{
  "generated_at": "2026-09-05T21:29:32.273858+00:00",
  "counts": {
    "typed_api": 264,
    "receipt": 48,
    "typed_signer": 70,
    "countersigner": 12
  },
  "total_endpoint_patterns": 394,
  "scope": "All explicit method/path registrations in four exact deployed-lineage service trees, dynamic honesty contracts, InkFrame router, signer upstream route loop, briefing routes and preflight handlers. Framework-implied HEAD/OPTIONS and dynamic path parameter values not individually expanded.",
  "observations": [
    {
      "url": "https://hive-typed-receipts-api.onrender.com/keys",
      "at": "2026-09-05T21:17:08Z",
      "signing_key_id": "did:hive:typed-receipts-v2",
      "count": 2,
      "example_key_count": 22,
      "trust": "Example seeds public; example_registry means demonstration, never evidence"
    },
    {
      "url": "https://hive-typed-signer.onrender.com/pubkey",
      "at": "2026-09-05T21:17:08Z",
      "issuer": "did:hive:typed-demo",
      "algorithm": "ML-DSA-65",
      "signature_bytes": 3309,
      "publicKey_bytes": 1952,
      "note": "Dedicated public demo key. Real ML-DSA-65. Isolated from production keys."
    },
    {
      "url": "https://hive-typed-receipts-api.onrender.com/health",
      "at": "2026-09-05T21:45:48.436Z",
      "revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "basis": "Live build.revision matched the authenticated Render deployment.",
      "trust": "Metadata corroboration only; signature, issuer and execution acceptance remain separate."
    }
  ],
  "aliases": "Parent verified inkframe.thehiveryiq.com DNS origin to hive-receipt.onrender.com. Render custom-domain binding and all proxy prefix rewrites remain outside this source inventory.",
  "routes": [
    {
      "service": "typed_api",
      "endpoint": "OPTIONS https://hive-typed-receipts-api.onrender.com*",
      "method": "OPTIONS",
      "path": "*",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. HEAD is implicit on GET. Source registers unprefixed routes; /v1 aliases require separately verified proxy behavior.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/",
      "method": "GET",
      "path": "/",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. HEAD is implicit on GET. Source registers unprefixed routes; /v1 aliases require separately verified proxy behavior.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/health",
      "method": "GET",
      "path": "/health",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. HEAD is implicit on GET. Source registers unprefixed routes; /v1 aliases require separately verified proxy behavior.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/schema",
      "method": "GET",
      "path": "/schema",
      "schema_version": "JSON Schema catalog: 107 typed contracts plus explicit legacy envelope schema",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /schema/:type is a dynamic route; each supported type is listed in the reviewed typed schema registry. HEAD is implicit on GET.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify",
      "method": "POST",
      "path": "/verify",
      "schema_version": "HiveBoundEnvelope v1.0.0; https://hivebound.io/schemas/envelope/v1.0.0",
      "algorithm": "Ed25519",
      "key_identifier": "envelope-supplied key; stable trusted key id unknown",
      "trust_source": "envelope supplied key only; issuer_identity_verified:false",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Unsigned metadata/execution excluded. Expiry and algorithm now checked; arbitrary caller key does not establish issuer.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/batch",
      "method": "POST",
      "path": "/verify/batch",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/schema/hivebound.envelope.legacy",
      "method": "GET",
      "path": "/schema/hivebound.envelope.legacy",
      "schema_version": "JSON Schema catalog: 107 typed contracts plus explicit legacy envelope schema",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /schema/:type is a dynamic route; each supported type is listed in the reviewed typed schema registry. HEAD is implicit on GET.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/schema/:type",
      "method": "GET",
      "path": "/schema/:type",
      "schema_version": "JSON Schema catalog: 107 typed contracts plus explicit legacy envelope schema",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /schema/:type is a dynamic route; each supported type is listed in the reviewed typed schema registry. HEAD is implicit on GET.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/keys",
      "method": "GET",
      "path": "/keys",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. HEAD is implicit on GET. Source registers unprefixed routes; /v1 aliases require separately verified proxy behavior.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/evar",
      "method": "POST",
      "path": "/verify/evar",
      "schema_version": "eval.attestation; https://thehiveryiq.com/.well-known/schemas/evar-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/perf-budget",
      "method": "POST",
      "path": "/verify/perf-budget",
      "schema_version": "perf.budget; https://thehiveryiq.com/.well-known/schemas/perf-budget-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/perf-attestation",
      "method": "POST",
      "path": "/verify/perf-attestation",
      "schema_version": "perf.attestation; https://thehiveryiq.com/.well-known/schemas/perf-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/bpa",
      "method": "POST",
      "path": "/verify/bpa",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/parametric-trigger",
      "method": "POST",
      "path": "/verify/parametric-trigger",
      "schema_version": "parametric.trigger; https://thehiveryiq.com/.well-known/schemas/parametric-trigger-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/mandate-conformance",
      "method": "POST",
      "path": "/verify/mandate-conformance",
      "schema_version": "mandate.conformance; https://thehiveryiq.com/.well-known/schemas/mandate-conformance-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/mandate-evaluation",
      "method": "POST",
      "path": "/verify/mandate-evaluation",
      "schema_version": "mandate.evaluation; https://thehiveryiq.com/.well-known/schemas/mandate-evaluation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/mandate-evaluation",
      "method": "POST",
      "path": "/mint/mandate-evaluation",
      "schema_version": "mandate.evaluation; https://thehiveryiq.com/.well-known/schemas/mandate-evaluation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/mandate-evaluation",
      "method": "GET",
      "path": "/demo/mandate-evaluation",
      "schema_version": "mandate.evaluation; https://thehiveryiq.com/.well-known/schemas/mandate-evaluation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/tamper-attempt",
      "method": "POST",
      "path": "/verify/tamper-attempt",
      "schema_version": "tamper.attempt; https://thehiveryiq.com/.well-known/schemas/tamper-attempt-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/tamper-attempt",
      "method": "POST",
      "path": "/mint/tamper-attempt",
      "schema_version": "tamper.attempt; https://thehiveryiq.com/.well-known/schemas/tamper-attempt-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/tamper-attempt",
      "method": "GET",
      "path": "/demo/tamper-attempt",
      "schema_version": "tamper.attempt; https://thehiveryiq.com/.well-known/schemas/tamper-attempt-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/eval-administration",
      "method": "POST",
      "path": "/verify/eval-administration",
      "schema_version": "eval.administration; https://thehiveryiq.com/.well-known/schemas/eval-administration-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/causal-path",
      "method": "POST",
      "path": "/verify/causal-path",
      "schema_version": "causal.path; https://thehiveryiq.com/.well-known/schemas/causal-path-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/portfolio-exposure",
      "method": "POST",
      "path": "/verify/portfolio-exposure",
      "schema_version": "portfolio.exposure; https://thehiveryiq.com/.well-known/schemas/portfolio-exposure-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/mandate-aggregate",
      "method": "POST",
      "path": "/verify/mandate-aggregate",
      "schema_version": "mandate.aggregate; https://thehiveryiq.com/.well-known/schemas/mandate-aggregate-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/admission-binding",
      "method": "POST",
      "path": "/verify/admission-binding",
      "schema_version": "admission.binding; https://thehiveryiq.com/.well-known/schemas/admission-binding-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/cross-acceptor",
      "method": "POST",
      "path": "/verify/cross-acceptor",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/authorization-decision",
      "method": "POST",
      "path": "/verify/authorization-decision",
      "schema_version": "authorization.decision; https://thehiveryiq.com/.well-known/schemas/authorization-decision-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/fault-attribution",
      "method": "POST",
      "path": "/verify/fault-attribution",
      "schema_version": "fault.attribution; https://thehiveryiq.com/.well-known/schemas/fault-attribution-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/intent-verifiability",
      "method": "POST",
      "path": "/verify/intent-verifiability",
      "schema_version": "intent.verifiability; https://thehiveryiq.com/.well-known/schemas/intent-verifiability-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/recovery-determination",
      "method": "POST",
      "path": "/verify/recovery-determination",
      "schema_version": "recovery.determination; https://thehiveryiq.com/.well-known/schemas/recovery-determination-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/intent-affirmation",
      "method": "POST",
      "path": "/verify/intent-affirmation",
      "schema_version": "intent.affirmation; https://thehiveryiq.com/.well-known/schemas/intent-affirmation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/conduct-record",
      "method": "POST",
      "path": "/verify/conduct-record",
      "schema_version": "conduct.record; https://thehiveryiq.com/.well-known/schemas/conduct-record-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/mandate-crossreference",
      "method": "POST",
      "path": "/verify/mandate-crossreference",
      "schema_version": "mandate.crossreference; https://thehiveryiq.com/.well-known/schemas/mandate-crossreference-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/directory-state",
      "method": "POST",
      "path": "/verify/directory-state",
      "schema_version": "directory.state; https://thehiveryiq.com/.well-known/schemas/directory-state-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/capability-exercise",
      "method": "POST",
      "path": "/verify/capability-exercise",
      "schema_version": "capability.exercise; https://thehiveryiq.com/.well-known/schemas/capability-exercise-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/capture-commitment",
      "method": "POST",
      "path": "/verify/capture-commitment",
      "schema_version": "capture.commitment; https://thehiveryiq.com/.well-known/schemas/capture-commitment-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/capture-commitment/segment",
      "method": "POST",
      "path": "/verify/capture-commitment/segment",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/corpus-commitment",
      "method": "POST",
      "path": "/verify/corpus-commitment",
      "schema_version": "corpus.commitment; https://thehiveryiq.com/.well-known/schemas/corpus-commitment-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/erasure-receipt",
      "method": "POST",
      "path": "/verify/erasure-receipt",
      "schema_version": "erasure.receipt; https://thehiveryiq.com/.well-known/schemas/erasure-receipt-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/meter-witness",
      "method": "POST",
      "path": "/verify/meter-witness",
      "schema_version": "meter.witness; https://thehiveryiq.com/.well-known/schemas/meter-witness-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/analysis-replay",
      "method": "POST",
      "path": "/verify/analysis-replay",
      "schema_version": "analysis.replay; https://thehiveryiq.com/.well-known/schemas/analysis-replay-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/control-replay",
      "method": "POST",
      "path": "/verify/control-replay",
      "schema_version": "control.replay; https://thehiveryiq.com/.well-known/schemas/control-replay-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/transparency-checkpoint",
      "method": "POST",
      "path": "/verify/transparency-checkpoint",
      "schema_version": "transparency.checkpoint; https://thehiveryiq.com/.well-known/schemas/transparency-checkpoint-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/transparency-checkpoint/inclusion",
      "method": "POST",
      "path": "/verify/transparency-checkpoint/inclusion",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/transparency-checkpoint/consistency",
      "method": "POST",
      "path": "/verify/transparency-checkpoint/consistency",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/delegation-attenuation",
      "method": "POST",
      "path": "/verify/delegation-attenuation",
      "schema_version": "delegation.attenuation; https://thehiveryiq.com/.well-known/schemas/delegation-attenuation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/authority-revocation",
      "method": "POST",
      "path": "/verify/authority-revocation",
      "schema_version": "authority.revocation; https://thehiveryiq.com/.well-known/schemas/authority-revocation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/authority-qualification",
      "method": "POST",
      "path": "/verify/authority-qualification",
      "schema_version": "authority.qualification; https://thehiveryiq.com/.well-known/schemas/authority-qualification-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/effect-quiescence",
      "method": "POST",
      "path": "/verify/effect-quiescence",
      "schema_version": "effect.quiescence; https://thehiveryiq.com/.well-known/schemas/effect-quiescence-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/authority-carriage",
      "method": "POST",
      "path": "/verify/authority-carriage",
      "schema_version": "authority.carriage; https://thehiveryiq.com/.well-known/schemas/authority-carriage-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/submission-attestation",
      "method": "POST",
      "path": "/verify/submission-attestation",
      "schema_version": "submission.attestation; https://thehiveryiq.com/.well-known/schemas/submission-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/ledger-parity",
      "method": "POST",
      "path": "/verify/ledger-parity",
      "schema_version": "ledger.parity; https://thehiveryiq.com/.well-known/schemas/ledger-parity-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/knowledge-timestamp",
      "method": "POST",
      "path": "/verify/knowledge-timestamp",
      "schema_version": "knowledge.timestamp; https://thehiveryiq.com/.well-known/schemas/knowledge-timestamp-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/screening-attestation",
      "method": "POST",
      "path": "/verify/screening-attestation",
      "schema_version": "screening.attestation; https://thehiveryiq.com/.well-known/schemas/screening-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/proof-transition",
      "method": "POST",
      "path": "/verify/proof-transition",
      "schema_version": "proof.transition; https://thehiveryiq.com/.well-known/schemas/proof-state-transition-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/proof-transition-portable",
      "method": "POST",
      "path": "/verify/proof-transition-portable",
      "schema_version": "proof.transition.portable; https://thehiveryiq.com/.well-known/schemas/proof-transition-portable-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/assembly",
      "method": "POST",
      "path": "/verify/assembly",
      "schema_version": "assembly.receipt; https://thehiveryiq.com/.well-known/schemas/assembly-receipt-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/routing",
      "method": "POST",
      "path": "/verify/routing",
      "schema_version": "routing.receipt; https://thehiveryiq.com/.well-known/schemas/routing-receipt-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/delegation-link",
      "method": "POST",
      "path": "/verify/delegation-link",
      "schema_version": "authority.delegation; https://thehiveryiq.com/.well-known/schemas/delegated-authority-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/delegation-chain",
      "method": "POST",
      "path": "/verify/delegation-chain",
      "schema_version": "authority.delegation; https://thehiveryiq.com/.well-known/schemas/delegated-authority-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/supersession",
      "method": "POST",
      "path": "/verify/supersession",
      "schema_version": "supersession.receipt; https://thehiveryiq.com/.well-known/schemas/supersession-receipt-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/effect-closure",
      "method": "POST",
      "path": "/verify/effect-closure",
      "schema_version": "effect.closure; https://thehiveryiq.com/.well-known/schemas/effect-closure-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/proof-demand",
      "method": "POST",
      "path": "/verify/proof-demand",
      "schema_version": "proof.demand; https://thehiveryiq.com/.well-known/schemas/proof-demand-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/stream-attestation",
      "method": "POST",
      "path": "/verify/stream-attestation",
      "schema_version": "stream.attestation; https://thehiveryiq.com/.well-known/schemas/stream-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/stream-attestation/chain",
      "method": "POST",
      "path": "/verify/stream-attestation/chain",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/sequence-attestation/root",
      "method": "POST",
      "path": "/sequence-attestation/root",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/sequence-attestation",
      "method": "POST",
      "path": "/verify/sequence-attestation",
      "schema_version": "sequence.attestation; https://thehiveryiq.com/.well-known/schemas/sequence-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/divergence-record",
      "method": "POST",
      "path": "/verify/divergence-record",
      "schema_version": "divergence.record; https://thehiveryiq.com/.well-known/schemas/divergence-record-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/sigr-chain",
      "method": "POST",
      "path": "/verify/sigr-chain",
      "schema_version": "sigr.chain; https://thehiveryiq.com/.well-known/schemas/sigr-chain-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/imprimatur-clearance",
      "method": "POST",
      "path": "/verify/imprimatur-clearance",
      "schema_version": "imprimatur.clearance; https://thehiveryiq.com/.well-known/schemas/imprimatur-clearance-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/sigr-bill",
      "method": "POST",
      "path": "/verify/sigr-bill",
      "schema_version": "sigr.bill; https://thehiveryiq.com/.well-known/schemas/sigr-bill-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/sigr-bond",
      "method": "POST",
      "path": "/verify/sigr-bond",
      "schema_version": "sigr.bond; https://thehiveryiq.com/.well-known/schemas/sigr-bond-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/sigr-consensus",
      "method": "POST",
      "path": "/verify/sigr-consensus",
      "schema_version": "sigr.consensus; https://thehiveryiq.com/.well-known/schemas/sigr-consensus-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/sigr-gca",
      "method": "POST",
      "path": "/verify/sigr-gca",
      "schema_version": "sigr.gca; https://thehiveryiq.com/.well-known/schemas/sigr-gca-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/sigr-gitm",
      "method": "POST",
      "path": "/verify/sigr-gitm",
      "schema_version": "sigr.gitm; https://thehiveryiq.com/.well-known/schemas/sigr-gitm-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/sigr-cachesign",
      "method": "POST",
      "path": "/verify/sigr-cachesign",
      "schema_version": "sigr.cachesign; https://thehiveryiq.com/.well-known/schemas/sigr-cachesign-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/sigr-manifest",
      "method": "POST",
      "path": "/verify/sigr-manifest",
      "schema_version": "sigr.manifest; https://thehiveryiq.com/.well-known/schemas/sigr-manifest-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/sigr-mir",
      "method": "POST",
      "path": "/verify/sigr-mir",
      "schema_version": "sigr.mir; https://thehiveryiq.com/.well-known/schemas/sigr-mir-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/evar",
      "method": "POST",
      "path": "/mint/evar",
      "schema_version": "eval.attestation; https://thehiveryiq.com/.well-known/schemas/evar-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/bpa/budget",
      "method": "POST",
      "path": "/mint/bpa/budget",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/bpa/attestation",
      "method": "POST",
      "path": "/mint/bpa/attestation",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/parametric/trigger",
      "method": "POST",
      "path": "/mint/parametric/trigger",
      "schema_version": "parametric.trigger; https://thehiveryiq.com/.well-known/schemas/parametric-trigger-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/proof-transition",
      "method": "POST",
      "path": "/mint/proof-transition",
      "schema_version": "proof.transition; https://thehiveryiq.com/.well-known/schemas/proof-state-transition-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/assembly",
      "method": "POST",
      "path": "/mint/assembly",
      "schema_version": "assembly.receipt; https://thehiveryiq.com/.well-known/schemas/assembly-receipt-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/routing",
      "method": "POST",
      "path": "/mint/routing",
      "schema_version": "routing.receipt; https://thehiveryiq.com/.well-known/schemas/routing-receipt-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/delegation-link",
      "method": "POST",
      "path": "/mint/delegation-link",
      "schema_version": "authority.delegation; https://thehiveryiq.com/.well-known/schemas/delegated-authority-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/mandate/conformance",
      "method": "POST",
      "path": "/mint/mandate/conformance",
      "schema_version": "mandate.conformance; https://thehiveryiq.com/.well-known/schemas/mandate-conformance-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/eval/administration",
      "method": "POST",
      "path": "/mint/eval/administration",
      "schema_version": "eval.administration; https://thehiveryiq.com/.well-known/schemas/eval-administration-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/causal/path",
      "method": "POST",
      "path": "/mint/causal/path",
      "schema_version": "causal.path; https://thehiveryiq.com/.well-known/schemas/causal-path-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/portfolio/exposure",
      "method": "POST",
      "path": "/mint/portfolio/exposure",
      "schema_version": "portfolio.exposure; https://thehiveryiq.com/.well-known/schemas/portfolio-exposure-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/mandate/aggregate",
      "method": "POST",
      "path": "/mint/mandate/aggregate",
      "schema_version": "mandate.aggregate; https://thehiveryiq.com/.well-known/schemas/mandate-aggregate-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/ledger/parity",
      "method": "POST",
      "path": "/mint/ledger/parity",
      "schema_version": "ledger.parity; https://thehiveryiq.com/.well-known/schemas/ledger-parity-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/knowledge/timestamp",
      "method": "POST",
      "path": "/mint/knowledge/timestamp",
      "schema_version": "knowledge.timestamp; https://thehiveryiq.com/.well-known/schemas/knowledge-timestamp-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/screening/attestation",
      "method": "POST",
      "path": "/mint/screening/attestation",
      "schema_version": "screening.attestation; https://thehiveryiq.com/.well-known/schemas/screening-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/evar",
      "method": "GET",
      "path": "/demo/evar",
      "schema_version": "eval.attestation; https://thehiveryiq.com/.well-known/schemas/evar-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/eval-administration",
      "method": "GET",
      "path": "/demo/eval-administration",
      "schema_version": "eval.administration; https://thehiveryiq.com/.well-known/schemas/eval-administration-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/perf-budget",
      "method": "GET",
      "path": "/demo/perf-budget",
      "schema_version": "perf.budget; https://thehiveryiq.com/.well-known/schemas/perf-budget-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/perf-attestation",
      "method": "GET",
      "path": "/demo/perf-attestation",
      "schema_version": "perf.attestation; https://thehiveryiq.com/.well-known/schemas/perf-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/parametric-trigger",
      "method": "GET",
      "path": "/demo/parametric-trigger",
      "schema_version": "parametric.trigger; https://thehiveryiq.com/.well-known/schemas/parametric-trigger-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/usap-pbs",
      "method": "GET",
      "path": "/demo/usap-pbs",
      "schema_version": "usap.pbs; https://thehiveryiq.com/.well-known/schemas/usap-pbs-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/usap-refusal",
      "method": "GET",
      "path": "/demo/usap-refusal",
      "schema_version": "usap.refusal; https://thehiveryiq.com/.well-known/schemas/usap-refusal-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/usap-howler",
      "method": "GET",
      "path": "/demo/usap-howler",
      "schema_version": "usap.howler; https://thehiveryiq.com/.well-known/schemas/usap-howler-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/usap-forensic",
      "method": "GET",
      "path": "/demo/usap-forensic",
      "schema_version": "usap.forensic; https://thehiveryiq.com/.well-known/schemas/usap-forensic-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/replay-disclosurefree",
      "method": "GET",
      "path": "/demo/replay-disclosurefree",
      "schema_version": "replay.disclosurefree; https://thehiveryiq.com/.well-known/schemas/replay-disclosurefree-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/sigr-mir",
      "method": "GET",
      "path": "/demo/sigr-mir",
      "schema_version": "sigr.mir; https://thehiveryiq.com/.well-known/schemas/sigr-mir-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/imprimatur-clearance",
      "method": "GET",
      "path": "/demo/imprimatur-clearance",
      "schema_version": "imprimatur.clearance; https://thehiveryiq.com/.well-known/schemas/imprimatur-clearance-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/sigr-bond",
      "method": "GET",
      "path": "/demo/sigr-bond",
      "schema_version": "sigr.bond; https://thehiveryiq.com/.well-known/schemas/sigr-bond-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/causal-path",
      "method": "GET",
      "path": "/demo/causal-path",
      "schema_version": "causal.path; https://thehiveryiq.com/.well-known/schemas/causal-path-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/portfolio-exposure",
      "method": "GET",
      "path": "/demo/portfolio-exposure",
      "schema_version": "portfolio.exposure; https://thehiveryiq.com/.well-known/schemas/portfolio-exposure-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/authority-receipt",
      "method": "GET",
      "path": "/demo/authority-receipt",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/mandate-conformance",
      "method": "GET",
      "path": "/demo/mandate-conformance",
      "schema_version": "mandate.conformance; https://thehiveryiq.com/.well-known/schemas/mandate-conformance-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/admission-binding",
      "method": "GET",
      "path": "/demo/admission-binding",
      "schema_version": "admission.binding; https://thehiveryiq.com/.well-known/schemas/admission-binding-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/cross-acceptor",
      "method": "GET",
      "path": "/demo/cross-acceptor",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/authorization-decision",
      "method": "GET",
      "path": "/demo/authorization-decision",
      "schema_version": "authorization.decision; https://thehiveryiq.com/.well-known/schemas/authorization-decision-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/fault-attribution",
      "method": "GET",
      "path": "/demo/fault-attribution",
      "schema_version": "fault.attribution; https://thehiveryiq.com/.well-known/schemas/fault-attribution-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/intent-verifiability",
      "method": "GET",
      "path": "/demo/intent-verifiability",
      "schema_version": "intent.verifiability; https://thehiveryiq.com/.well-known/schemas/intent-verifiability-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/recovery-determination",
      "method": "GET",
      "path": "/demo/recovery-determination",
      "schema_version": "recovery.determination; https://thehiveryiq.com/.well-known/schemas/recovery-determination-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/intent-affirmation",
      "method": "GET",
      "path": "/demo/intent-affirmation",
      "schema_version": "intent.affirmation; https://thehiveryiq.com/.well-known/schemas/intent-affirmation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/conduct-record",
      "method": "GET",
      "path": "/demo/conduct-record",
      "schema_version": "conduct.record; https://thehiveryiq.com/.well-known/schemas/conduct-record-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/mandate-crossreference",
      "method": "GET",
      "path": "/demo/mandate-crossreference",
      "schema_version": "mandate.crossreference; https://thehiveryiq.com/.well-known/schemas/mandate-crossreference-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/capability-exercise",
      "method": "GET",
      "path": "/demo/capability-exercise",
      "schema_version": "capability.exercise; https://thehiveryiq.com/.well-known/schemas/capability-exercise-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/transparency-checkpoint",
      "method": "GET",
      "path": "/demo/transparency-checkpoint",
      "schema_version": "transparency.checkpoint; https://thehiveryiq.com/.well-known/schemas/transparency-checkpoint-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/capture-commitment",
      "method": "GET",
      "path": "/demo/capture-commitment",
      "schema_version": "capture.commitment; https://thehiveryiq.com/.well-known/schemas/capture-commitment-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/directory-state",
      "method": "GET",
      "path": "/demo/directory-state",
      "schema_version": "directory.state; https://thehiveryiq.com/.well-known/schemas/directory-state-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/delegation-attenuation",
      "method": "GET",
      "path": "/demo/delegation-attenuation",
      "schema_version": "delegation.attenuation; https://thehiveryiq.com/.well-known/schemas/delegation-attenuation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/authority-revocation",
      "method": "GET",
      "path": "/demo/authority-revocation",
      "schema_version": "authority.revocation; https://thehiveryiq.com/.well-known/schemas/authority-revocation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/authority-qualification",
      "method": "GET",
      "path": "/demo/authority-qualification",
      "schema_version": "authority.qualification; https://thehiveryiq.com/.well-known/schemas/authority-qualification-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/effect-quiescence",
      "method": "GET",
      "path": "/demo/effect-quiescence",
      "schema_version": "effect.quiescence; https://thehiveryiq.com/.well-known/schemas/effect-quiescence-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/authority-carriage",
      "method": "GET",
      "path": "/demo/authority-carriage",
      "schema_version": "authority.carriage; https://thehiveryiq.com/.well-known/schemas/authority-carriage-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/submission-attestation",
      "method": "GET",
      "path": "/demo/submission-attestation",
      "schema_version": "submission.attestation; https://thehiveryiq.com/.well-known/schemas/submission-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/authority-carriage",
      "method": "POST",
      "path": "/mint/authority-carriage",
      "schema_version": "authority.carriage; https://thehiveryiq.com/.well-known/schemas/authority-carriage-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/submission-attestation",
      "method": "POST",
      "path": "/mint/submission-attestation",
      "schema_version": "submission.attestation; https://thehiveryiq.com/.well-known/schemas/submission-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/supersession",
      "method": "POST",
      "path": "/mint/supersession",
      "schema_version": "supersession.receipt; https://thehiveryiq.com/.well-known/schemas/supersession-receipt-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/effect-closure",
      "method": "POST",
      "path": "/mint/effect-closure",
      "schema_version": "effect.closure; https://thehiveryiq.com/.well-known/schemas/effect-closure-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/proof-demand",
      "method": "POST",
      "path": "/mint/proof-demand",
      "schema_version": "proof.demand; https://thehiveryiq.com/.well-known/schemas/proof-demand-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/stream-attestation",
      "method": "POST",
      "path": "/mint/stream-attestation",
      "schema_version": "stream.attestation; https://thehiveryiq.com/.well-known/schemas/stream-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/divergence-record",
      "method": "POST",
      "path": "/mint/divergence-record",
      "schema_version": "divergence.record; https://thehiveryiq.com/.well-known/schemas/divergence-record-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/sequence-attestation",
      "method": "POST",
      "path": "/mint/sequence-attestation",
      "schema_version": "sequence.attestation; https://thehiveryiq.com/.well-known/schemas/sequence-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/sigr-chain",
      "method": "POST",
      "path": "/mint/sigr-chain",
      "schema_version": "sigr.chain; https://thehiveryiq.com/.well-known/schemas/sigr-chain-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/imprimatur-clearance",
      "method": "POST",
      "path": "/mint/imprimatur-clearance",
      "schema_version": "imprimatur.clearance; https://thehiveryiq.com/.well-known/schemas/imprimatur-clearance-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/corpus-commitment",
      "method": "POST",
      "path": "/mint/corpus-commitment",
      "schema_version": "corpus.commitment; https://thehiveryiq.com/.well-known/schemas/corpus-commitment-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/erasure-receipt",
      "method": "POST",
      "path": "/mint/erasure-receipt",
      "schema_version": "erasure.receipt; https://thehiveryiq.com/.well-known/schemas/erasure-receipt-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/meter-witness",
      "method": "POST",
      "path": "/mint/meter-witness",
      "schema_version": "meter.witness; https://thehiveryiq.com/.well-known/schemas/meter-witness-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/analysis-replay",
      "method": "POST",
      "path": "/mint/analysis-replay",
      "schema_version": "analysis.replay; https://thehiveryiq.com/.well-known/schemas/analysis-replay-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/control-replay",
      "method": "POST",
      "path": "/mint/control-replay",
      "schema_version": "control.replay; https://thehiveryiq.com/.well-known/schemas/control-replay-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/transparency-checkpoint",
      "method": "POST",
      "path": "/mint/transparency-checkpoint",
      "schema_version": "transparency.checkpoint; https://thehiveryiq.com/.well-known/schemas/transparency-checkpoint-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/transparency-checkpoint/open",
      "method": "POST",
      "path": "/mint/transparency-checkpoint/open",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/numeric-lineage",
      "method": "POST",
      "path": "/verify/numeric-lineage",
      "schema_version": "numeric.lineage; https://thehiveryiq.com/.well-known/schemas/numeric-lineage-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/numeric-lineage",
      "method": "POST",
      "path": "/mint/numeric-lineage",
      "schema_version": "numeric.lineage; https://thehiveryiq.com/.well-known/schemas/numeric-lineage-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/cache-epoch",
      "method": "POST",
      "path": "/verify/cache-epoch",
      "schema_version": "cache.epoch; https://thehiveryiq.com/.well-known/schemas/cache-epoch-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/cache-epoch",
      "method": "POST",
      "path": "/mint/cache-epoch",
      "schema_version": "cache.epoch; https://thehiveryiq.com/.well-known/schemas/cache-epoch-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/entropy-custody",
      "method": "POST",
      "path": "/verify/entropy-custody",
      "schema_version": "entropy.custody; https://thehiveryiq.com/.well-known/schemas/entropy-custody-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/entropy-custody",
      "method": "POST",
      "path": "/mint/entropy-custody",
      "schema_version": "entropy.custody; https://thehiveryiq.com/.well-known/schemas/entropy-custody-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/disclosure-presentation",
      "method": "POST",
      "path": "/verify/disclosure-presentation",
      "schema_version": "disclosure.presentation; https://thehiveryiq.com/.well-known/schemas/disclosure-presentation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/disclosure-presentation",
      "method": "POST",
      "path": "/mint/disclosure-presentation",
      "schema_version": "disclosure.presentation; https://thehiveryiq.com/.well-known/schemas/disclosure-presentation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/custody-handoff",
      "method": "POST",
      "path": "/verify/custody-handoff",
      "schema_version": "custody.handoff; https://thehiveryiq.com/.well-known/schemas/custody-handoff-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/custody-handoff",
      "method": "POST",
      "path": "/mint/custody-handoff",
      "schema_version": "custody.handoff; https://thehiveryiq.com/.well-known/schemas/custody-handoff-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/retention-purge",
      "method": "POST",
      "path": "/verify/retention-purge",
      "schema_version": "retention.purge; https://thehiveryiq.com/.well-known/schemas/retention-purge-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/retention-purge",
      "method": "POST",
      "path": "/mint/retention-purge",
      "schema_version": "retention.purge; https://thehiveryiq.com/.well-known/schemas/retention-purge-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/model-change",
      "method": "POST",
      "path": "/verify/model-change",
      "schema_version": "model.change; https://thehiveryiq.com/.well-known/schemas/model-change-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/model-change",
      "method": "POST",
      "path": "/mint/model-change",
      "schema_version": "model.change; https://thehiveryiq.com/.well-known/schemas/model-change-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/safety-envelope",
      "method": "POST",
      "path": "/verify/safety-envelope",
      "schema_version": "safety.envelope; https://thehiveryiq.com/.well-known/schemas/safety-envelope-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/safety-envelope",
      "method": "POST",
      "path": "/mint/safety-envelope",
      "schema_version": "safety.envelope; https://thehiveryiq.com/.well-known/schemas/safety-envelope-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/agent-coalition",
      "method": "POST",
      "path": "/verify/agent-coalition",
      "schema_version": "agent.coalition; https://thehiveryiq.com/.well-known/schemas/agent-coalition-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/agent-coalition",
      "method": "POST",
      "path": "/mint/agent-coalition",
      "schema_version": "agent.coalition; https://thehiveryiq.com/.well-known/schemas/agent-coalition-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/agent-metamorphosis",
      "method": "POST",
      "path": "/verify/agent-metamorphosis",
      "schema_version": "agent.metamorphosis; https://thehiveryiq.com/.well-known/schemas/agent-metamorphosis-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/agent-metamorphosis",
      "method": "POST",
      "path": "/mint/agent-metamorphosis",
      "schema_version": "agent.metamorphosis; https://thehiveryiq.com/.well-known/schemas/agent-metamorphosis-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/jurisdictional-clearance",
      "method": "POST",
      "path": "/verify/jurisdictional-clearance",
      "schema_version": "jurisdictional.clearance; https://thehiveryiq.com/.well-known/schemas/jurisdictional-clearance-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/jurisdictional-clearance",
      "method": "POST",
      "path": "/mint/jurisdictional-clearance",
      "schema_version": "jurisdictional.clearance; https://thehiveryiq.com/.well-known/schemas/jurisdictional-clearance-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/cloazk-warden",
      "method": "POST",
      "path": "/verify/cloazk-warden",
      "schema_version": "cloazk.warden; https://thehiveryiq.com/.well-known/schemas/cloazk-warden-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/cloazk-warden",
      "method": "POST",
      "path": "/mint/cloazk-warden",
      "schema_version": "cloazk.warden; https://thehiveryiq.com/.well-known/schemas/cloazk-warden-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/sls-metering",
      "method": "POST",
      "path": "/verify/sls-metering",
      "schema_version": "sls.metering; https://thehiveryiq.com/.well-known/schemas/sls-metering-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/sls-metering",
      "method": "POST",
      "path": "/mint/sls-metering",
      "schema_version": "sls.metering; https://thehiveryiq.com/.well-known/schemas/sls-metering-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/retention-policy",
      "method": "POST",
      "path": "/verify/retention-policy",
      "schema_version": "retention.policy; https://thehiveryiq.com/.well-known/schemas/retention-policy-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/retention-policy",
      "method": "POST",
      "path": "/mint/retention-policy",
      "schema_version": "retention.policy; https://thehiveryiq.com/.well-known/schemas/retention-policy-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/capture-commitment",
      "method": "POST",
      "path": "/mint/capture-commitment",
      "schema_version": "capture.commitment; https://thehiveryiq.com/.well-known/schemas/capture-commitment-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/capture-commitment/open",
      "method": "POST",
      "path": "/mint/capture-commitment/open",
      "schema_version": "unknown exact route-to-schema mapping; full schema catalog in the reviewed typed schema registry",
      "algorithm": "Ed25519 for typed receipts; unsigned helper/digest routes are not signatures",
      "key_identifier": "per-envelope key id; /keys service signer did:hive:typed-receipts-v2; exact route key unknown",
      "trust_source": "service/example/caller trust classification is route-specific; not independent approval",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. A regex GET /verify|mint handler returns method hints/405, not successful verification.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/sigr-bill",
      "method": "POST",
      "path": "/mint/sigr-bill",
      "schema_version": "sigr.bill; https://thehiveryiq.com/.well-known/schemas/sigr-bill-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/sigr-bond",
      "method": "POST",
      "path": "/mint/sigr-bond",
      "schema_version": "sigr.bond; https://thehiveryiq.com/.well-known/schemas/sigr-bond-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/sigr-consensus",
      "method": "POST",
      "path": "/mint/sigr-consensus",
      "schema_version": "sigr.consensus; https://thehiveryiq.com/.well-known/schemas/sigr-consensus-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/sigr-gca",
      "method": "POST",
      "path": "/mint/sigr-gca",
      "schema_version": "sigr.gca; https://thehiveryiq.com/.well-known/schemas/sigr-gca-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/sigr-gitm",
      "method": "POST",
      "path": "/mint/sigr-gitm",
      "schema_version": "sigr.gitm; https://thehiveryiq.com/.well-known/schemas/sigr-gitm-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/sigr-cachesign",
      "method": "POST",
      "path": "/mint/sigr-cachesign",
      "schema_version": "sigr.cachesign; https://thehiveryiq.com/.well-known/schemas/sigr-cachesign-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/sigr-manifest",
      "method": "POST",
      "path": "/mint/sigr-manifest",
      "schema_version": "sigr.manifest; https://thehiveryiq.com/.well-known/schemas/sigr-manifest-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/sigr-mir",
      "method": "POST",
      "path": "/mint/sigr-mir",
      "schema_version": "sigr.mir; https://thehiveryiq.com/.well-known/schemas/sigr-mir-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/usap-pbs",
      "method": "POST",
      "path": "/verify/usap-pbs",
      "schema_version": "usap.pbs; https://thehiveryiq.com/.well-known/schemas/usap-pbs-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/usap-pbs",
      "method": "POST",
      "path": "/mint/usap-pbs",
      "schema_version": "usap.pbs; https://thehiveryiq.com/.well-known/schemas/usap-pbs-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/usap-refusal",
      "method": "POST",
      "path": "/verify/usap-refusal",
      "schema_version": "usap.refusal; https://thehiveryiq.com/.well-known/schemas/usap-refusal-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/usap-refusal",
      "method": "POST",
      "path": "/mint/usap-refusal",
      "schema_version": "usap.refusal; https://thehiveryiq.com/.well-known/schemas/usap-refusal-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/usap-howler",
      "method": "POST",
      "path": "/verify/usap-howler",
      "schema_version": "usap.howler; https://thehiveryiq.com/.well-known/schemas/usap-howler-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/usap-howler",
      "method": "POST",
      "path": "/mint/usap-howler",
      "schema_version": "usap.howler; https://thehiveryiq.com/.well-known/schemas/usap-howler-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/usap-perimeter",
      "method": "POST",
      "path": "/verify/usap-perimeter",
      "schema_version": "usap.perimeter; https://thehiveryiq.com/.well-known/schemas/usap-perimeter-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/usap-perimeter",
      "method": "POST",
      "path": "/mint/usap-perimeter",
      "schema_version": "usap.perimeter; https://thehiveryiq.com/.well-known/schemas/usap-perimeter-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/usap-diurnal",
      "method": "POST",
      "path": "/verify/usap-diurnal",
      "schema_version": "usap.diurnal; https://thehiveryiq.com/.well-known/schemas/usap-diurnal-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/usap-diurnal",
      "method": "POST",
      "path": "/mint/usap-diurnal",
      "schema_version": "usap.diurnal; https://thehiveryiq.com/.well-known/schemas/usap-diurnal-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/usap-egress",
      "method": "POST",
      "path": "/verify/usap-egress",
      "schema_version": "usap.egress; https://thehiveryiq.com/.well-known/schemas/usap-egress-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/usap-egress",
      "method": "POST",
      "path": "/mint/usap-egress",
      "schema_version": "usap.egress; https://thehiveryiq.com/.well-known/schemas/usap-egress-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/usap-forensic",
      "method": "POST",
      "path": "/verify/usap-forensic",
      "schema_version": "usap.forensic; https://thehiveryiq.com/.well-known/schemas/usap-forensic-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/usap-forensic",
      "method": "POST",
      "path": "/mint/usap-forensic",
      "schema_version": "usap.forensic; https://thehiveryiq.com/.well-known/schemas/usap-forensic-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/afir-stream",
      "method": "POST",
      "path": "/verify/afir-stream",
      "schema_version": "afir.stream; https://thehiveryiq.com/.well-known/schemas/afir-stream-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/afir-stream",
      "method": "POST",
      "path": "/mint/afir-stream",
      "schema_version": "afir.stream; https://thehiveryiq.com/.well-known/schemas/afir-stream-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/hiveseal-qpuf",
      "method": "POST",
      "path": "/verify/hiveseal-qpuf",
      "schema_version": "hiveseal.qpuf; https://thehiveryiq.com/.well-known/schemas/hiveseal-qpuf-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/hiveseal-qpuf",
      "method": "POST",
      "path": "/mint/hiveseal-qpuf",
      "schema_version": "hiveseal.qpuf; https://thehiveryiq.com/.well-known/schemas/hiveseal-qpuf-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/proof-prefill",
      "method": "POST",
      "path": "/verify/proof-prefill",
      "schema_version": "proof.prefill; https://thehiveryiq.com/.well-known/schemas/proof-prefill-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/proof-prefill",
      "method": "POST",
      "path": "/mint/proof-prefill",
      "schema_version": "proof.prefill; https://thehiveryiq.com/.well-known/schemas/proof-prefill-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/hivebound-envelope",
      "method": "POST",
      "path": "/verify/hivebound-envelope",
      "schema_version": "hivebound.envelope; https://thehiveryiq.com/.well-known/schemas/hivebound-envelope-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/hivebound-envelope",
      "method": "POST",
      "path": "/mint/hivebound-envelope",
      "schema_version": "hivebound.envelope; https://thehiveryiq.com/.well-known/schemas/hivebound-envelope-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/s2s-signature",
      "method": "POST",
      "path": "/verify/s2s-signature",
      "schema_version": "s2s.signature; https://thehiveryiq.com/.well-known/schemas/s2s-signature-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/s2s-signature",
      "method": "POST",
      "path": "/mint/s2s-signature",
      "schema_version": "s2s.signature; https://thehiveryiq.com/.well-known/schemas/s2s-signature-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/ppr-wearable",
      "method": "POST",
      "path": "/verify/ppr-wearable",
      "schema_version": "ppr.wearable; https://thehiveryiq.com/.well-known/schemas/ppr-wearable-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/ppr-wearable",
      "method": "POST",
      "path": "/mint/ppr-wearable",
      "schema_version": "ppr.wearable; https://thehiveryiq.com/.well-known/schemas/ppr-wearable-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/royalty-provenance",
      "method": "POST",
      "path": "/verify/royalty-provenance",
      "schema_version": "royalty.provenance; https://thehiveryiq.com/.well-known/schemas/royalty-provenance-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/royalty-provenance",
      "method": "POST",
      "path": "/mint/royalty-provenance",
      "schema_version": "royalty.provenance; https://thehiveryiq.com/.well-known/schemas/royalty-provenance-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/origin-proof",
      "method": "POST",
      "path": "/verify/origin-proof",
      "schema_version": "origin.proof; https://thehiveryiq.com/.well-known/schemas/origin-proof-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/origin-proof",
      "method": "POST",
      "path": "/mint/origin-proof",
      "schema_version": "origin.proof; https://thehiveryiq.com/.well-known/schemas/origin-proof-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/afir-s3",
      "method": "POST",
      "path": "/verify/afir-s3",
      "schema_version": "afir.s3; https://thehiveryiq.com/.well-known/schemas/afir-s3-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/afir-s3",
      "method": "POST",
      "path": "/mint/afir-s3",
      "schema_version": "afir.s3; https://thehiveryiq.com/.well-known/schemas/afir-s3-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/structural-lateration",
      "method": "POST",
      "path": "/verify/structural-lateration",
      "schema_version": "structural.lateration; https://thehiveryiq.com/.well-known/schemas/structural-lateration-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/structural-lateration",
      "method": "POST",
      "path": "/mint/structural-lateration",
      "schema_version": "structural.lateration; https://thehiveryiq.com/.well-known/schemas/structural-lateration-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/settlement-feed",
      "method": "POST",
      "path": "/verify/settlement-feed",
      "schema_version": "settlement.feed; https://thehiveryiq.com/.well-known/schemas/settlement-feed-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/settlement-feed",
      "method": "POST",
      "path": "/mint/settlement-feed",
      "schema_version": "settlement.feed; https://thehiveryiq.com/.well-known/schemas/settlement-feed-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/receipt-registry-sovereign",
      "method": "POST",
      "path": "/verify/receipt-registry-sovereign",
      "schema_version": "receipt.registry.sovereign; https://thehiveryiq.com/.well-known/schemas/receipt-registry-sovereign-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/receipt-registry-sovereign",
      "method": "POST",
      "path": "/mint/receipt-registry-sovereign",
      "schema_version": "receipt.registry.sovereign; https://thehiveryiq.com/.well-known/schemas/receipt-registry-sovereign-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/voting-verifiable",
      "method": "POST",
      "path": "/verify/voting-verifiable",
      "schema_version": "voting.verifiable; https://thehiveryiq.com/.well-known/schemas/voting-verifiable-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/voting-verifiable",
      "method": "POST",
      "path": "/mint/voting-verifiable",
      "schema_version": "voting.verifiable; https://thehiveryiq.com/.well-known/schemas/voting-verifiable-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/inkframe-nonmutation",
      "method": "POST",
      "path": "/verify/inkframe-nonmutation",
      "schema_version": "inkframe.nonmutation; https://thehiveryiq.com/.well-known/schemas/inkframe-nonmutation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/inkframe-nonmutation",
      "method": "POST",
      "path": "/mint/inkframe-nonmutation",
      "schema_version": "inkframe.nonmutation; https://thehiveryiq.com/.well-known/schemas/inkframe-nonmutation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/replay-disclosurefree",
      "method": "POST",
      "path": "/verify/replay-disclosurefree",
      "schema_version": "replay.disclosurefree; https://thehiveryiq.com/.well-known/schemas/replay-disclosurefree-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/replay-disclosurefree",
      "method": "POST",
      "path": "/mint/replay-disclosurefree",
      "schema_version": "replay.disclosurefree; https://thehiveryiq.com/.well-known/schemas/replay-disclosurefree-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/tolerance-bond",
      "method": "POST",
      "path": "/verify/tolerance-bond",
      "schema_version": "tolerance.bond; https://thehiveryiq.com/.well-known/schemas/tolerance-bond-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/tolerance-bond",
      "method": "POST",
      "path": "/mint/tolerance-bond",
      "schema_version": "tolerance.bond; https://thehiveryiq.com/.well-known/schemas/tolerance-bond-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/render-profile",
      "method": "POST",
      "path": "/verify/render-profile",
      "schema_version": "render.profile; https://thehiveryiq.com/.well-known/schemas/render-profile-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/render-profile",
      "method": "POST",
      "path": "/mint/render-profile",
      "schema_version": "render.profile; https://thehiveryiq.com/.well-known/schemas/render-profile-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/verdict-custody",
      "method": "POST",
      "path": "/verify/verdict-custody",
      "schema_version": "verdict.custody; https://thehiveryiq.com/.well-known/schemas/verdict-custody-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/verdict-custody",
      "method": "POST",
      "path": "/mint/verdict-custody",
      "schema_version": "verdict.custody; https://thehiveryiq.com/.well-known/schemas/verdict-custody-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/divergence-attestation",
      "method": "POST",
      "path": "/verify/divergence-attestation",
      "schema_version": "divergence.attestation; https://thehiveryiq.com/.well-known/schemas/divergence-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/divergence-attestation",
      "method": "POST",
      "path": "/mint/divergence-attestation",
      "schema_version": "divergence.attestation; https://thehiveryiq.com/.well-known/schemas/divergence-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/determinism-class",
      "method": "POST",
      "path": "/verify/determinism-class",
      "schema_version": "determinism.class; https://thehiveryiq.com/.well-known/schemas/determinism-class-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/determinism-class",
      "method": "POST",
      "path": "/mint/determinism-class",
      "schema_version": "determinism.class; https://thehiveryiq.com/.well-known/schemas/determinism-class-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/stage-replay",
      "method": "POST",
      "path": "/verify/stage-replay",
      "schema_version": "stage.replay; https://thehiveryiq.com/.well-known/schemas/stage-replay-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/stage-replay",
      "method": "POST",
      "path": "/mint/stage-replay",
      "schema_version": "stage.replay; https://thehiveryiq.com/.well-known/schemas/stage-replay-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/binding-uncertainty",
      "method": "POST",
      "path": "/verify/binding-uncertainty",
      "schema_version": "binding.uncertainty; https://thehiveryiq.com/.well-known/schemas/binding-uncertainty-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/binding-uncertainty",
      "method": "POST",
      "path": "/mint/binding-uncertainty",
      "schema_version": "binding.uncertainty; https://thehiveryiq.com/.well-known/schemas/binding-uncertainty-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/absence-scope",
      "method": "POST",
      "path": "/verify/absence-scope",
      "schema_version": "absence.scope; https://thehiveryiq.com/.well-known/schemas/absence-scope-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/absence-scope",
      "method": "POST",
      "path": "/mint/absence-scope",
      "schema_version": "absence.scope; https://thehiveryiq.com/.well-known/schemas/absence-scope-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/decision-provenance",
      "method": "POST",
      "path": "/verify/decision-provenance",
      "schema_version": "decision.provenance; https://thehiveryiq.com/.well-known/schemas/decision-provenance-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/decision-provenance",
      "method": "POST",
      "path": "/mint/decision-provenance",
      "schema_version": "decision.provenance; https://thehiveryiq.com/.well-known/schemas/decision-provenance-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/origin-raster",
      "method": "POST",
      "path": "/verify/origin-raster",
      "schema_version": "origin.raster; https://thehiveryiq.com/.well-known/schemas/origin-raster-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/origin-raster",
      "method": "POST",
      "path": "/mint/origin-raster",
      "schema_version": "origin.raster; https://thehiveryiq.com/.well-known/schemas/origin-raster-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/verify/afir-ocr-docproof",
      "method": "POST",
      "path": "/verify/afir-ocr-docproof",
      "schema_version": "afir.ocr.docproof; https://thehiveryiq.com/.well-known/schemas/afir-ocr-docproof-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "POST https://hive-typed-receipts-api.onrender.com/mint/afir-ocr-docproof",
      "method": "POST",
      "path": "/mint/afir-ocr-docproof",
      "schema_version": "afir.ocr.docproof; https://thehiveryiq.com/.well-known/schemas/afir-ocr-docproof-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/tolerance-bond",
      "method": "GET",
      "path": "/demo/tolerance-bond",
      "schema_version": "tolerance.bond; https://thehiveryiq.com/.well-known/schemas/tolerance-bond-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/render-profile",
      "method": "GET",
      "path": "/demo/render-profile",
      "schema_version": "render.profile; https://thehiveryiq.com/.well-known/schemas/render-profile-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/verdict-custody",
      "method": "GET",
      "path": "/demo/verdict-custody",
      "schema_version": "verdict.custody; https://thehiveryiq.com/.well-known/schemas/verdict-custody-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/divergence-attestation",
      "method": "GET",
      "path": "/demo/divergence-attestation",
      "schema_version": "divergence.attestation; https://thehiveryiq.com/.well-known/schemas/divergence-attestation-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/determinism-class",
      "method": "GET",
      "path": "/demo/determinism-class",
      "schema_version": "determinism.class; https://thehiveryiq.com/.well-known/schemas/determinism-class-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/stage-replay",
      "method": "GET",
      "path": "/demo/stage-replay",
      "schema_version": "stage.replay; https://thehiveryiq.com/.well-known/schemas/stage-replay-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/binding-uncertainty",
      "method": "GET",
      "path": "/demo/binding-uncertainty",
      "schema_version": "binding.uncertainty; https://thehiveryiq.com/.well-known/schemas/binding-uncertainty-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/absence-scope",
      "method": "GET",
      "path": "/demo/absence-scope",
      "schema_version": "absence.scope; https://thehiveryiq.com/.well-known/schemas/absence-scope-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/decision-provenance",
      "method": "GET",
      "path": "/demo/decision-provenance",
      "schema_version": "decision.provenance; https://thehiveryiq.com/.well-known/schemas/decision-provenance-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/origin-raster",
      "method": "GET",
      "path": "/demo/origin-raster",
      "schema_version": "origin.raster; https://thehiveryiq.com/.well-known/schemas/origin-raster-v1.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/demo/afir-ocr-docproof",
      "method": "GET",
      "path": "/demo/afir-ocr-docproof",
      "schema_version": "afir.ocr.docproof; https://thehiveryiq.com/.well-known/schemas/afir-ocr-docproof-v2.json",
      "algorithm": "Ed25519",
      "key_identifier": "did:hive:typed-receipts-v2 observed via /keys; individual envelope may use another registered/example/caller key",
      "trust_source": "service registry or public example registry, with caller-key fallback where allowed; inspect result.key_trust. Service registry is not independent issuer approval.",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. 107 contracts exist in registry. Legacy v1/v2 acceptance depends on individual verifier. Signing sample data does not prove a real event.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "typed_api",
      "endpoint": "GET https://hive-typed-receipts-api.onrender.com/^\\/(verify|mint)(\\/|$)/",
      "method": "GET",
      "path": "/^\\/(verify|mint)(\\/|$)/",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "observation_time": "2026-09-05T22:10:11.729987+00:00",
      "observation_basis": "Source inventory reconciled to reviewed release; Render and live build identity agree.",
      "relevant_test_evidence": "431 focused local tests passed; broader run not a clean gate; local acceptance retains unavailable external timestamp and incomplete live coverage; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared; typed verification is stateless. External record history, backup, recovery and retention acceptance unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. HEAD is implicit on GET. Source registers unprefixed routes; /v1 aliases require separately verified proxy behavior.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "Reviewed release observed deployed; not per-route acceptance."
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/openapi.json",
      "method": "GET",
      "path": "/openapi.json",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/health",
      "method": "GET",
      "path": "/health",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/",
      "method": "GET",
      "path": "/",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/.well-known/agent.json",
      "method": "GET",
      "path": "/.well-known/agent.json",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/mcp",
      "method": "POST",
      "path": "/mcp",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/receipt/sign",
      "method": "POST",
      "path": "/v1/receipt/sign",
      "schema_version": "Spectral JSON payload envelope; formal schema/version unknown",
      "algorithm": "Ed25519; JSON.stringify payload field-order bytes",
      "key_identifier": "hive-receipt-spectral-1 advertised in JWKS, not a stable key fingerprint; runtime public key unknown",
      "trust_source": "embedded public key; current service-key discovery does not establish historical identity",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Payment receipt storage is a process Map. Audit tier changes price only, not seven-year retention. Signing endpoint not exercised with money.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/receipt/verify/:receipt_id",
      "method": "GET",
      "path": "/v1/receipt/verify/:receipt_id",
      "schema_version": "Spectral JSON payload envelope; formal schema/version unknown",
      "algorithm": "Ed25519; JSON.stringify payload field-order bytes",
      "key_identifier": "hive-receipt-spectral-1 advertised in JWKS, not a stable key fingerprint; runtime public key unknown",
      "trust_source": "embedded public key; current service-key discovery does not establish historical identity",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Payment receipt storage is a process Map. Audit tier changes price only, not seven-year retention. Signing endpoint not exercised with money.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/receipt/list/:payer_did",
      "method": "GET",
      "path": "/v1/receipt/list/:payer_did",
      "schema_version": "Spectral JSON payload envelope; formal schema/version unknown",
      "algorithm": "Ed25519; JSON.stringify payload field-order bytes",
      "key_identifier": "hive-receipt-spectral-1 advertised in JWKS, not a stable key fingerprint; runtime public key unknown",
      "trust_source": "embedded public key; current service-key discovery does not establish historical identity",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Payment receipt storage is a process Map. Audit tier changes price only, not seven-year retention. Signing endpoint not exercised with money.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/carnac/sandbox",
      "method": "POST",
      "path": "/v1/carnac/sandbox",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/carnac/judge",
      "method": "POST",
      "path": "/v1/carnac/judge",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/carnac/judgment/:id",
      "method": "GET",
      "path": "/v1/carnac/judgment/:id",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/carnac/trajectory/:id",
      "method": "GET",
      "path": "/v1/carnac/trajectory/:id",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/carnac/policy",
      "method": "GET",
      "path": "/v1/carnac/policy",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/carnac/policy/amend",
      "method": "POST",
      "path": "/v1/carnac/policy/amend",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/carnac/disposition",
      "method": "POST",
      "path": "/v1/carnac/disposition",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/carnac/howler/:id",
      "method": "GET",
      "path": "/v1/carnac/howler/:id",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/carnac/verify",
      "method": "POST",
      "path": "/v1/carnac/verify",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/carnac/verify/:id",
      "method": "GET",
      "path": "/v1/carnac/verify/:id",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/carnac/export",
      "method": "GET",
      "path": "/v1/carnac/export",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/carnac/seal",
      "method": "POST",
      "path": "/v1/carnac/seal",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/carnac/lifecycle/open",
      "method": "POST",
      "path": "/v1/carnac/lifecycle/open",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/carnac/lifecycle/:id/stage",
      "method": "POST",
      "path": "/v1/carnac/lifecycle/:id/stage",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/carnac/lifecycle/:id",
      "method": "GET",
      "path": "/v1/carnac/lifecycle/:id",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/carnac/lifecycle/:id/finalize",
      "method": "POST",
      "path": "/v1/carnac/lifecycle/:id/finalize",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/carnac/lifecycle/verify",
      "method": "POST",
      "path": "/v1/carnac/lifecycle/verify",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/carnac/health",
      "method": "GET",
      "path": "/v1/carnac/health",
      "schema_version": "Carnac artifact schema/version is operation-specific; exact version unknown here",
      "algorithm": "Ed25519 (wire ed25519) plus optional delegated ML-DSA-65; not every result is complete hybrid verification",
      "key_identifier": "embedded Spectral public_key; optional external signer key id/configuration unknown",
      "trust_source": "embedded key consistency; PQ result delegated to configured signer, not independently pinned",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. GET /v1/carnac/health can call signing/compute dependencies; deliberately not probed. Lifecycle and record-read routes can be tenant/auth sensitive.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/primitives",
      "method": "GET",
      "path": "/v1/primitives",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/primitives/smoke",
      "method": "GET",
      "path": "/v1/primitives/smoke",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/.well-known/x402",
      "method": "GET",
      "path": "/.well-known/x402",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/.well-known/agent-card.json",
      "method": "GET",
      "path": "/.well-known/agent-card.json",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/.well-known/ap2.json",
      "method": "GET",
      "path": "/.well-known/ap2.json",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/.well-known/openapi.json",
      "method": "GET",
      "path": "/.well-known/openapi.json",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/.well-known/jwks.json",
      "method": "GET",
      "path": "/.well-known/jwks.json",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/.well-known/did.json",
      "method": "GET",
      "path": "/.well-known/did.json",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/ping/clarity",
      "method": "GET",
      "path": "/ping/clarity",
      "schema_version": "telemetry row/HTML; no cryptographic receipt",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Log newly requires existing SITE_INTEL_TOKEN/OWNER_ADMIN_TOKEN mechanism; query-token compatibility retained, with no-store and no-referrer. Collector IP geolocation disabled; raw IP telemetry still exists.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/ping/clarity/log",
      "method": "GET",
      "path": "/ping/clarity/log",
      "schema_version": "telemetry row/HTML; no cryptographic receipt",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Log newly requires existing SITE_INTEL_TOKEN/OWNER_ADMIN_TOKEN mechanism; query-token compatibility retained, with no-store and no-referrer. Collector IP geolocation disabled; raw IP telemetry still exists.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/site/health",
      "method": "GET",
      "path": "/v1/site/health",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/site/intelligence",
      "method": "GET",
      "path": "/v1/site/intelligence",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. MCP exposes tools beyond this route; .well-known documents are metadata, not assurance. Exact availability/auth for this route not measured.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "GET https://hive-receipt.onrender.com/v1/inkframe/health",
      "method": "GET",
      "path": "/v1/inkframe/health",
      "schema_version": "inkframe-v1",
      "algorithm": "Ed25519 + ML-DSA-65; both component checks required by hybridVerify",
      "key_identifier": "per-frame embedded keys; runtime INKFRAME_SEED_B64 / gateway seed configuration unknown",
      "trust_source": "embedded keys; independent issuer approval not established",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Key fallback generates per-process keys. HTTP compatibility, deterministic-seed custody and retention gates remain.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/inkframe/frame",
      "method": "POST",
      "path": "/v1/inkframe/frame",
      "schema_version": "inkframe-v1",
      "algorithm": "Ed25519 + ML-DSA-65; both component checks required by hybridVerify",
      "key_identifier": "per-frame embedded keys; runtime INKFRAME_SEED_B64 / gateway seed configuration unknown",
      "trust_source": "embedded keys; independent issuer approval not established",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Key fallback generates per-process keys. HTTP compatibility, deterministic-seed custody and retention gates remain.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/inkframe/prefill",
      "method": "POST",
      "path": "/v1/inkframe/prefill",
      "schema_version": "inkframe-v1",
      "algorithm": "Ed25519 + ML-DSA-65; both component checks required by hybridVerify",
      "key_identifier": "per-frame embedded keys; runtime INKFRAME_SEED_B64 / gateway seed configuration unknown",
      "trust_source": "embedded keys; independent issuer approval not established",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Key fallback generates per-process keys. HTTP compatibility, deterministic-seed custody and retention gates remain.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/inkframe/cue-edge",
      "method": "POST",
      "path": "/v1/inkframe/cue-edge",
      "schema_version": "inkframe-v1",
      "algorithm": "Ed25519 + ML-DSA-65; both component checks required by hybridVerify",
      "key_identifier": "per-frame embedded keys; runtime INKFRAME_SEED_B64 / gateway seed configuration unknown",
      "trust_source": "embedded keys; independent issuer approval not established",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Key fallback generates per-process keys. HTTP compatibility, deterministic-seed custody and retention gates remain.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/inkframe/replay",
      "method": "POST",
      "path": "/v1/inkframe/replay",
      "schema_version": "inkframe-v1",
      "algorithm": "Ed25519 + ML-DSA-65; both component checks required by hybridVerify",
      "key_identifier": "per-frame embedded keys; runtime INKFRAME_SEED_B64 / gateway seed configuration unknown",
      "trust_source": "embedded keys; independent issuer approval not established",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Key fallback generates per-process keys. HTTP compatibility, deterministic-seed custody and retention gates remain.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/inkframe/countersign",
      "method": "POST",
      "path": "/v1/inkframe/countersign",
      "schema_version": "inkframe-v1",
      "algorithm": "Ed25519 + ML-DSA-65; both component checks required by hybridVerify",
      "key_identifier": "per-frame embedded keys; runtime INKFRAME_SEED_B64 / gateway seed configuration unknown",
      "trust_source": "embedded keys; independent issuer approval not established",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Key fallback generates per-process keys. HTTP compatibility, deterministic-seed custody and retention gates remain.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/inkframe/verify-frame",
      "method": "POST",
      "path": "/v1/inkframe/verify-frame",
      "schema_version": "inkframe-v1",
      "algorithm": "Ed25519 + ML-DSA-65; both component checks required by hybridVerify",
      "key_identifier": "per-frame embedded keys; runtime INKFRAME_SEED_B64 / gateway seed configuration unknown",
      "trust_source": "embedded keys; independent issuer approval not established",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Key fallback generates per-process keys. HTTP compatibility, deterministic-seed custody and retention gates remain.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/inkframe/verify-replay",
      "method": "POST",
      "path": "/v1/inkframe/verify-replay",
      "schema_version": "inkframe-v1",
      "algorithm": "Ed25519 + ML-DSA-65; both component checks required by hybridVerify",
      "key_identifier": "per-frame embedded keys; runtime INKFRAME_SEED_B64 / gateway seed configuration unknown",
      "trust_source": "embedded keys; independent issuer approval not established",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Key fallback generates per-process keys. HTTP compatibility, deterministic-seed custody and retention gates remain.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "POST https://hive-receipt.onrender.com/v1/inkframe/verify-countersign",
      "method": "POST",
      "path": "/v1/inkframe/verify-countersign",
      "schema_version": "inkframe-v1",
      "algorithm": "Ed25519 + ML-DSA-65; both component checks required by hybridVerify",
      "key_identifier": "per-frame embedded keys; runtime INKFRAME_SEED_B64 / gateway seed configuration unknown",
      "trust_source": "embedded keys; independent issuer approval not established",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Key fallback generates per-process keys. HTTP compatibility, deterministic-seed custody and retention gates remain.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "receipt",
      "endpoint": "OPTIONS https://hive-receipt.onrender.com*",
      "method": "OPTIONS",
      "path": "*",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "cfd51e9f95f237ce29c2a61c08c4fe3999dd5ae9",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "174 local tests passed; local HTTP and synthetic telemetry checks passed; no deployed signer/auth, persistence or key-continuity acceptance; not a claim that this individual endpoint passed",
      "durability_status": "No Render disk declared. Payment receipt Map is process-memory. Carnac optional external store may degrade to memory; deployed configuration/recovery unknown. Telemetry retention/RLS unknown.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Global middleware preflight handler; receipt routes and Carnac differ in CORS policy.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "typed_signer",
      "endpoint": "GET https://hive-typed-signer.onrender.com/",
      "method": "GET",
      "path": "/",
      "schema_version": "metadata",
      "algorithm": "not applicable",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "GET https://hive-typed-signer.onrender.com/health",
      "method": "GET",
      "path": "/health",
      "schema_version": "metadata",
      "algorithm": "not applicable",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "GET https://hive-typed-signer.onrender.com/pubkey",
      "method": "GET",
      "path": "/pubkey",
      "schema_version": "metadata",
      "algorithm": "not applicable",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "GET https://hive-typed-signer.onrender.com/qpuf/info",
      "method": "GET",
      "path": "/qpuf/info",
      "schema_version": "metadata",
      "algorithm": "not applicable",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "GET https://hive-typed-signer.onrender.com/signing-backends",
      "method": "GET",
      "path": "/signing-backends",
      "schema_version": "metadata",
      "algorithm": "not applicable",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sign",
      "method": "POST",
      "path": "/sign",
      "schema_version": "Carnac digest-binding object or typed-fragment envelope r1.0.0",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sign-qpuf",
      "method": "POST",
      "path": "/sign-qpuf",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/verify",
      "method": "POST",
      "path": "/verify",
      "schema_version": "Carnac digest-binding object or typed-fragment envelope r1.0.0",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/bill",
      "method": "POST",
      "path": "/sigr/bill",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/bill/verify",
      "method": "POST",
      "path": "/sigr/bill/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/bond",
      "method": "POST",
      "path": "/sigr/bond",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/bond/verify",
      "method": "POST",
      "path": "/sigr/bond/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/chain",
      "method": "POST",
      "path": "/sigr/chain",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/chain/verify",
      "method": "POST",
      "path": "/sigr/chain/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/consensus",
      "method": "POST",
      "path": "/sigr/consensus",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/consensus/verify",
      "method": "POST",
      "path": "/sigr/consensus/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/toolscope",
      "method": "POST",
      "path": "/sigr/toolscope",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/toolscope/verify",
      "method": "POST",
      "path": "/sigr/toolscope/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/agentic",
      "method": "POST",
      "path": "/sigr/agentic",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/agentic/verify",
      "method": "POST",
      "path": "/sigr/agentic/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/cern",
      "method": "POST",
      "path": "/sigr/cern",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/cern/verify",
      "method": "POST",
      "path": "/sigr/cern/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/reward",
      "method": "POST",
      "path": "/sigr/reward",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/reward/verify",
      "method": "POST",
      "path": "/sigr/reward/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/gca",
      "method": "POST",
      "path": "/sigr/gca",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/gca/verify",
      "method": "POST",
      "path": "/sigr/gca/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/gitm",
      "method": "POST",
      "path": "/sigr/gitm",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/gitm/verify",
      "method": "POST",
      "path": "/sigr/gitm/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/toolanchor",
      "method": "POST",
      "path": "/sigr/toolanchor",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/toolanchor/verify",
      "method": "POST",
      "path": "/sigr/toolanchor/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/cachesign",
      "method": "POST",
      "path": "/sigr/cachesign",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/cachesign/verify",
      "method": "POST",
      "path": "/sigr/cachesign/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/manifest",
      "method": "POST",
      "path": "/sigr/manifest",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/manifest/verify",
      "method": "POST",
      "path": "/sigr/manifest/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/mir",
      "method": "POST",
      "path": "/sigr/mir",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/mir/verify",
      "method": "POST",
      "path": "/sigr/mir/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/' + r.path + '/verify",
      "method": "POST",
      "path": "/sigr/' + r.path + '/verify",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/upstream/gate",
      "method": "POST",
      "path": "/sigr/upstream/gate",
      "schema_version": "operation-specific typed schema/version unknown",
      "algorithm": "ML-DSA-65; optional QPUF preprocessing is not a separate signature algorithm",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "GET https://hive-typed-signer.onrender.com/sigr/upstream",
      "method": "GET",
      "path": "/sigr/upstream",
      "schema_version": "metadata",
      "algorithm": "not applicable",
      "key_identifier": "did:hive:typed-demo observed at /pubkey; no cryptographic identity pin established",
      "trust_source": "demo public key; several verification routes accept embedded caller keys",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Public demo key designation observed. Carnac branch may require X-Hive-Internal-Token; receipt client bearer-token integration not established. No push or source edit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/pbs/manifest",
      "method": "POST",
      "path": "/sigr/pbs/manifest",
      "schema_version": "usap.v1; pbs.manifest",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/pbs/manifest/verify",
      "method": "POST",
      "path": "/sigr/pbs/manifest/verify",
      "schema_version": "usap.v1; pbs.manifest",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/pbs/attestation",
      "method": "POST",
      "path": "/sigr/pbs/attestation",
      "schema_version": "usap.v1; pbs.attestation",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/pbs/attestation/verify",
      "method": "POST",
      "path": "/sigr/pbs/attestation/verify",
      "schema_version": "usap.v1; pbs.attestation",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/refusal/mutation",
      "method": "POST",
      "path": "/sigr/refusal/mutation",
      "schema_version": "usap.v1; refusal.mutation",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/refusal/mutation/verify",
      "method": "POST",
      "path": "/sigr/refusal/mutation/verify",
      "schema_version": "usap.v1; refusal.mutation",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/refusal/binding",
      "method": "POST",
      "path": "/sigr/refusal/binding",
      "schema_version": "usap.v1; refusal.binding",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/refusal/binding/verify",
      "method": "POST",
      "path": "/sigr/refusal/binding/verify",
      "schema_version": "usap.v1; refusal.binding",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/howler/drift",
      "method": "POST",
      "path": "/sigr/howler/drift",
      "schema_version": "usap.v1; howler.drift",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/howler/drift/verify",
      "method": "POST",
      "path": "/sigr/howler/drift/verify",
      "schema_version": "usap.v1; howler.drift",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/howler/capability",
      "method": "POST",
      "path": "/sigr/howler/capability",
      "schema_version": "usap.v1; howler.capability",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/howler/capability/verify",
      "method": "POST",
      "path": "/sigr/howler/capability/verify",
      "schema_version": "usap.v1; howler.capability",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/howler/contamination",
      "method": "POST",
      "path": "/sigr/howler/contamination",
      "schema_version": "usap.v1; howler.contamination",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/howler/contamination/verify",
      "method": "POST",
      "path": "/sigr/howler/contamination/verify",
      "schema_version": "usap.v1; howler.contamination",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/perimeter/manifest",
      "method": "POST",
      "path": "/sigr/perimeter/manifest",
      "schema_version": "usap.v1; perimeter.manifest",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/perimeter/manifest/verify",
      "method": "POST",
      "path": "/sigr/perimeter/manifest/verify",
      "schema_version": "usap.v1; perimeter.manifest",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/perimeter/attempt",
      "method": "POST",
      "path": "/sigr/perimeter/attempt",
      "schema_version": "usap.v1; perimeter.attempt",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/perimeter/attempt/verify",
      "method": "POST",
      "path": "/sigr/perimeter/attempt/verify",
      "schema_version": "usap.v1; perimeter.attempt",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/diurnal/regime",
      "method": "POST",
      "path": "/sigr/diurnal/regime",
      "schema_version": "usap.v1; diurnal.regime",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/diurnal/regime/verify",
      "method": "POST",
      "path": "/sigr/diurnal/regime/verify",
      "schema_version": "usap.v1; diurnal.regime",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/diurnal/attestation",
      "method": "POST",
      "path": "/sigr/diurnal/attestation",
      "schema_version": "usap.v1; diurnal.attestation",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/diurnal/attestation/verify",
      "method": "POST",
      "path": "/sigr/diurnal/attestation/verify",
      "schema_version": "usap.v1; diurnal.attestation",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/egress/manifest",
      "method": "POST",
      "path": "/sigr/egress/manifest",
      "schema_version": "usap.v1; egress.manifest",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/egress/manifest/verify",
      "method": "POST",
      "path": "/sigr/egress/manifest/verify",
      "schema_version": "usap.v1; egress.manifest",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/egress/measurement",
      "method": "POST",
      "path": "/sigr/egress/measurement",
      "schema_version": "usap.v1; egress.measurement",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/egress/measurement/verify",
      "method": "POST",
      "path": "/sigr/egress/measurement/verify",
      "schema_version": "usap.v1; egress.measurement",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/forensic/credential",
      "method": "POST",
      "path": "/sigr/forensic/credential",
      "schema_version": "usap.v1; forensic.credential",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/forensic/credential/verify",
      "method": "POST",
      "path": "/sigr/forensic/credential/verify",
      "schema_version": "usap.v1; forensic.credential",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/forensic/analysis",
      "method": "POST",
      "path": "/sigr/forensic/analysis",
      "schema_version": "usap.v1; forensic.analysis",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "POST https://hive-typed-signer.onrender.com/sigr/forensic/analysis/verify",
      "method": "POST",
      "path": "/sigr/forensic/analysis/verify",
      "schema_version": "usap.v1; forensic.analysis",
      "algorithm": "ML-DSA-65",
      "key_identifier": "did:hive:typed-demo / envelope-carried key; exact trusted issuer mapping unknown",
      "trust_source": "configured or envelope-supplied key; no independent issuer pin",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Dynamic UPSTREAM_ROUTES registration. Optional expiry override and cross-receipt rules are caller-dependent; no execution or governance acceptance.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "typed_signer",
      "endpoint": "OPTIONS https://hive-typed-signer.onrender.com*",
      "method": "OPTIONS",
      "path": "*",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "Source reviewed; real local ML-DSA compatibility test covers Carnac module only, not deployed HTTP/auth or other endpoints; not a claim that this individual endpoint passed",
      "durability_status": "Key custody, historical key mapping, restart and receipt retention evidence unknown; no changes made.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Express CORS middleware preflight, not an additional verification contract.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "observed deployed source, unmodified in this audit"
    },
    {
      "service": "countersigner",
      "endpoint": "GET https://hive-countersigner.onrender.com/health",
      "method": "GET",
      "path": "/health",
      "schema_version": "unversioned countersigner signed record / BLAKE3-domain-separated log",
      "algorithm": "Ed25519 countersignature; briefing operator ML-DSA-65 is a separate component",
      "key_identifier": "runtime countersigner_public_key_b64; no stable kid; fingerprint unknown in inventory",
      "trust_source": "current service key or caller-supplied key distinguished; operator_signature only length-checked",
      "source_revision": "c9d381b180bd687e0beca37361034657abb9cf99",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "11 isolated local tests passed with temporary key/log; ordinary local restart only; briefing routes not exercised; not a claim that this individual endpoint passed",
      "durability_status": "Authenticated Render metadata declares 1GB /var/hive disk, one worker. Local ordinary restart tested; crash/truncation/rollback/backup/restore/historical-key recovery not accepted.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. No independent party; supplied-root inclusion is not a trusted checkpoint, non-equivocation, completeness or replay proof.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "countersigner",
      "endpoint": "POST https://hive-countersigner.onrender.com/countersign",
      "method": "POST",
      "path": "/countersign",
      "schema_version": "unversioned countersigner signed record / BLAKE3-domain-separated log",
      "algorithm": "Ed25519 countersignature; briefing operator ML-DSA-65 is a separate component",
      "key_identifier": "runtime countersigner_public_key_b64; no stable kid; fingerprint unknown in inventory",
      "trust_source": "current service key or caller-supplied key distinguished; operator_signature only length-checked",
      "source_revision": "c9d381b180bd687e0beca37361034657abb9cf99",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "11 isolated local tests passed with temporary key/log; ordinary local restart only; briefing routes not exercised; not a claim that this individual endpoint passed",
      "durability_status": "Authenticated Render metadata declares 1GB /var/hive disk, one worker. Local ordinary restart tested; crash/truncation/rollback/backup/restore/historical-key recovery not accepted.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. No independent party; supplied-root inclusion is not a trusted checkpoint, non-equivocation, completeness or replay proof.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "countersigner",
      "endpoint": "GET https://hive-countersigner.onrender.com/log/head",
      "method": "GET",
      "path": "/log/head",
      "schema_version": "unversioned countersigner signed record / BLAKE3-domain-separated log",
      "algorithm": "Ed25519 countersignature; briefing operator ML-DSA-65 is a separate component",
      "key_identifier": "runtime countersigner_public_key_b64; no stable kid; fingerprint unknown in inventory",
      "trust_source": "current service key or caller-supplied key distinguished; operator_signature only length-checked",
      "source_revision": "c9d381b180bd687e0beca37361034657abb9cf99",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "11 isolated local tests passed with temporary key/log; ordinary local restart only; briefing routes not exercised; not a claim that this individual endpoint passed",
      "durability_status": "Authenticated Render metadata declares 1GB /var/hive disk, one worker. Local ordinary restart tested; crash/truncation/rollback/backup/restore/historical-key recovery not accepted.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. No independent party; supplied-root inclusion is not a trusted checkpoint, non-equivocation, completeness or replay proof.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "countersigner",
      "endpoint": "GET https://hive-countersigner.onrender.com/log/inclusion",
      "method": "GET",
      "path": "/log/inclusion",
      "schema_version": "unversioned countersigner signed record / BLAKE3-domain-separated log",
      "algorithm": "Ed25519 countersignature; briefing operator ML-DSA-65 is a separate component",
      "key_identifier": "runtime countersigner_public_key_b64; no stable kid; fingerprint unknown in inventory",
      "trust_source": "current service key or caller-supplied key distinguished; operator_signature only length-checked",
      "source_revision": "c9d381b180bd687e0beca37361034657abb9cf99",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "11 isolated local tests passed with temporary key/log; ordinary local restart only; briefing routes not exercised; not a claim that this individual endpoint passed",
      "durability_status": "Authenticated Render metadata declares 1GB /var/hive disk, one worker. Local ordinary restart tested; crash/truncation/rollback/backup/restore/historical-key recovery not accepted.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. No independent party; supplied-root inclusion is not a trusted checkpoint, non-equivocation, completeness or replay proof.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "countersigner",
      "endpoint": "POST https://hive-countersigner.onrender.com/verify",
      "method": "POST",
      "path": "/verify",
      "schema_version": "unversioned countersigner signed record / BLAKE3-domain-separated log",
      "algorithm": "Ed25519 countersignature; briefing operator ML-DSA-65 is a separate component",
      "key_identifier": "runtime countersigner_public_key_b64; no stable kid; fingerprint unknown in inventory",
      "trust_source": "current service key or caller-supplied key distinguished; operator_signature only length-checked",
      "source_revision": "c9d381b180bd687e0beca37361034657abb9cf99",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "11 isolated local tests passed with temporary key/log; ordinary local restart only; briefing routes not exercised; not a claim that this individual endpoint passed",
      "durability_status": "Authenticated Render metadata declares 1GB /var/hive disk, one worker. Local ordinary restart tested; crash/truncation/rollback/backup/restore/historical-key recovery not accepted.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. No independent party; supplied-root inclusion is not a trusted checkpoint, non-equivocation, completeness or replay proof.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "countersigner",
      "endpoint": "POST https://hive-countersigner.onrender.com/briefing/issue",
      "method": "POST",
      "path": "/briefing/issue",
      "schema_version": "briefing r1.0.0 operator envelope plus countersigner record; countersign log schema unversioned",
      "algorithm": "Ed25519 countersignature; briefing operator ML-DSA-65 is a separate component",
      "key_identifier": "runtime countersigner_public_key_b64; no stable kid; fingerprint unknown in inventory",
      "trust_source": "current service key or caller-supplied key distinguished; operator_signature only length-checked",
      "source_revision": "c9d381b180bd687e0beca37361034657abb9cf99",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "11 isolated local tests passed with temporary key/log; ordinary local restart only; briefing routes not exercised; not a claim that this individual endpoint passed",
      "durability_status": "Authenticated Render metadata declares 1GB /var/hive disk, one worker. Local ordinary restart tested; crash/truncation/rollback/backup/restore/historical-key recovery not accepted.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. No independent party; supplied-root inclusion is not a trusted checkpoint, non-equivocation, completeness or replay proof.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "countersigner",
      "endpoint": "GET https://hive-countersigner.onrender.com/briefing/receipt/<receipt_id>",
      "method": "GET",
      "path": "/briefing/receipt/<receipt_id>",
      "schema_version": "briefing r1.0.0 operator envelope plus countersigner record; countersign log schema unversioned",
      "algorithm": "Ed25519 countersignature; briefing operator ML-DSA-65 is a separate component",
      "key_identifier": "runtime countersigner_public_key_b64; no stable kid; fingerprint unknown in inventory",
      "trust_source": "current service key or caller-supplied key distinguished; operator_signature only length-checked",
      "source_revision": "c9d381b180bd687e0beca37361034657abb9cf99",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "11 isolated local tests passed with temporary key/log; ordinary local restart only; briefing routes not exercised; not a claim that this individual endpoint passed",
      "durability_status": "Authenticated Render metadata declares 1GB /var/hive disk, one worker. Local ordinary restart tested; crash/truncation/rollback/backup/restore/historical-key recovery not accepted.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. No independent party; supplied-root inclusion is not a trusted checkpoint, non-equivocation, completeness or replay proof.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "countersigner",
      "endpoint": "POST https://hive-countersigner.onrender.com/briefing/check",
      "method": "POST",
      "path": "/briefing/check",
      "schema_version": "briefing r1.0.0 operator envelope plus countersigner record; countersign log schema unversioned",
      "algorithm": "Ed25519 countersignature; briefing operator ML-DSA-65 is a separate component",
      "key_identifier": "runtime countersigner_public_key_b64; no stable kid; fingerprint unknown in inventory",
      "trust_source": "current service key or caller-supplied key distinguished; operator_signature only length-checked",
      "source_revision": "c9d381b180bd687e0beca37361034657abb9cf99",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "11 isolated local tests passed with temporary key/log; ordinary local restart only; briefing routes not exercised; not a claim that this individual endpoint passed",
      "durability_status": "Authenticated Render metadata declares 1GB /var/hive disk, one worker. Local ordinary restart tested; crash/truncation/rollback/backup/restore/historical-key recovery not accepted.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. No independent party; supplied-root inclusion is not a trusted checkpoint, non-equivocation, completeness or replay proof.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "countersigner",
      "endpoint": "GET https://hive-countersigner.onrender.com/briefing/check",
      "method": "GET",
      "path": "/briefing/check",
      "schema_version": "briefing r1.0.0 operator envelope plus countersigner record; countersign log schema unversioned",
      "algorithm": "Ed25519 countersignature; briefing operator ML-DSA-65 is a separate component",
      "key_identifier": "runtime countersigner_public_key_b64; no stable kid; fingerprint unknown in inventory",
      "trust_source": "current service key or caller-supplied key distinguished; operator_signature only length-checked",
      "source_revision": "c9d381b180bd687e0beca37361034657abb9cf99",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "11 isolated local tests passed with temporary key/log; ordinary local restart only; briefing routes not exercised; not a claim that this individual endpoint passed",
      "durability_status": "Authenticated Render metadata declares 1GB /var/hive disk, one worker. Local ordinary restart tested; crash/truncation/rollback/backup/restore/historical-key recovery not accepted.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. No independent party; supplied-root inclusion is not a trusted checkpoint, non-equivocation, completeness or replay proof.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "countersigner",
      "endpoint": "GET https://hive-countersigner.onrender.com/briefing/qr",
      "method": "GET",
      "path": "/briefing/qr",
      "schema_version": "briefing r1.0.0 operator envelope plus countersigner record; countersign log schema unversioned",
      "algorithm": "Ed25519 countersignature; briefing operator ML-DSA-65 is a separate component",
      "key_identifier": "runtime countersigner_public_key_b64; no stable kid; fingerprint unknown in inventory",
      "trust_source": "current service key or caller-supplied key distinguished; operator_signature only length-checked",
      "source_revision": "c9d381b180bd687e0beca37361034657abb9cf99",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "11 isolated local tests passed with temporary key/log; ordinary local restart only; briefing routes not exercised; not a claim that this individual endpoint passed",
      "durability_status": "Authenticated Render metadata declares 1GB /var/hive disk, one worker. Local ordinary restart tested; crash/truncation/rollback/backup/restore/historical-key recovery not accepted.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. No independent party; supplied-root inclusion is not a trusted checkpoint, non-equivocation, completeness or replay proof.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "countersigner",
      "endpoint": "OPTIONS https://hive-countersigner.onrender.com/",
      "method": "OPTIONS",
      "path": "/",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "c9d381b180bd687e0beca37361034657abb9cf99",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "11 isolated local tests passed with temporary key/log; ordinary local restart only; briefing routes not exercised; not a claim that this individual endpoint passed",
      "durability_status": "Authenticated Render metadata declares 1GB /var/hive disk, one worker. Local ordinary restart tested; crash/truncation/rollback/backup/restore/historical-key recovery not accepted.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Explicit Flask preflight; HEAD and automatic OPTIONS on GET otherwise implicit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    },
    {
      "service": "countersigner",
      "endpoint": "OPTIONS https://hive-countersigner.onrender.com/<path:_any>",
      "method": "OPTIONS",
      "path": "/<path:_any>",
      "schema_version": "not applicable: metadata/nonreceipt endpoint",
      "algorithm": "not applicable: endpoint does not itself verify or sign",
      "key_identifier": "not applicable",
      "trust_source": "not applicable",
      "source_revision": "c9d381b180bd687e0beca37361034657abb9cf99",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "observation_time": "2026-09-05T21:29:32.273858+00:00",
      "observation_basis": "Source inventory at observation_time; deployed revisions from parent's authenticated Render snapshot, not attested by this endpoint",
      "relevant_test_evidence": "11 isolated local tests passed with temporary key/log; ordinary local restart only; briefing routes not exercised; not a claim that this individual endpoint passed",
      "durability_status": "Authenticated Render metadata declares 1GB /var/hive disk, one worker. Local ordinary restart tested; crash/truncation/rollback/backup/restore/historical-key recovery not accepted.",
      "limitations": "Source-defined route, not a production availability claim. Unknown deployment auth, issuer approval and proxy rewriting unless expressly noted. Explicit Flask preflight; HEAD and automatic OPTIONS on GET otherwise implicit.",
      "source_reference": "reviewed service source; deployment source identity must be checked independently",
      "source_revision_status": "local audit candidate; not asserted deployed"
    }
  ],
  "publication_status": "source-audit metadata; candidate corrections not deployed by this audit worker; not operational acceptance",
  "publication_note": "Contains endpoint patterns, declared algorithms, public key identifiers, source revisions and explicit limitations; no customer records, raw key material or internal evidence file paths. Before release, refresh deployed revisions and observation times independently.",
  "release_binding": "Dated verification of the reviewed content revision, not a claim that this registry's containing commit was tested or deployed. Subsequent parser, link and metadata changes are tracked separately. No endpoint acceptance follows from a source or deployment identifier."
}
