Issuer Record, format v1 (final)¶
Status: final, version 1. Example: spec/xybern-formats-v1/vectors/issuer_record.json.
Served at /.well-known/xybern-issuer/<issuer_id> by every issuer and mirrored at xybern.com/.well-known/xybern-issuers for issuers that opt in (decision D10). A receiver pins issuers by their record, or by the mirror.
| Key | Meaning |
|---|---|
format |
"xybern-issuer-record-v1" |
issuer_id |
The issuing workspace id |
display_name |
Human name of the issuer |
resolver |
Base URL of the stamp resolver (<resolver>/<stamp_id> returns the public view, ?format=json for machines, POST <resolver>/<stamp_id>/honour for the cross-install handshake) |
issuer_record |
This record's own URL |
keys[] |
{key_id, algorithm, public_key_pem, status} |
stamp_format, algorithm |
"xybern-stamp-v1", "ecdsa-p256-sha256" |
status |
active or retired |
published_at |
ISO 8601 UTC |
The record is served over TLS and is not itself signed; the keys it carries are what sign everything else.