# ED25519 PUBLIC KEY — INDEPENDENT VERIFICATION

Technical documentation for performing offline, independent verification of VerixID ledger records using the Ed25519 signature scheme. Developers, security auditors, and AI agent platforms can validate record authenticity independently without relying on operational VerixID infrastructure.

---

## PUBLIC KEY SPECIFICATIONS

| Parameter | Specification |
| :--- | :--- |
| **Algorithm** | Ed25519 (Edwards-curve Digital Signature Algorithm) |
| **Distribution Format** | PEM (PKCS#8) |
| **Well-Known URI** | `https://verixid.com/.well-known/verixid-public-key.pem` (RFC 8615) |
| **Primary Function** | Cryptographic signing of record payloads during submission processing |
| **Private Key Policy** | Managed exclusively via isolated server-side secrets (never exposed client-side or in browsers) |

---

## CANONICAL PAYLOAD & VERIFICATION PROCEDURE

### Canonical JSON Payload Structure
Digital signatures are derived from a canonical JSON payload with lexicographically sorted keys:

```json
{
  "record_id": "<vxYYYYMMxxxxxxxx>",
  "hash1": "<sha256_hex>",
  "server_timestamp": "<ISO8601_UTC>",
  "ownership_key_hash": "<sha256_hex>"
}