Payload class

The subject presents a previously-issued challenge along with the framework proof that binds the document to a VID. The proof IS the authentication. 0.3 adds an optional proxied form: principal names a party the signer authenticates as, distinct from issuer (the signer, e.g. a VTA acting on the principal's behalf), together with delegationEvidence establishing the entitlement. Absent principal, or principal equal to issuer, is the ordinary auth/authenticate/0.2 form unchanged. 0.3 also carries forward the optional sessionKey member from 0.2.

Constructors

Payload({required String challenge, required String sessionId, List<String>? scope, String? principal, PayloadDelegationEvidence? delegationEvidence, String? sessionKey, Ext? ext})
const
Payload.fromJson(Map<String, dynamic> json)
Read this payload from a decoded JSON object.
factory

Properties

challenge → String
The exact challenge value returned by a prior auth/challenge call. Consumers MUST reject mismatch, expired, or re-used challenges.
final
delegationEvidence → PayloadDelegationEvidence?
REQUIRED whenever principal is present and differs from issuer; MUST be omitted otherwise. Describes the evidence that entitles issuer to authenticate as principal. The framework does not prescribe its shape — see Authorization — but the consumer's policy MUST verify it independently rather than take issuer's claim of entitlement at face value.
final
ext → Ext?
Ecosystem-defined extension members per SPEC.md §4.5.1.
final
hashCode → int
The hash code for this object.
no setterinherited
principal → String?
The VID being authenticated as, when it differs from the signer of this document. Present and unequal to issuer marks a proxied authenticate: issuer is a delegate (typically the principal's VTA) presenting its own proof, and payload.delegationEvidence MUST also be present, describing what entitles issuer to act for principal. Omitted, or equal to issuer, is the ordinary case: the signer authenticates as itself, exactly as auth/authenticate/0.2. See Authorization and Security & Privacy.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
scope → List<String>?
Optional capability tags being requested on the issued tokens. The consumer's authorization layer decides which are granted; the issued TokenBundle's scope MAY be a subset.
final
sessionId → String
The sessionId returned alongside the challenge. Consumers use it to look up the server-side challenge binding.
final
sessionKey → String?
A did:key VID the producer asks the consumer to bind to the session this authenticate document creates. The producer MUST hold the corresponding private key and SHOULD keep it non-extractable (for example, a WebCrypto non-extractable key). Once bound, the consumer MUST accept a framework proof made by this key, with proofPurpose: authentication, as the session's subject — for this session only, bounded by the session's expiresAt and acr, and never where a specification requires an assertionMethod attestation (SPEC.md §7.2 item 10; see Security & Privacy). Behaves identically whether or not this document is a proxied authenticate. The consumer MAY refuse a key type it does not support with auth/authenticate:sessionKeyUnsupported.
final

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toJson() → Map<String, dynamic>
Serialize to a JSON-encodable map, omitting absent members.
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited