keyId. Verification needs the public
half of each named key. Parmana serves them without authentication.
Fetch a key
Response
pem field to the verifiers, keyed by keyId:
GET /.well-known/jwks.json lists every key the server holds, as JWKs.
Which keys a record needs
Collect everykeyId the record names:
default (Ed25519) and default-secondary (ML-DSA-65).
Keys in production use
- Fetch once, then pin. Store the keys you trust and pass them in from storage. Fetching a key from the same server at verification time only proves the record matches that server’s current key.
- Rotated keys stay valid. Rotation signs new records under a new
keyId. The server keeps serving the old key while it holds it, and older records still name the oldkeyId, so they remain verifiable. Keep every key you have pinned. - Sandbox and production are separate. Each has its own keys; a record verifies only against the environment that signed it.
- A
KeyObjectworks too.publicKeysvalues may benode:cryptoKeyObjects instead of PEM strings.