Payload class

The subject presents a previously-issued challenge along with the framework proof that binds the document to their VID. The proof IS the authentication. 0.2 adds the optional sessionKey member, a did:key VID the consumer binds to the created session so later documents in that session can be signed with it instead of the subject's own key.

Constructors

Payload({required String challenge, required String sessionId, List<String>? scope, String? sessionKey, Ext? ext})
const
Payload.fromJson(Map<String, dynamic> json)
Read this payload from a decoded JSON object.
factory

Properties

challenge → String
The exact challenge value returned by a prior auth/challenge call. Consumers MUST reject mismatch, expired, or re-used challenges.
final
ext → Ext?
Ecosystem-defined extension members per SPEC.md §4.5.1.
final
hashCode → int
The hash code for this object.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
scope → List<String>?
Optional capability tags the subject is requesting on the issued tokens. The consumer's authorization layer decides which are granted; the issued TokenBundle's scope MAY be a subset.
final
sessionId → String
The sessionId returned alongside the challenge. Consumers use it to look up the server-side challenge binding.
final
sessionKey → String?
A did:key VID the producer asks the consumer to bind to the session this authenticate document creates. The producer MUST hold the corresponding private key and SHOULD keep it non-extractable (for example, a WebCrypto non-extractable key). Once bound, the consumer MUST accept a framework proof made by this key, with proofPurpose: authentication, as the subject — for this session only, bounded by the session's expiresAt and acr, and never where a specification requires an assertionMethod attestation (SPEC.md §7.2 item 10; see Security & Privacy). The consumer MAY refuse a key type it does not support with auth/authenticate:sessionKeyUnsupported. It sits inside payload, so the subject's own authentication proof on this document covers it — a party cannot bind a session key without signing for it.
final

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toJson() → Map<String, dynamic>
Serialize to a JSON-encodable map, omitting absent members.
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited