{"enabled":false,"allowed_issuers":[],"allowed_issuer_count":0,"accepted_algorithms":["EdDSA","ES256","RS256"],"mandate_header":"Authorization: AP2 <compact-jws>","jwks_path":"/.well-known/jwks.json","notes":["AP2 mandates authorize spend; settlement still requires a payment rail receipt.","RelayZero accepts EdDSA/Ed25519, ES256/P-256, and RS256 JWS mandates.","Update AP2_ALLOWED_ISSUERS in the deployment environment to change trusted issuers."]}