Payload class
The subject presents a previously-issued challenge along with the framework proof
that binds the document to a VID. The proof IS the authentication. 0.3 adds an
optional proxied form: principal names a party the signer authenticates as,
distinct from issuer (the signer, e.g. a VTA acting on the principal's behalf),
together with delegationEvidence establishing the entitlement. Absent
principal, or principal equal to issuer, is the ordinary
auth/authenticate/0.2 form unchanged. 0.3 also carries forward the optional
sessionKey member from 0.2.
Constructors
Properties
- challenge → String
-
The exact challenge value returned by a prior auth/challenge call. Consumers MUST
reject mismatch, expired, or re-used challenges.
final
- delegationEvidence → PayloadDelegationEvidence?
-
REQUIRED whenever
principalis present and differs fromissuer; MUST be omitted otherwise. Describes the evidence that entitlesissuerto authenticate asprincipal. The framework does not prescribe its shape — see Authorization — but the consumer's policy MUST verify it independently rather than takeissuer's claim of entitlement at face value.final - ext → Ext?
-
Ecosystem-defined extension members per SPEC.md §4.5.1.
final
- hashCode → int
-
The hash code for this object.
no setterinherited
- principal → String?
-
The VID being authenticated as, when it differs from the signer of this document.
Present and unequal to
issuermarks a proxied authenticate:issueris a delegate (typically the principal's VTA) presenting its own proof, andpayload.delegationEvidenceMUST also be present, describing what entitlesissuerto act forprincipal. Omitted, or equal toissuer, is the ordinary case: the signer authenticates as itself, exactly as auth/authenticate/0.2. See Authorization and Security & Privacy.final - runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
-
scope
→ List<
String> ? -
Optional capability tags being requested on the issued tokens. The consumer's
authorization layer decides which are granted; the issued TokenBundle's
scopeMAY be a subset.final - sessionId → String
-
The sessionId returned alongside the challenge. Consumers use it to look up the
server-side challenge binding.
final
- sessionKey → String?
-
A did:key VID the producer asks the consumer to bind to the session this
authenticate document creates. The producer MUST hold the corresponding private key
and SHOULD keep it non-extractable (for example, a WebCrypto non-extractable key).
Once bound, the consumer MUST accept a framework
proofmade by this key, withproofPurpose: authentication, as the session'ssubject— for this session only, bounded by the session'sexpiresAtandacr, and never where a specification requires anassertionMethodattestation (SPEC.md §7.2 item 10; see Security & Privacy). Behaves identically whether or not this document is a proxied authenticate. The consumer MAY refuse a key type it does not support withauth/authenticate:sessionKeyUnsupported.final
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toJson(
) → Map< String, dynamic> - Serialize to a JSON-encodable map, omitting absent members.
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited