Signing-key ID (kid)
The 4-byte identifier of an Ed25519 signing key, SHA-256 over the 0x51 byte prefix and the public key truncated to 4 bytes and written as 8 lowercase hex characters, recorded on items, blocks, entropy observations, commitments, and the signing_key_id field of a bundle's subject and block maps.
Overview
A signing-key ID (kid) is a short identifier of one of Truestamp’s Ed25519 signing keys: SHA-256 over the byte prefix 0x51 followed by the 32-byte public key, truncated to the first 4 bytes and written as 8 lowercase hex characters. It is recorded on every item, block, entropy observation, and commitment record, and bound into each object’s composite hash. A proof bundle carries it as signing_key_id on the subject and on every block map it contains, and as the kid field of the signed payload. A verifier uses it to look up the exact public key that produced a signature, which is what lets signatures made by an earlier key keep verifying after key rotation; under legitimate rotation the proof signer’s key id may differ from the block’s or subject’s, and that is allowed. See Ed25519 signatures and the proof bundle wire format; the item-side binding is part of the item’s composite fingerprint.