sessionKey property
A did:key VID the producer asks the consumer to bind to the session this
authenticate document creates. The producer MUST hold the corresponding private key
and SHOULD keep it non-extractable (for example, a WebCrypto non-extractable key).
Once bound, the consumer MUST accept a framework proof made by this key, with
proofPurpose: authentication, as the subject — for this session only, bounded by
the session's expiresAt and acr, and never where a specification requires an
assertionMethod attestation (SPEC.md §7.2 item 10; see Security & Privacy). The
consumer MAY refuse a key type it does not support with
auth/authenticate:sessionKeyUnsupported. It sits inside payload, so the
subject's own authentication proof on this document covers it — a party cannot
bind a session key without signing for it.
Implementation
final String? sessionKey;