---
schema: formation.trust_keys/v0.1
kind: trust_keys
created_at: '2026-09-22T13:50:19Z'
visibility: public
sequence: 1
keys:
  - key_id: 'key_7886bf6da1d056cf3859e8a7909d3703'
    algorithm: ed25519
    public_key: 'arGM6geHR1t2oROCFjuA08zXmynWzfPnAgi1i-r_ME8'
    fingerprint: 'sha256:7886bf6da1d056cf3859e8a7909d3703f3be0f8e5cfcdab0b1d85ad233f80686'
    status: active
    activated_at: '2026-09-22T13:50:19Z'
---

# Topology Index signing keys

These Ed25519 keys verify detached artifact signatures (`SIGNATURE.md`). The key records are in the frontmatter.

- `active` keys sign new artifacts.
- `retired` keys no longer sign. Signatures they issued between `activated_at` and `retired_at` still verify.
- `revoked` keys are not trusted for any signature, whatever issuance time it claims.

## Trust bootstrap

Do not trust a key only because this document lists it: this document and the artifacts it vouches for come from the same origin. Compare each `fingerprint`, the SHA-256 digest of the raw 32-byte public key, with a fingerprint distributed with a trusted CLI or package release, or with explicitly approved configuration.

## Current status

This document is mutable. `sequence` increases with every change. Discard a copy whose sequence is lower than one already seen, and fetch a fresh copy before relying on the status of a key.
