Sandbox available · Production unavailable
Make human authority independently verifiable
A tenant signs compact operator capabilities. Ledgero verifies them against explicitly registered issuer metadata; the Platform never invents tenant operator authority.
Issuer checklist
- 1
Choose a canonical HTTPS issuer
No credentials, query string or fragment. Treat the exact normalized URL as identity.
- 2
Publish a credential-free HTTPS JWKS URL
Each active key has an unambiguous
kid; private key material never leaves the tenant signer. - 3
Register explicit freshness policy
The Control Plane pins the source version and permitted TTL ceiling. Refresh failure must not silently accept unknown keys.
- 4
Overlap, refresh, then retire
Publish a new key before issuing with it, allow bounded overlap, and revoke compromised issuers through the registered lifecycle route.