KeyPackage class

The KEM recipient key(s) one APKAM keypair advertises so that other clients of the same atSign can seal secrets to it.

The recipient unit is the APKAM keypair, not a client process. Enrollment cardinality is 1:1:1 — one enrollment has exactly one APKAM keypair and therefore exactly one key package — so a key package is identified by its enrollmentId (with apkamId carried alongside for reference).

Key packages are enrollment-internal — they live in the enrollment record, conveyed there by riding enroll:request as opaque EnrollParams.metadata at enrollment time, and are discovered only via the gated enroll:listns verb (see EnrollmentDirectory). They are not published as ordinary at-keys. Per the ratified design the advertised key package is wrapped in an APKAM-signed envelope by its generating enrollment and verified against that enrollment's _apsk, so the encapsulation target is authenticated rather than merely server-vouched. A package that does not verify, or that is signed by an enrollment other than the one advertising it, is not sealed to.

toJson / fromPayload are the inner payload — the value stored at metadata.keyPackage is that payload wrapped in the signed envelope. enrollmentId and apkamId are carried by the enclosing verb structure, not duplicated in the payload.

Annotations
  • @experimental

Constructors

KeyPackage({required String enrollmentId, String? apkamId, required DateTime createdAt, required List<PackageKey> keys, List<String>? suites, int v = currentVersion})
suites defaults to what keys can open — see the field's own doc for why that is not the same as what this build supports.
factory

Properties

apkamId → String?
The APKAM keypair this key package belongs to, as reported by the verb (the enrollment's apkamPubKey). Null on a key package this client builds for its own enrollment — identity is carried by the enclosing enrollment.
final
createdAt → DateTime
final
enrollmentId → String
The enrollment this key package belongs to.
final
hashCode → int
The hash code for this object.
no setterinherited
keys → List<PackageKey>
final
kpid → String?
The addressing token for this key package: the kid of its active enc-use key (the KEM public key a sender seals to). Null if the package advertises no active key for SecretSharingAlgos.keyAlgos.
no setter
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
suites → List<String>
The sealing suites this package's holder can open, strongest first.
final
v → int
final

Methods

bestKeyFor(List<String> supportedAlgos, {String use = SecretSharingAlgos.useEnc}) → PackageKey?
The first active key in supportedAlgos order (strongest first) that this key package advertises for use. Returns null if the package and supportedAlgos have no algorithm in common, or if every key they do have in common is retired.
bestSuiteFor(List<String> senderSuites) → String?
The first suite in senderSuites order (strongest first) that this package's holder can also open, or null if there is no overlap.
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toJson() → Map<String, Object?>
The value stored at metadata.keyPackage — the payload only. enrollmentId / apkamId are carried by the enclosing verb structure (the enrollment and its APKAM-keypair entry), not repeated here.
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Static Methods

fromPayload(Object? payload, {required String enrollmentId, String? apkamId}) → KeyPackage
Parses a stored key-package payload (from metadata.keyPackage), injecting the enrollmentId / apkamId the enclosing verb structure carried. Skips malformed entries in keys rather than throwing — a payload written by a newer client may carry key entries (or extra fields) this version does not understand.
payloadFor({required DateTime createdAt, required List<PackageKey> keys, List<String>? suites, int v = currentVersion}) → Map<String, Object?>
The same payload as toJson, for a package whose enrollment does not exist yet.

Constants

currentVersion → const int