Publish the public keys agents use to check your messages
Your UCP profile lists no public keys, so an agent cannot confirm that a message really came from your store.
Why it matters
Agents use these keys to check that checkout messages really came from you. A store that takes payment through the agent needs them. A store that sends the buyer to its own checkout page can manage without them for now.
Show fix
Create an Ed25519 key pair. Add the public key to a "keys" list at the top level of your UCP profile, as in the example, and keep the private key on your server. Replace the key once a year, giving each new key its own "kid".
{
"keys": [
{
"kty": "OKP",
"crv": "Ed25519",
"x": "<base64url-encoded-public-key>",
"kid": "key-2026-04",
"alg": "EdDSA"
}
],
"ucp": { ... }
}
