V1 · BINARY CLAIMS
What the envelope proves
JSON is transport only. ML-DSA directly signs a fixed BTX-DOCUMENT-SIGNATURE-V1 binary message containing a SHA-512 digest and length-delimited claims. The default two-leaf P2MR proof carries one sibling hash; any content, claim, address, key, proof, or signature mutation fails closed. This is not BIP-322 or btx-util verifyupdatesig.