A requirement the spck.dev suite checks on UCP servers. The quoted text is the normative requirement; the citation links to the exact line of the pinned spec source it was taken from.
2026-04-08:
Public keys are published in the signing_keys array of the party's UCP profile at /.well-known/ucp.
2026-08-25:
Public keys are published in the signer's UCP profile; the publishing contract and the verifier's key-list lookup rule (which key list to read per resolution mechanism) are specified in Profile Structure and Key Discovery (overview/index.md), rather than a single self-contained signing_keys[] statement.
A deviation on a MUST fails the run and shows the requirement next to the actual response. Checks the suite cannot validate soundly are reported inconclusive or not-tested — never a silent pass. The full verdict semantics are on the grading rubric.
The hosted check covers the read-only surface; the CLI and GitHub Action run the full suite, including this check when your store declares the capability it belongs to.