Expand description
Passive application-token contracts, independent of runtime and storage.
Decoding these values does not verify a proof or establish authority. Hosts must obtain expected audience, caller, time and issuer policy independently. These tokens are not IC ingress delegations.
Structs§
- Audience
Id - Exact network-qualified audience, with existing protocol field labels. The host owns the meaning and trusted source of both identifiers; this type contains no fleet topology, membership, derivation or installation policy.
- Auth
Request Metadata - Auth
Role - Canonical role label, checked at construction and deserialization. The grammar matches the existing signed protocol; it adds no case folding, normalization, built-in roles or implicit role authority.
- Canonical
Id - Exactly 32 identity bytes, represented as lowercase hexadecimal on the wire. No sentinel bytes are reserved by this protocol. A host must compare this value with its protected identity, never enroll trust from a client claim.
- Chain
KeyBatch Header V1 - Chain
KeyBatch Witness V1 - Chain
KeyDelegation Cert V1 - Chain
KeyKey Id - Chain
KeyRoot Signature V1 - Delegated
Role Grant - Delegated
Token - Delegated
Token Claims - Delegated
Token GetRequest - Delegated
Token Prepare Request - Delegated
Token Prepare Response - Delegation
Cert - Delegation
Proof - IcCanister
Signature Proof V1 - IcChain
KeyBatch Signature Proof V1 - Principal
- Generic ID on Internet Computer.
Enums§
- Chain
KeyAlgorithm - Chain
KeyBatch Witness Step V1 - Delegation
Audience - Identifier
Error - Invalid protocol identifier syntax. This says nothing about authorization.
- Issuer
Proof - Issuer
Proof Algorithm - Issuer
Proof Binding - Root
Proof