sessionKey property
A did:key VID the producer asks the consumer to bind to the session this
authenticate document creates. The producer MUST hold the corresponding private key
and SHOULD keep it non-extractable (for example, a WebCrypto non-extractable key).
Once bound, the consumer MUST accept a framework proof made by this key, with
proofPurpose: authentication, as the session's subject — for this session only,
bounded by the session's expiresAt and acr, and never where a specification
requires an assertionMethod attestation (SPEC.md §7.2 item 10; see Security &
Privacy). Behaves identically whether or not this document is a proxied
authenticate. The consumer MAY refuse a key type it does not support with
auth/authenticate:sessionKeyUnsupported.
Implementation
final String? sessionKey;