Skip to main content

Module keys

Module keys 

Source
Expand description

The OAuth confidential-client signing key, and the documents derived from it.

A production atproto OAuth client is a confidential client: it authenticates to the PDS with private_key_jwt, signing a client assertion with a long-lived ES256 key. That key must

  • survive restarts (it anchors client_id, so regenerating it invalidates in-flight authorizations),
  • be published in public form at jwks_uri so the PDS can verify assertions,
  • and not sit on disk in the clear whenever a codec key is configured.

So it is persisted as a JWK, AEAD-encrypted with super::crypto. The JWK format is deliberately the same one the Node sidecar writes, so a rollback to the sidecar can still read a key this module created, and vice versa.

That third requirement is conditional, and the condition is load-bearing: super::crypto::Codec::Null is a pass-through, so a deployment with no key configured writes the private JWK as plaintext. The sidecar refuses to boot in production without a key; the equivalent guard for this path belongs in config validation at cutover, and until then Codec::Null is a dev-only arrangement rather than an enforced one.

The thumbprint is RFC 7638 and is computed over the PUBLIC members only (crv, kty, x, y) in lexicographic order — never over the raw JWK text, and never including d.

Structs§

SigningKey
The confidential client’s long-lived ES256 signing key.

Functions§

load_or_create
Load the signing key from path, generating and persisting one if absent.