bellaPrivateKeyFromEnvValue function

Uint8List? bellaPrivateKeyFromEnvValue(
  1. String? value
)

Parses the value of BELLA_BAXTER_PRIVATE_KEY into PKCS#8 DER bytes.

Accepts a PKCS#8 PEM (what bella sdk run injects) or bare base64 PKCS#8 DER: the -----…----- armour and all whitespace (including CRLF) are stripped before decoding, the same rule the JS, Java and .NET SDKs apply.

Returns null when value is null or blank — no device key is configured, and the client generates an ephemeral key as it always has.

Throws a StateError naming BELLA_BAXTER_PRIVATE_KEY when a key IS present but cannot be read as a P-256 private key. It never falls back to an ephemeral key in that case (#989): silently presenting a key nobody registered makes every read fail later with a 403 whose cause is invisible from inside the application.

Implementation

Uint8List? bellaPrivateKeyFromEnvValue(String? value) {
  if (value == null || value.trim().isEmpty) return null;

  final body = value.replaceAll(RegExp(r'-----[A-Z ]+-----|\s'), '');
  try {
    final der = base64Decode(body);
    // Parse it now, so a bad key fails here rather than on the first request.
    e2eeKeyPairFromPkcs8(der);
    return der;
  } catch (_) {
    throw StateError(
      'BELLA_BAXTER_PRIVATE_KEY is set but is not a readable PKCS#8 P-256 '
      'private key (PEM or base64 DER expected). Refusing to continue with a '
      'throwaway key instead of your device key.\n'
      '  Unset it, or re-run: bella auth setup',
    );
  }
}