{"alg":"Ed25519","key_id":"95fc733781e2bb04","public_key_pem":"-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEA3spaXUCOoNRI/D5Kz3XfpZl52bLv+kOKkQLGsHnaSyU=\n-----END PUBLIC KEY-----\n","canonicalization":"JSON with object keys sorted recursively at every level, arrays in order, no insignificant whitespace. For a certified extract, apply this to the certified_extract object exactly as received (extract_id included). For an answer receipt, apply it to the receipt object with the signature field removed (receipt_id included). The same key signs both.","verify_node":"crypto.verify(null, Buffer.from(canonicalJson(signedObject)), crypto.createPublicKey(pem), Buffer.from(sig_b64, \"base64\"))","verify_python":"cryptography.hazmat.primitives.asymmetric.ed25519.Ed25519PublicKey verify(sig, canonical_json_bytes) after serialization.load_pem_public_key(pem)","verify_answer_receipt":"Same verify_node / verify_python calls. Pass the answer_receipt object with signature removed (kind \"answer_receipt\", receipt_id included) instead of certified_extract. Same key_id, same canonicalization, same public key. A valid signature does not turn the receipt into a series certified extract.","what_a_valid_signature_proves":"That this exact extract or answer receipt, byte for byte under the rule above, was issued by this service. It does not by itself prove the underlying value is current - read the artifact's limitations. An answer receipt (kind answer_receipt) is not a series certified extract and is not legal advice.","endpoint":"https://afriref.dev/v1/certified/{country}/{series}","answer_receipts":"Paid answers embed a receipt when the request sets receipt: true (JSON boolean, or query receipt=true). It is included in the answer price. Verify the receipt object with the signature field removed. A receipt is not issued on HTTP 402 or on a free refusal.","kinds":{"certified_extract":{"endpoint":"https://afriref.dev/v1/certified/{country}/{series}","note":"Series certified extract. Separate product from answer receipts."},"answer_receipt":{"kind":"answer_receipt","request":"POST a paid /v1/answers/* body with receipt:true (default false). Included in the answer's existing price; no extra charge. Present only on a paid HTTP 200 - not on 402 or free 4xx.","note":"Shares this key and this canonicalization rule. Not a series certified extract."}}}