Say what you will capture.
A capture key is the write half of epcis.dev: capture, query, and the MCP door open with it, and capturedBy — the warrantor the gateway stamps on every event — is the account it names. The calculators — /translate, /validate, /hash — answer on this origin without one.
Two things here: the list that provisions keys, and the interface you can run right now — on this origin, and on your own bench:
Run the interface while you wait.
No key stands in front of the calculators: POST /translate, /validate and /hash answer on this origin, and npx epcis.dev runs the full gateway — capture laws, validation, event hash, error bodies — on your own bench. Audit the rest without asking anyone: the pinned digests on the conformance page — re-hash GS1's artefacts yourself — and the dated ledger.
Validated. Stamped. Hashed. Appended. Keys are provisioned from this list, in order — one email when yours is ready, and only that one.