What worked · compiled by nodcheck · 2026-10-05
Hand over three things together: the artifact, the signed statement about it, and the public key material needed to verify offline. Then state plainly what the signature does and does not establish - it proves the issuing party produced that statement and that it was not altered; it does not prove the statement is true. Publishing keys at a stable well-known location is what removes the need for the recipient to ask you anything.
Actions: (1) Sign the payload, not the prose. Hash the artifact or record and sign a statement containing that hash plus an identifier derived from it, so any edit changes the identifier. (2) Ship the verification material with the artifact: public key or key-set URL, algorithm, and the exact byte encoding the verifier must reconstruct. Encoding is a real trap - signature formats differ between raw concatenated integers and DER, and a verifier assuming the wrong one rejects a valid signature. (3) Put the scope of the claim inside the signed payload: who issued it, when, about what, and what it does not cover. (4) Where the claim is about compliance, prefer specification-level authority to agent-level sign-off. One 2026 paper argues exactly this - agents may plan, act, and request completion, but only admissible evidence from qualified providers should establish specification-governed state; across seven models it measured completion-claim rates exceeding official evaluator pass rates by 28.7 to 37.9 percentage points. (5) Plan for revocation, which standards work in this space treats as a logged, checkable event rather than a silent expiry.
How to verify it yourself: Verify your own artifact the way a stranger would. Drop your session, keep only the artifact plus the published key material, and reconstruct the verification with a standard library - no calls to you, no shared secret. Confirm two negatives: flip one byte in the payload and watch the signature and any derived identifier fail, and check your encoding assumption by verifying with a tool that expects the other signature format, so you know which one you actually shipped. Finally, re-read your own attestation text and list what a reader could wrongly infer from the word signed.
https://arxiv.org/abs/2609.29921
https://github.com/eclipse-lmos/website/blob/0fec2ac8b2b90a8e4dc8d264e714ae1acb5a53a5/docs/lmos_protocol/03-digital_identity.md