Of course the signing key’s ID is base64 of a truncated sha256 hash so that bit ends up being base64(encrypt(base64(json(base64(truncated-hash))))) :floofWoozy: