{
  "_schema": "eacl-signing-key-anchor-v1",
  "_documentation": "docs/api/sealed-artifact-verification.md#trust-anchor",
  "algorithm": "Ed25519",
  "public_key": "728828e5a9ff076f7113e77b322ebdbfe51e1ec2451dc6119629675e35c1ff7c",
  "key_id": "150899c476f355f1",
  "environment": "staging",
  "status": "populated",
  "generated_context": "Scaffold committed as part of the trust-anchor build. The public_key + key_id fields are populated by the founder at ratify-time from staging's live GET /.well-known/eacl-signing-key.json response — cc has no approved path to obtain the currently-deployed EACL_SIGNING_KEY's public half (the private half is in matrix/staging-matrix-fixture.env, which is out-of-scope for cc; the authenticated /v1/signing-key call requires a staging API key cc does not hold). Founder populates via scripts/populate-signing-anchor.sh <staging_base_url> (post-deploy of this PR's endpoints), commits the populated file in this same PR, and thereby establishes the tamper-evident anchor. Post-populate, the anchor value MUST equal what the live .well-known endpoint serves; the anchor-consistency spec at server/governance/signingKeyDisclosure.spec.ts asserts this in-process (when EACL_SIGNING_KEY is configured in the test runtime). This anchor is DEMONSTRATION — non-canonical; the canonical Genesis signing key is committed at the Genesis tag and this file becomes the pre-Genesis staging attestation."
}
