{"alg":"ed25519","canon":"JSON with object keys sorted, then UTF-8 bytes","how":"A `signed` block names `keyId`, the `fields` it covers — a list of field names in that order, or \"document\" for the whole answer with `signed` removed — and a base64 signature. Rebuild those bytes and verify with the key below whose id matches.","card":"The agent card is signed the way A2A defines instead: a `signatures` array of JWS entries. The payload is the card with `signatures` removed, canonicalised as above; the signing input is `protected` + \".\" + base64url of those bytes, and `alg` is EdDSA over the same key.","keys":[{"keyId":"E84xNrn4yKd23dVAc9XpmUEX6qutjGDizompmYKtSPEY","alg":"ed25519","publicKeyBase58":"E84xNrn4yKd23dVAc9XpmUEX6qutjGDizompmYKtSPEY","owner":"key:E84xNrn4yKd23dVAc9XpmUEX6qutjGDizompmYKtSPEY","use":["agent card","time pulses","verdicts","paid answers","model receipts"]}],"retired":[],"more":"https://brick.blue/api/v1/services"}