This is a key handover announcement, and the signature on it is made by the OUTGOING key — the one being retired. That is the point: only the holder of the retiring key could have produced it, so a handover carrying this signature is distinguishable from somebody who took over the page and changed the key on it. Check it the same way you check anything else here: ed25519_verify(utf8(signed_payload), hex_to_bytes(signature), hex_to_bytes(public_key)), then confirm public_key is the key that was in service before the announced date, listed in key_history at /.well-known/scvd-signing-key.","note":"Genuine handover announcement, signed by the key it retires."}