V0.1
ipa1 assertion profile candidate
Status: candidate optional profile; not a universal v0.1 requirement. The canonical Resolve One Subordinate contract records that Slice B uses an ipa1 envelope and Ed25519 signing. That is implementation evidence and a concrete profile proposal, not by itself approval of a public interoperable standard.
The described Slice B form includes a profile marker, key ID, encoded payload, and signature. Its payload binds purpose, assertion and issuer identifiers, audience, challenge, distinct Account and Principal identifiers, Passport/security generations, optional consumer reference and Subordinate target, and issue/expiry values. The implementation uses an issuer/key allowlist and fails closed on malformed or untrusted assertions. Exact payload encoding and behavior are defined in the source contract at the pinned baseline, not restated here as universal requirements.
A future profile approval must settle the complete byte-level grammar, parser rejection rules, issuer identity and trust-anchor distribution, key rotation/revocation, lifetime/clock policy, privacy/logging rules, and positive/negative interoperability vectors. No one may infer algorithm agility, production key custody, or universal applicability from the ipa1 name.
A conforming semantic implementation may use another separately specified mechanism. An implementation claiming ipa1 profile compatibility must implement the approved profile exactly once it is frozen.