{
  "note": "Cross-language golden vectors for Canonical Authority Representation v1. Static and hand-authored from canonical-authority-representation-v1.md, not emitted from an implementation: these vectors govern formats that do not exist yet, so there is nothing to emit them from. contracts/authority/verify-car-v1.mjs implements CAR v1 from the specification alone and must reproduce every accepted vector and refuse every rejected one. Future .NET, TypeScript, Python, Java and Go implementations must do the same.",
  "specification": "contracts/authority/canonical-authority-representation-v1.md",
  "reference_family": {
    "identifier": "verid.car.reference.v1",
    "note": "A specification fixture, not a live signing family. Nothing in runtime code signs it; it exists so that every CAR v1 rule has a worked example with a digest. A real format copies its representation, never its identifier.",
    "schema": {
      "action": {"kind": "string", "case": "lower"},
      "agent_id": {"kind": "external_id"},
      "amount": {"kind": "decimal"},
      "currency": {"kind": "string", "case": "upper"},
      "data_classes": {"kind": "set", "optional": true},
      "expires_at": {"kind": "timestamp"},
      "grant_id": {"kind": "guid"},
      "record_count": {"kind": "integer"},
      "region": {"kind": "string", "case": "upper"},
      "single_use": {"kind": "boolean"},
      "tenant_id": {"kind": "guid"}
    }
  },
  "objects": [
    {
      "name": "reference",
      "note": "Every rule at once. Inputs are raw: untrimmed, mixed case, a duplicate set member, and an upper-case GUID. An implementation must trim, case per field, deduplicate, sort by code point, and lower-case the GUID. Field order in the output is ascending Unicode code point of the field name, which is derivable and therefore not transcribed from a table.",
      "input": {
        "action": " Transfer ",
        "agent_id": " Agent-7 ",
        "amount": " 13800.00 ",
        "currency": " usd ",
        "data_classes": ["pii", "financial", "pii"],
        "expires_at": "2026-07-27T10:15:30.000Z",
        "grant_id": "3F2A1B4C-5D6E-7F80-9A1B-2C3D4E5F6071",
        "record_count": 42,
        "region": " eu ",
        "single_use": true,
        "tenant_id": "11111111-1111-1111-1111-111111111111"
      },
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "digest": "78C5A5E3840376A70D75BFA172E4E7F830F385DD43F6E4A5508FEC08D2B78AC3",
      "verifies": true
    },
    {
      "name": "optional-field-absent",
      "note": "data_classes omitted entirely: unconstrained, not stated. The line does not appear. Compare the digest with optional-field-empty below - absent and empty are different objects and must never canonicalize alike.",
      "input": {
        "action": "transfer",
        "agent_id": "Agent-7",
        "amount": "13800.00",
        "currency": "USD",
        "expires_at": "2026-07-27T10:15:30.000Z",
        "grant_id": "3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071",
        "record_count": 42,
        "region": "EU",
        "single_use": true,
        "tenant_id": "11111111-1111-1111-1111-111111111111"
      },
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "digest": "2632D652C749EDEACA6BEAA3E91C70EFC7397D91F58A1542A2E7A769057FC05C",
      "verifies": true
    },
    {
      "name": "optional-field-empty",
      "note": "data_classes present and empty: stated, and it authorizes nothing. The line appears with an empty value. An implementation that coerces this to absent silently widens a constraint somebody locked deliberately.",
      "input": {
        "action": "transfer",
        "agent_id": "Agent-7",
        "amount": "13800.00",
        "currency": "USD",
        "data_classes": [],
        "expires_at": "2026-07-27T10:15:30.000Z",
        "grant_id": "3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071",
        "record_count": 42,
        "region": "EU",
        "single_use": true,
        "tenant_id": "11111111-1111-1111-1111-111111111111"
      },
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "digest": "B648342DFEEBEAC11431A06B95EBB730AE668F243A761C9CF442A51F2219EFE3",
      "verifies": true
    }
  ],
  "scalars": {
    "decimal": [
      {"input": "100", "status": "accepted", "canonical": "100"},
      {"input": "100.0", "status": "accepted", "canonical": "100.0", "note": "Distinct from 100. Scale is significant."},
      {"input": "100.00", "status": "accepted", "canonical": "100.00", "note": "Distinct from both 100 and 100.0."},
      {"input": "0", "status": "accepted", "canonical": "0"},
      {"input": "0.01", "status": "accepted", "canonical": "0.01"},
      {"input": "123456789.123456", "status": "accepted", "canonical": "123456789.123456", "note": "Nine integer digits, six fractional. At the fractional bound."},
      {"input": " 100.00 ", "status": "accepted", "canonical": "100.00", "note": "The only normalization a decimal receives is trimming."},
      {"input": "-100.00", "status": "accepted", "canonical": "-100.00"},
      {"input": "-0", "status": "rejected", "reason": "Negative zero is not a quantity, and 0 and -0 would be two spellings of one value."},
      {"input": "-0.00", "status": "rejected", "reason": "Same reason as -0."},
      {"input": "00.50", "status": "rejected", "reason": "Leading zeros are prohibited except the single 0 before a decimal point."},
      {"input": "007", "status": "rejected", "reason": "Leading zeros."},
      {"input": "100.", "status": "rejected", "reason": "Trailing decimal point."},
      {"input": ".5", "status": "rejected", "reason": "Integer part is required."},
      {"input": "1e2", "status": "rejected", "reason": "Exponent notation."},
      {"input": "1E2", "status": "rejected", "reason": "Exponent notation."},
      {"input": "+100", "status": "rejected", "reason": "Leading plus."},
      {"input": "1,000.00", "status": "rejected", "reason": "Group separators."},
      {"input": "100.0000001", "status": "rejected", "reason": "Seven fractional digits exceeds the bound of six."},
      {"input": "1234567890123456789", "status": "rejected", "reason": "Nineteen integer digits exceeds the bound of eighteen."},
      {"input": "", "status": "rejected", "reason": "Absence is expressed by omitting the field, never by an empty decimal."},
      {"input": "abc", "status": "rejected", "reason": "Not a decimal."},
      {"input": "1 00", "status": "rejected", "reason": "Interior whitespace."}
    ],
    "timestamp": [
      {"input": "2026-07-27T10:15:30.000Z", "status": "accepted", "canonical": "2026-07-27T10:15:30.000Z", "note": "The only accepted shape."},
      {"input": "2026-12-31T23:59:59.999Z", "status": "accepted", "canonical": "2026-12-31T23:59:59.999Z", "note": "Year boundary."},
      {"input": "1970-01-01T00:00:00.000Z", "status": "accepted", "canonical": "1970-01-01T00:00:00.000Z", "note": "Epoch."},
      {"input": "2024-02-29T00:00:00.000Z", "status": "accepted", "canonical": "2024-02-29T00:00:00.000Z", "note": "2024 is a leap year."},
      {"input": "2026-07-27T10:15:30.000z", "status": "rejected", "reason": "Lower-case z is a second spelling of one instant."},
      {"input": "2026-07-27T10:15:30Z", "status": "rejected", "reason": "No fractional part. Exactly three digits are required."},
      {"input": "2026-07-27T10:15:30.0Z", "status": "rejected", "reason": "One fractional digit."},
      {"input": "2026-07-27T10:15:30.00Z", "status": "rejected", "reason": "Two fractional digits."},
      {"input": "2026-07-27T10:15:30.0000Z", "status": "rejected", "reason": "Four fractional digits."},
      {"input": "2026-07-27T10:15:30.000000Z", "status": "rejected", "reason": "Six fractional digits: the microsecond form Python and Go emit by default."},
      {"input": "2026-07-27T10:15:30.0000000Z", "status": "rejected", "reason": "Seven fractional digits: the .NET round-trip form two registered legacy formats use."},
      {"input": "2026-07-27T10:15:30.000+00:00", "status": "rejected", "reason": "An offset, even though it denotes UTC. Offsets are rejected, never normalized."},
      {"input": "2026-07-27T11:15:30.000+01:00", "status": "rejected", "reason": "Positive offset. Conversion to UTC is the caller's job, done once, before constructing the object."},
      {"input": "2026-07-27T09:15:30.000-01:00", "status": "rejected", "reason": "Negative offset."},
      {"input": "2026-07-27 10:15:30.000Z", "status": "rejected", "reason": "Space instead of T."},
      {"input": "2026-02-29T00:00:00.000Z", "status": "rejected", "reason": "2026 is not a leap year. Not a real instant."},
      {"input": "2026-07-27T23:59:60.000Z", "status": "rejected", "reason": "Leap second. No conforming format represents one."},
      {"input": "2026-13-01T00:00:00.000Z", "status": "rejected", "reason": "Month 13."},
      {"input": "2026-07-27T24:00:00.000Z", "status": "rejected", "reason": "Hour 24."},
      {"input": "1753308930", "status": "rejected", "reason": "Unix seconds. Second resolution cannot express the expiry of a 60-second grant precisely enough to reason about."},
      {"input": "", "status": "rejected", "reason": "Not a timestamp."}
    ],
    "string": [
      {"input": " Transfer ", "case": "lower", "status": "accepted", "canonical": "transfer"},
      {"input": " usd ", "case": "upper", "status": "accepted", "canonical": "USD"},
      {"input": "Invoice", "case": "lower", "status": "accepted", "canonical": "invoice", "note": "Invariant culture. A tr-TR locale lowercases I to the dotless i and would produce a value matching nothing written anywhere else."},
      {"input": " Agent-7 ", "case": "none", "status": "accepted", "canonical": "Agent-7", "note": "An identifier issued outside 2AYE. Trimmed only; case is significant, because lowercasing it would make two distinct principals compare equal."},
      {"input": "two  spaces", "case": "none", "status": "accepted", "canonical": "two  spaces", "note": "Interior whitespace is preserved. Only the ends are trimmed."},
      {"input": "café", "case": "none", "status": "accepted", "canonical": "café", "note": "Decomposed e-acute is preserved. No Unicode normalization is applied, so this is a different identifier from the composed form below."},
      {"input": "café", "case": "none", "status": "accepted", "canonical": "café", "note": "Composed e-acute. Distinct from the decomposed form above, deliberately: folding them would make two distinct counterparties compare equal."},
      {"input": "line\nbreak", "case": "none", "status": "rejected", "reason": "A control character in a value could forge an entire line in a line-oriented format. Refused rather than escaped, because an escaping layer is a thing to get wrong."},
      {"input": "tab\there", "case": "none", "status": "rejected", "reason": "Control character."},
      {"input": "null\u0000byte", "case": "none", "status": "rejected", "reason": "Control character."},
      {"input": "unit\u001fseparator", "case": "none", "status": "rejected", "reason": "Control character, and the separator a display statement uses between a label and its value."}
    ],
    "integer": [
      {"input": 42, "status": "accepted", "canonical": "42"},
      {"input": 0, "status": "accepted", "canonical": "0"},
      {"input": -7, "status": "accepted", "canonical": "-7"},
      {"input": "042", "status": "rejected", "reason": "Leading zeros."},
      {"input": "+42", "status": "rejected", "reason": "Leading plus."},
      {"input": "1,000", "status": "rejected", "reason": "Group separators."},
      {"input": "4e2", "status": "rejected", "reason": "Exponent notation."},
      {"input": "42.0", "status": "rejected", "reason": "An integer is not a decimal."}
    ],
    "boolean": [
      {"input": true, "status": "accepted", "canonical": "true"},
      {"input": false, "status": "accepted", "canonical": "false"},
      {"input": "True", "status": "rejected", "reason": "Lower case only."},
      {"input": 1, "status": "rejected", "reason": "A boolean is not an integer."},
      {"input": "yes", "status": "rejected", "reason": "Not a boolean token."}
    ],
    "set": [
      {"input": ["pii", "financial"], "status": "accepted", "canonical": "financial,pii", "note": "Sorted by code point. Order is not semantically meaningful, so it must not change the digest."},
      {"input": ["financial", "pii"], "status": "accepted", "canonical": "financial,pii", "note": "The same set in the other order canonicalizes identically. A caller that serialized its members differently must not find its own grant unredeemable."},
      {"input": ["pii", "financial", "pii"], "status": "accepted", "canonical": "financial,pii", "note": "Deduplicated before canonicalization."},
      {"input": ["Zebra", "apple", "Banana"], "status": "accepted", "canonical": "Banana,Zebra,apple", "note": "Ordinal, which is byte order: upper case sorts before lower case. A culture-aware sort would place apple first in some locales and not others, so the machine that signed would not be the one that verified."},
      {"input": [], "status": "accepted", "canonical": "", "note": "Empty, and distinct from absent."},
      {"input": [" pii ", "financial"], "status": "accepted", "canonical": "financial,pii", "note": "Members are trimmed before sorting, not after: trimming after would sort on the untrimmed value."},
      {"input": ["pii,financial"], "status": "rejected", "reason": "A member containing the separator. Refused rather than escaped, per CAR-19."}
    ],
    "guid": [
      {"input": "3F2A1B4C-5D6E-7F80-9A1B-2C3D4E5F6071", "status": "accepted", "canonical": "3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071", "note": "Lower-cased."},
      {"input": "3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071", "status": "accepted", "canonical": "3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071"},
      {"input": "{3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071}", "status": "rejected", "reason": "Braces."},
      {"input": "3f2a1b4c5d6e7f809a1b2c3d4e5f6071", "status": "rejected", "reason": "Unhyphenated."},
      {"input": "urn:uuid:3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071", "status": "rejected", "reason": "URN prefix."},
      {"input": "not-a-guid", "status": "rejected", "reason": "Not a GUID."}
    ],
    "digest": [
      {"input": "78c5a5e3840376a70d75bfa172e4e7f830f385dd43f6e4a5508fec08d2b78ac3", "status": "accepted", "canonical": "78C5A5E3840376A70D75BFA172E4E7F830F385DD43F6E4A5508FEC08D2B78AC3", "note": "Uppercased with no per-field exception. Dart and Go return lower case, .NET returns upper; the specification says which, so one of them converts."},
      {"input": " 78C5A5E3840376A70D75BFA172E4E7F830F385DD43F6E4A5508FEC08D2B78AC3 ", "status": "accepted", "canonical": "78C5A5E3840376A70D75BFA172E4E7F830F385DD43F6E4A5508FEC08D2B78AC3"},
      {"input": "sha256:78C5A5E3840376A70D75BFA172E4E7F830F385DD43F6E4A5508FEC08D2B78AC3", "status": "rejected", "reason": "Prefixed."},
      {"input": "78:C5:A5:E3", "status": "rejected", "reason": "Separators."}
    ]
  },
  "negative": [
    {
      "name": "field-reordered",
      "category": "field order",
      "canonical": "statement=verid.car.reference.v1\nagent_id=Agent-7\naction=transfer\namount=13800.00\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "action and agent_id swapped. Ascending code point puts action first, because c precedes g."
    },
    {
      "name": "decimal-scale-altered",
      "category": "decimal",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.0\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "13800.00 became 13800.0. The same number, a different authorization. This is what a round trip through a float produces."
    },
    {
      "name": "decimal-trailing-zeros-stripped",
      "category": "decimal",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "What JSON.stringify(13800.00) produces."
    },
    {
      "name": "timestamp-reformatted-dotnet",
      "category": "timestamp",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.0000000+00:00\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "The .NET round-trip form. The same instant, different bytes."
    },
    {
      "name": "timestamp-offset-not-normalized",
      "category": "timestamp",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T11:15:30.000+01:00\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "The same instant expressed with an offset, which CAR v1 rejects rather than converting."
    },
    {
      "name": "unicode-recomposed",
      "category": "unicode",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent́-7\namount=13800.00\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "A combining mark added to the agent identifier. A different identifier, and no normalization will fold it into the original."
    },
    {
      "name": "set-reordered",
      "category": "collection order",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=pii,financial\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "Members present but unsorted. The set is the same; the canonical form is not, so these bytes were never produced by a conforming implementation."
    },
    {
      "name": "digest-case-changed",
      "category": "hash casing",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=usd\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "A field whose casing is material left un-cased. currency is specified upper case, so usd is not its canonical form."
    },
    {
      "name": "guid-case-changed",
      "category": "identifier",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3F2A1B4C-5D6E-7F80-9A1B-2C3D4E5F6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "An upper-case GUID. CAR-20 requires lower case."
    },
    {
      "name": "external-id-case-folded",
      "category": "identifier",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=agent-7\namount=13800.00\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "An externally issued identifier lowercased. Agent-7 and agent-7 may be two different principals upstream, which is why case is preserved."
    },
    {
      "name": "parameter-changed",
      "category": "parameter",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13900.00\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "The amount changed. The case the whole mechanism exists for."
    },
    {
      "name": "extra-newline",
      "category": "framing",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n\n",
      "note": "One extra byte at the end."
    },
    {
      "name": "missing-trailing-newline",
      "category": "framing",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111",
      "note": "What a join produces instead of a sequence of terminated lines. One byte short."
    },
    {
      "name": "crlf-line-endings",
      "category": "framing",
      "canonical": "statement=verid.car.reference.v1\r\naction=transfer\r\nagent_id=Agent-7\r\namount=13800.00\r\ncurrency=USD\r\ndata_classes=financial,pii\r\nexpires_at=2026-07-27T10:15:30.000Z\r\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\r\nrecord_count=42\r\nregion=EU\r\nsingle_use=true\r\ntenant_id=11111111-1111-1111-1111-111111111111\r\n",
      "note": "What a Windows text writer produces. Twelve extra bytes."
    },
    {
      "name": "unknown-field-appended",
      "category": "unknown field",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nnote=approved+by+ops\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "A field not in the schema, inserted in correct code-point position so that an implementation sorting its own output would not notice. A verifier that checks the fields it knows and ignores the rest accepts this, and an appended line is a free-text channel into a closed representation."
    },
    {
      "name": "null-instead-of-omitted",
      "category": "absent semantics",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=null\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "null is prohibited in CAR v1. It is a third spelling with no distinct meaning, and the registry already records two other conventions."
    },
    {
      "name": "none-sentinel-instead-of-omitted",
      "category": "absent semantics",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=none\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "The sentinel the legacy statement families use. CAR v1 omits the line instead, so that absent and the string none cannot be confused."
    },
    {
      "name": "absent-coerced-to-empty",
      "category": "absent semantics",
      "canonical": "statement=verid.car.reference.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "Valid bytes for a DIFFERENT object. These are the canonical bytes of optional-field-empty, and they must not verify against a signature made over optional-field-absent. Absent is unconstrained; empty authorizes nothing. This is the pair most likely to be collapsed by an implementation that treats a missing collection as an empty one."
    },
    {
      "name": "wrong-domain-separator",
      "category": "domain separation",
      "canonical": "statement=verid.car.other.v1\naction=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "Every field identical, a different format identifier. The property the separator exists for: a signature collected for one format can never present as another."
    },
    {
      "name": "domain-separator-removed",
      "category": "domain separation",
      "canonical": "action=transfer\nagent_id=Agent-7\namount=13800.00\ncurrency=USD\ndata_classes=financial,pii\nexpires_at=2026-07-27T10:15:30.000Z\ngrant_id=3f2a1b4c-5d6e-7f80-9a1b-2c3d4e5f6071\nrecord_count=42\nregion=EU\nsingle_use=true\ntenant_id=11111111-1111-1111-1111-111111111111\n",
      "note": "The shape the deprecated legacy approval statement has, and the reason it is deprecated: bytes with no domain separator are the cheapest to collide with another format."
    }
  ]
}
