//! Pure application-token encoding and optional signature/token/session machinery.
//!
//! Hashing untrusted material does not authenticate it. Applications must not
//! admit tokens by hashing them or checking just one signature. Use the optional
//! token verifier with protected host inputs. The optional session engine uses
//! one explicit host transaction for admission and replay consumption.