{
  "issuer": "isao.org.uk",
  "algorithm": "Ed25519",
  "encoding": "base64url",
  "trust": "Only these keys verify ISAO signatures. A retired key verifies only signatures made before its retirement; a revoked key verifies none.",
  "keys": [
    {
      "id": "isao-2026-01",
      "publicKey": "r3IhimrAcXYasoob5Ez2uMw52A1CrLhW6V2-AESuF24",
      "status": "active",
      "createdAt": "2026-10-02T05:41:07.917Z",
      "retiredAt": null,
      "revokedAt": null
    }
  ],
  "payload": {
    "version": 3,
    "fields": [
      "type",
      "number",
      "revision",
      "holderName",
      "standards",
      "scopeText",
      "issueDate",
      "expiryDate",
      "issuer",
      "publicCode",
      "payloadVersion",
      "validFrom",
      "auditReportNo",
      "placeOfIssue",
      "issuingOffice",
      "mainCertificateNumber",
      "recognitionMarks",
      "signedAt",
      "originalIssueDate",
      "sectorCodes",
      "holder",
      "sites",
      "issuerAccreditationNumber",
      "accreditation",
      "auditor",
      "documentDigest"
    ],
    "versions": [
      {
        "version": 1,
        "fields": [
          "type",
          "number",
          "revision",
          "holderName",
          "standards",
          "scopeText",
          "issueDate",
          "expiryDate",
          "issuer",
          "publicCode"
        ],
        "description": "The original payload, for certificates signed before payload version 2 was introduced (September 2026). No payloadVersion field.",
        "fieldNotes": {
          "number": "The certificate number without the revision suffix.",
          "issuer": "The issuing certification body's legal name, or ISAO's legal name for certificates ISAO issues itself.",
          "standards": "Standard codes in the order printed."
        }
      },
      {
        "version": 2,
        "fields": [
          "type",
          "number",
          "revision",
          "holderName",
          "standards",
          "scopeText",
          "issueDate",
          "expiryDate",
          "issuer",
          "publicCode",
          "payloadVersion",
          "validFrom",
          "auditReportNo",
          "placeOfIssue",
          "issuingOffice",
          "mainCertificateNumber",
          "recognitionMarks"
        ],
        "description": "Version 1 plus the printed certificate fields: valid-from date, audit report number, place of issue, issuing office, main certificate number and recognition marks.",
        "fieldNotes": {
          "payloadVersion": "The number 2.",
          "validFrom": "The first day of validity as printed (\"Valid from\"): the certificate's valid-from date, or its issue date. YYYY-MM-DD.",
          "auditReportNo": "The audit report number as recorded, or null.",
          "placeOfIssue": "The place of issue as recorded (for example \"Mumbai\"), or null.",
          "issuingOffice": "The issuing office printed in the footer, as recorded at issue: { name, addressLines, website } (website null when there is none), or null.",
          "mainCertificateNumber": "For a site or sub-certificate: the main certificate's number as printed, with its revision suffix (for example \"ABC-QMS-26-00001 R1\"); otherwise null.",
          "recognitionMarks": "Names of the recognition marks printed on the certificate, in print order ([] when none)."
        }
      },
      {
        "version": 3,
        "fields": [
          "type",
          "number",
          "revision",
          "holderName",
          "standards",
          "scopeText",
          "issueDate",
          "expiryDate",
          "issuer",
          "publicCode",
          "payloadVersion",
          "validFrom",
          "auditReportNo",
          "placeOfIssue",
          "issuingOffice",
          "mainCertificateNumber",
          "recognitionMarks",
          "signedAt",
          "originalIssueDate",
          "sectorCodes",
          "holder",
          "sites",
          "issuerAccreditationNumber",
          "accreditation",
          "auditor",
          "documentDigest"
        ],
        "description": "Version 2 with the issuer name as printed, the signing time, the initial certification date, the IAF sector codes, the holder's and sites' details as certified, the accreditation details printed on the certificate, and a digest of the whole frozen certificate document.",
        "fieldNotes": {
          "payloadVersion": "The number 3.",
          "issuer": "The issuer's name as printed on the certificate (a certification body's later change of legal name does not change it).",
          "signedAt": "When the certificate was signed: ISO 8601 UTC with milliseconds, for example \"2026-10-02T09:14:05.123Z\".",
          "originalIssueDate": "The initial certification date as printed (\"Initial certification\"), YYYY-MM-DD, or null.",
          "sectorCodes": "IAF sector codes as recorded: trimmed, without duplicates, in numeric order ([] when none).",
          "holder": "The holder as certified: { tradingNames, addressLines (as printed, country last), city, countryCode (ISO 3166-1 alpha-2) }; city and countryCode are null when not recorded.",
          "sites": "The sites as certified, in print order: { name, addressLines, activities, city, countryCode } ([] when none).",
          "issuerAccreditationNumber": "The certification body's ISAO accreditation number as recorded at issue, or null (always null when ISAO issued the certificate itself).",
          "accreditation": "Certificates of accreditation: the schedule as printed, { number, firstGrantedAt, scopes: [{ standardCode, sectorCodes, countries, validFrom, validTo }] }; otherwise null.",
          "auditor": "Auditor registrations: { grade, standards, registrationNo } as printed; otherwise null.",
          "documentDigest": "Hex SHA-256 of the canonical JSON of the frozen certificate document ISAO stores (logos, signatories, wording, layout options, artwork and planned surveillance). Only ISAO can recompute it; any change to the stored document breaks the signature."
        }
      }
    ],
    "versioning": "A version 3 payload carries \"payloadVersion\": 3, a version 2 payload \"payloadVersion\": 2; a version 1 payload has no payloadVersion field. New signatures use version 3 (version 2 for a certificate without a frozen document). A certificate keeps the version it was signed with: its content hash is the SHA-256 of exactly that payload. The verification API returns the payload in the version the certificate was signed with.",
    "canonicalisation": "JSON Canonicalization Scheme (RFC 8785): object keys sorted by UTF-16 code units, arrays kept in order, no whitespace, strings and numbers serialised as ECMAScript JSON.stringify.",
    "hash": "SHA-256",
    "signedMessage": "The Ed25519 signature (RFC 8032) covers the UTF-8 bytes of the canonical JSON. The content hash is the hex SHA-256 of the same bytes.",
    "dates": "issueDate, expiryDate, validFrom and originalIssueDate are YYYY-MM-DD strings (UTC) or null. signedAt is an ISO 8601 UTC date and time with milliseconds. revision is an integer."
  }
}
