{
  "schema": "key-history-v1",
  "subject": "https://gate.horizonshield.dev",
  "keys": [
    {
      "use": "agent-card",
      "kid": "hs-2026-09",
      "alg": "ES256",
      "public_jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "CytwnuXFtXi7PFCcF-TCbvW5OgOg4KuWRLeRvdfHWLs",
        "y": "Zha3FI2QplMaGveXjrIg8PxrZ6dTjHmESoGs88uAIiA"
      },
      "served_at": [
        "https://gate.horizonshield.dev/.well-known/jwks.json",
        "https://mcp.horizonshield.dev/.well-known/jwks.json",
        "https://ledger.horizonshield.dev/.well-known/jwks.json",
        "https://jidec.horizonshield.dev/.well-known/jwks.json"
      ],
      "signs": "the A2A section 8.4 JWS signatures on the agent cards of gate, mcp, ledger and jidec",
      "since": "2026-09-06",
      "since_commit": "849a3724",
      "status": "active",
      "retired_at": null,
      "revoked_at": null,
      "compromised_from": null,
      "reason": null
    },
    {
      "use": "agreement",
      "kid": "agreement",
      "alg": "Ed25519",
      "public_key_ed25519_b64": "Q8DJu/tXWNNzsrmIkIUm4r2cR4MYaXNf1E2j+oZi+oo=",
      "served_at": [
        "https://gate.horizonshield.dev/keys/agreement.json"
      ],
      "signs": "a2a-agreement-v1.1 records (the key is also carried inside each record's signed bytes)",
      "since": "2026-09-11",
      "since_commit": "20499efa",
      "status": "active",
      "retired_at": null,
      "revoked_at": null,
      "compromised_from": null,
      "reason": null
    },
    {
      "use": "witness",
      "kid": "witness",
      "alg": "Ed25519",
      "public_key_ed25519_b64": "jYoi4mw714eyuAUJoWwj58BGswDo4n27RNmAmIWZg4w=",
      "served_at": [
        "https://gate.horizonshield.dev/keys/witness.json"
      ],
      "signs": "conduct-witness records, nenrin-witness-observation-v1 replies, and task-bound observations (witness_sig)",
      "since": "2026-09-16",
      "since_commit": "fe2de792",
      "status": "active",
      "retired_at": null,
      "revoked_at": null,
      "compromised_from": null,
      "reason": null
    },
    {
      "use": "operator",
      "kid": "operator",
      "alg": "Ed25519",
      "public_key_ed25519_b64": "fqrEpRuYScHz52eeiuAWAFEeJB3T7VtZJlducNIhzZM=",
      "served_at": [
        "https://gate.horizonshield.dev/keys/operator.json"
      ],
      "signs": "nenrin-authorization-v1 recovery authorizations (TSUGI)",
      "since": "2026-09-20",
      "since_commit": "62745120",
      "status": "active",
      "retired_at": null,
      "revoked_at": null,
      "compromised_from": null,
      "reason": null
    }
  ],
  "rule": [
    "A key not listed here is not this domain's key.",
    "active: signatures by this key are attributable to the operator.",
    "retired: rotated out without compromise; signatures made while it was active stay attributable.",
    "revoked: a signature by this key is attributable only when the signed bytes are shown, by a clock the operator does not control (for example a Bitcoin-anchored timestamp), to have existed before compromised_from. Without that proof it is not attributable.",
    "Any key: signed bytes shown to have existed before since are not attributable (the key did not exist yet)."
  ],
  "history_sha256": "d479e3e036625b87e40cc1d0882e7f569843939d34f193e9e4da9b033559b7a9",
  "history_sha256_covers": "canonical JSON (sorted keys, UTF-8) of {schema, subject, keys, rule}",
  "env_consistency": [
    {
      "use": "agent-card",
      "configured": true,
      "matches_active": true
    },
    {
      "use": "witness",
      "configured": true,
      "matches_active": true
    },
    {
      "use": "operator",
      "configured": true,
      "matches_active": true
    },
    {
      "use": "agreement",
      "configured": true,
      "matches_active": true
    }
  ],
  "anchors": {
    "covers_served_list": true,
    "current": [
      {
        "history_sha256": "d479e3e036625b87e40cc1d0882e7f569843939d34f193e9e4da9b033559b7a9",
        "as_of": "2026-09-28",
        "jidec_entry": 60,
        "ledger_url": "https://ledger.horizonshield.dev/ledger/60",
        "canonical_bytes_url": "https://ledger.horizonshield.dev/ledger/60?format=raw",
        "ots_url": "https://ledger.horizonshield.dev/ledger/60/ots",
        "bitcoin_block": 968923,
        "bitcoin_block_time": "2026-09-28 02:48 UTC",
        "seed_in_repository": "https://github.com/ogasurfproject-jpg/horizon-shield/blob/main/workers/hs-ledger/seed_entry_key_history_2026-09-28.json",
        "seed_commit": "8f2e02c6",
        "zenodo_doi": "10.5281/zenodo.23122049",
        "zenodo_record": "https://zenodo.org/records/23122049"
      }
    ],
    "previous": [],
    "not_covered_by_history_sha256": true,
    "how_to_verify": [
      "Take the canonical bytes (the file in zenodo_record, canonical_bytes_url, or record_canonical in seed_in_repository) and check that their SHA-256 equals history_sha256.",
      "Run ots verify on those bytes with the proof (the .ots file in zenodo_record, or ots_url); it must point to the Bitcoin block named here. The Zenodo record holds both, so no HORIZON SHIELD server is needed."
    ],
    "establishes": "the served list of public keys existed, byte for byte, no later than the Bitcoin block named in the anchor",
    "does_not_establish": "that the keys were not stolen before or after that time; only when this list was fixed"
  },
  "spec": "https://github.com/ogasurfproject-jpg/horizon-shield/blob/main/workers/hs-verify-gate/ext/KEY_HISTORY_v1.md",
  "does_not_establish": [
    "that no key has been stolen; only what the operator has declared",
    "that a signature by an active key was made by the operator and not by someone who took the key without the operator knowing",
    "anything about a record's content; it says only whose key signed it and under which rule that counts"
  ]
}