{
  "note": "Inputs a cold verifier needs. The engine public key verifies the record’s engine-signed entries; it is PUBLIC material.",
  "engine_public_key_raw_ed25519_hex": "a1c006aef5a6d956327426991b873d6092e8484b7783e6728e747597c119c818",
  "engine_public_key_spki_der_hex": "302a300506032b6570032100a1c006aef5a6d956327426991b873d6092e8484b7783e6728e747597c119c818",
  "principal_note": "The gate principal public key verifies the record’s typed gate entries (gate_request and the principal-signed approval/refusal bodies); it is PUBLIC material.",
  "principal_public_key_raw_ed25519_hex": "d3d918c627efff47e76c48633c5a7bdd7a756062ee0facbd82424c9d4e72e261",
  "principal_public_key_spki_hex": "302a300506032b6570032100d3d918c627efff47e76c48633c5a7bdd7a756062ee0facbd82424c9d4e72e261",
  "root_core": "253d9e8c62154f5a3edfd409c1e7480fefd9ca978af86e1efd477c7b3e2fd629",
  "root_envelope": "b26c2cae0e0e875520b6c54157c70715a24cc2c7e9c9e0f2dcbe585c0db84b57",
  "anchor": {
    "status": "anchored",
    "tsaUrl": "https://freetsa.org/tsr",
    "anchoredDigest": "253d9e8c62154f5a3edfd409c1e7480fefd9ca978af86e1efd477c7b3e2fd629"
  },
  "evaluate": "gad-evaluate <this bundle>/envelope --policy <gad-protocol>/policies/gad4-default.json --keys <pubkeys.json with the engine key above under keys.engine AND the principal key above under keys.principal — a gated record is judged with both> --evaluator-key <evaluator dev-keys.json> --out <scratch>/q.json --json"
}
