{
  "fingerprint_format": "SHA-256 of DER SubjectPublicKeyInfo (lowercase hex)",
  "keys": [
    {
      "alg": "ES256",
      "description": "Verifies Civarro approval of an attested reader boot key for a specific vault, record and processing region. The vault must also verify fresh request possession, native SNP evidence and patient policy.",
      "kid": "spki-sha256-0b9412c748e0697e77f681ef44c213148020b99430da08a0b1a5dad18e3b9fa2",
      "pem_url": "https://trust.civarro.net/keys/spki-sha256-0b9412c748e0697e77f681ef44c213148020b99430da08a0b1a5dad18e3b9fa2.pem",
      "proof_url": "https://trust.civarro.net/keys/spki-sha256-0b9412c748e0697e77f681ef44c213148020b99430da08a0b1a5dad18e3b9fa2.proof.json",
      "purpose": "Chronovault reader approval",
      "spki_sha256": "0b9412c748e0697e77f681ef44c213148020b99430da08a0b1a5dad18e3b9fa2",
      "status": "active"
    },
    {
      "alg": "ES256",
      "description": "Civarro release approval and redistribution. Does not authenticate the upstream author or authorize a Chronovault reader.",
      "kid": "spki-sha256-fb1483ec47e11cd271062266db7c79a7519632ac956759eb3d792e9d73f2c0aa",
      "pem_url": "https://trust.civarro.net/keys/spki-sha256-fb1483ec47e11cd271062266db7c79a7519632ac956759eb3d792e9d73f2c0aa.pem",
      "proof_url": "https://trust.civarro.net/keys/spki-sha256-fb1483ec47e11cd271062266db7c79a7519632ac956759eb3d792e9d73f2c0aa.proof.json",
      "purpose": "OCI image release approval",
      "spki_sha256": "fb1483ec47e11cd271062266db7c79a7519632ac956759eb3d792e9d73f2c0aa",
      "status": "active"
    }
  ],
  "version": 1
}
