Aqta / Seal issuer signing keys (Ed25519, base64url, no padding) A receipt verifies against the key that was current when it was signed. Retired keys stay listed here permanently: receipts signed under them remain valid evidence, and removing a key would invalidate them. current 9Y3Eiq6V8QjRDUM5nPqSwKIOPQaoEU4SbagfYFdvWa4 from 2026-08-09 retired gUoUhIvptKAoLTnry3VrDtOQEWggGQveLrHFVrfNqmE 2026-04-21 to 2026-08-09 Rotation of 2026-08-09: the previous signing key became unrecoverable when the account holding it was suspended. No receipt was compromised and no receipt was invalidated. Receipts signed before that date verify against the retired key, exactly as they always did. Verify any receipt yourself: npx aqta-verify-receipt receipt.json --key