Signing keys
Every public key GENYOUINE has ever used to sign a certificate — current and retired, with the dates each was active. A certificate names the key that signed it; a verifier pins these keys and checks the signature itself, without trusting our website. A key id that isn’t on this list must fail as INVALID, never “unknown”.
Public keys are safe to publish — they can only verify, never sign. A retired key stays here forever, because the certificates it signed keep verifying forever.
- key-2026-07-04-14d02654active
- Public key (JWK)
- {"crv":"Ed25519","x":"ZWj5glUVXo3aegiScVYHxILdwiZK120l60NoagfkodQ","kty":"OKP"}
- Active from
- 2026-07-04
- Retired
- —
Production signing key — signs real testimonials.
- key-demo-2026active
- Public key (JWK)
- {"kty":"OKP","crv":"Ed25519","x":"mJVakgs4XIERfULotigPnXzTtHuYwYsh06lBEq6n1QQ"}
- Active from
- 2026-07-03
- Retired
- —
Sample key. Signs only the public sample certificate at /v/demo — never a real testimonial.
- key-demo-attn-2026active
- Public key (JWK)
- {"kty":"OKP","crv":"Ed25519","x":"1HJ7iU84ah_qMYyHNy-diYGPPUJ1E5VnczIuU5VJgSg"}
- Active from
- 2026-08-06
- Retired
- —
Sample key. Signs only the public sample transcript attestation at /p/demo — never a real transcript.
Want to check a certificate yourself? Use the offline verifier (works with your network off), or read the exact byte-level algorithm in docs/CERTIFICATE_SPEC.md.
