The combination that fails late
Building a pack reads your own records back, so it needsanchor:read. Nothing surfaces
the gap until then, because anchoring never touches the read routes.
Mint keys for a runtime with all three:
Why a runtime needs producer:enroll
Both SDKs enrol the signing key before the first anchor, so the agent appears on your fleet with no registration step written by you. The enrolment happens in the runtime, which is where the signing key is, so the runtime’s credential must be allowed to do it.What the signing key does, and what it never leaves
The API key and the signing key are different things and the split is the security model.
Sanning cannot produce a record that verifies as yours, because it has never held the key
that signs one.