Skip to content

Issuer Record, format v1 (final)

Status: final, version 1. Example: spec/xybern-formats-v1/vectors/issuer_record.json.

Served at /.well-known/xybern-issuer/<issuer_id> by every issuer and mirrored at xybern.com/.well-known/xybern-issuers for issuers that opt in (decision D10). A receiver pins issuers by their record, or by the mirror.

Key Meaning
format "xybern-issuer-record-v1"
issuer_id The issuing workspace id
display_name Human name of the issuer
resolver Base URL of the stamp resolver (<resolver>/<stamp_id> returns the public view, ?format=json for machines, POST <resolver>/<stamp_id>/honour for the cross-install handshake)
issuer_record This record's own URL
keys[] {key_id, algorithm, public_key_pem, status}
stamp_format, algorithm "xybern-stamp-v1", "ecdsa-p256-sha256"
status active or retired
published_at ISO 8601 UTC

The record is served over TLS and is not itself signed; the keys it carries are what sign everything else.