law: the plc did is a HANDLE, not the root โ lose it and the root re-attests a new one. rotation keys held by the bzDiD ceremony; the escrow fixtures already speak this field.
โก the nostr address โ npub
key schemesecp256k1 pair, bech32 (npub/nsec)
derivation rolebzDiD root derives the pair via registered context
npub (public)npub1<bech32-of-derived-pub>
nsec (secret)never rendered, never on-chain, client-held only
NIP-05name@beehive.nature
DM payloadpointers only (?room ?order ?piece) โ never content
law: the npub is an ADDRESS of the root, not the root itself; relays carry ciphertext (NIP-44 class), and the derivation context is registered so any client can re-derive from the ceremony. secp256k1 vendoring docks with the engine (bzdid-key carries ed25519 today).