Get trusted signing public keys (DEPRECATED — self-asserted)
Operations
Get trusted signing public keys (DEPRECATED — self-asserted)
Public keys used for receipt signature verification (current + previous during rotation). DEPRECATED (OSS-013): this response is SELF-ASSERTED and UNSIGNED — the producer vouches for itself. It MUST NOT be treated as a trust root by an updated verifier. Use the SIGNED, versioned, Rekor-anchored key registry at /v1/.well-known/trust-registry instead. This endpoint stays available during the migration window (design §9.3) and is removed at the end of it.
GET
Get trusted signing public keys (DEPRECATED — self-asserted)
Response
200 - application/json
Default Response