sessionKey property

String? sessionKey
final

A did:key VID the producer asks the consumer to bind to the session this authenticate document creates. The producer MUST hold the corresponding private key and SHOULD keep it non-extractable (for example, a WebCrypto non-extractable key). Once bound, the consumer MUST accept a framework proof made by this key, with proofPurpose: authentication, as the subject — for this session only, bounded by the session's expiresAt and acr, and never where a specification requires an assertionMethod attestation (SPEC.md §7.2 item 10; see Security & Privacy). The consumer MAY refuse a key type it does not support with auth/authenticate:sessionKeyUnsupported. It sits inside payload, so the subject's own authentication proof on this document covers it — a party cannot bind a session key without signing for it.

Implementation

final String? sessionKey;