Skip to content
PUBLIC-SURFACE LIMITED GO / CUSTOMER-PROCESSING NO-GO. Public information and synthetic examples may remain available; live files, checkout, production package generation, Registry-dependent issuance, and customer activation are paused.
Synthetic sample

Verify the current sample offline

Preserve the ZIP and obtain the sample-only issuer key set separately before disconnecting. The package cannot establish trust using a key from inside itself.

Demonstration trust domain only. This key validates only BRP-SAMPLE-2026-08-0001. It is not a production issuer key and does not imply certification, source truth, compliance, or buyer acceptance.

Download the independently identified inputs

Fail-closed verification sequence

  1. Confirm the downloaded ZIP and separately downloaded JWKS match the SHA-256 values above.

  2. Extract the ZIP into a new empty directory and reject absolute paths, parent traversal, duplicate members, missing members, and undeclared extra members.

  3. Recalculate every manifest-listed file hash and the canonical manifest SHA-256.

  4. Confirm the receipt binds BRP-SAMPLE-2026-08-0001, the manifest hash, and key ID attestlayer-brp-sample-2026-08-0001.

  5. Validate the Ed25519 signature using only the separately downloaded sample JWKS. Any mismatch is a failure.