GOLDEN PATH

Golden path · Verify custody

Hashing is present. Project signing is not yet complete.

HydraDG uses SHA-256 content identity for FCOs and FCG artifacts. The current project release does not have an admitted Ed25519 signature receipt sealing every current FCO/FCG, so the site must not call the project graph signed or sealed.

01 / CURRENT PROJECT STATE

Identity ≠ signature.

Object identity

SHA-256

ONE_CANONICAL_SHA256_PER_FCO. Byte/object identity only; not authorship, truth, or verification.

Ed25519 project signature

PENDING_EXTERNAL_PRIVATE_KEY_OPERATION

No current project public-key + detached-signature verification receipt has been admitted for every current project object.

Merkle / MMR

NOT_PROJECT_COMMITTED

A normal SHA-256 FCO identity is not promoted to a Merkle/MMR commitment.

02 / PRIVATE KEY BOUNDARY

The private key belongs outside the website.

Policy: EXTERNAL_SECRET_NOT_IN_GIT_HYDRADB_BROWSER_HTML_OR_PIXELS.

The website can render a public key or public-key fingerprint after it is admitted by a real signing receipt. It must never ship the authentic private key in JavaScript, HTML, CSS, image pixels, Git history, HydraDB records or public environment variables.

03 / PUBLICATION KEY

A real signed lineage exists—but its scope is the publication.

FCO publication v1 · Ed25519

DOI: 10.5281/zenodo.21210575

Public-key SHA-256 fingerprint:

f496a067808026d45fbbad785bf83c6acd66429c2d257d246cc103c6d7ff460d

Signed FCG root prefix: 741d12de…

Scope: PUBLICATION_FCG_ROOT_ONLY_NOT_HYDRADG_PROJECT_GRAPH. This signature cannot be inherited by later HydraDG project objects without a separate signing operation and receipt.

04 / REQUIRED PROJECT SIGNING FLOW

Seal only after the operation exists.

01canonical FCO/FCG bytes
02SHA-256 identity
03authorized external Ed25519 private-key operation
04detached signature
05public-key verification
06SigningReceiptFCO
07FCG successor edge

Required successor evidence: actual public key, detached signature, verified signature result and a SigningReceiptFCO linked into the project FCG. Until then, the claim ceiling remains HASHED_PROJECT_CUSTODY_OBJECTS_NOT_CURRENTLY_PROJECT_SIGNED_OR_MERKLE_COMMITTED.