Skip to main content

Crate ic_auth_protocol_types

Crate ic_auth_protocol_types 

Source
Expand description

Passive application-token contracts, independent of runtime and storage.

Decoding these values does not verify a proof or establish authority. Hosts must obtain expected audience, caller, time and issuer policy independently. These tokens are not IC ingress delegations.

Structs§

AudienceId
Exact network-qualified audience, with existing protocol field labels. The host owns the meaning and trusted source of both identifiers; this type contains no fleet topology, membership, derivation or installation policy.
AuthRequestMetadata
AuthRole
Canonical role label, checked at construction and deserialization. The grammar matches the existing signed protocol; it adds no case folding, normalization, built-in roles or implicit role authority.
CanonicalId
Exactly 32 identity bytes, represented as lowercase hexadecimal on the wire. No sentinel bytes are reserved by this protocol. A host must compare this value with its protected identity, never enroll trust from a client claim.
ChainKeyBatchHeaderV1
ChainKeyBatchWitnessV1
ChainKeyDelegationCertV1
ChainKeyKeyId
ChainKeyRootSignatureV1
DelegatedRoleGrant
DelegatedToken
DelegatedTokenClaims
DelegatedTokenGetRequest
DelegatedTokenPrepareRequest
DelegatedTokenPrepareResponse
DelegationCert
DelegationProof
IcCanisterSignatureProofV1
IcChainKeyBatchSignatureProofV1
Principal
Generic ID on Internet Computer.

Enums§

ChainKeyAlgorithm
ChainKeyBatchWitnessStepV1
DelegationAudience
IdentifierError
Invalid protocol identifier syntax. This says nothing about authorization.
IssuerProof
IssuerProofAlgorithm
IssuerProofBinding
RootProof