With https://github.com/tfpauly/privacy-proxy/pull/220, we have a 8-bit key ID that the issuer (but not attester) sees. We can consider moving this to be one bit only, to allow rotation while not having to worry about key targeting/consistency checks.
From https://github.com/tfpauly/privacy-proxy/issues/222