Signing and Key Handling
Public docs keep this section intentionally high-level.
Public Principles
- Signing keys must stay server-side and never be exposed to client bundles.
- Different operational duties should use separate key scopes.
- Signed payloads should be strict, short-lived, and nonce-protected.
What Is Internal
- Signer rotation steps.
- Environment-level key wiring.
- Incident response for key compromise.
