Expand description
Pure application-token encoding and optional signature/token/session machinery.
Hashing untrusted material does not authenticate it. Applications must not admit tokens by hashing them or checking just one signature. Use the optional token verifier with protected host inputs. The optional session engine uses one explicit host transaction for admission and replay consumption.
Modulesยง
- canonical
- Canonical signed bytes for the existing Canic application-token protocol. Domains and tags are protocol identities, not package branding. This module does not verify signatures, authority, validity or caller binding.