Session class

A logical authentication context bound to a subject. Producers and consumers exchange Session-shaped data in challenge issuance, authentication responses, and introspection (whoami).

Constructors

Session({required String id, required String subject, required String issuedAt, required String expiresAt, List<String>? amr, String? acr, String? sessionKey, Ext? ext})
const
Session.fromJson(Map<String, dynamic> json)
Read this payload from a decoded JSON object.
factory

Properties

acr → String?
Authentication Context Class Reference per [OIDC Core §2]. Profiles define their own values; the recommended set is "aal1" (single-factor DID auth), "aal2" (a second possession-or-biometric factor confirmed), and "aal3" (hardware-bound second factor).
final
amr → List<String>?
Authentication Methods References per [RFC 8176]. Typical values: "did" (challenge-response), "passkey" (WebAuthn), "vta" (verifiable-trust agent approval). Multi-factor sessions list every method used.
final
expiresAt → String
ISO-8601 timestamp when the session ceases to be valid. Producers SHOULD refresh before this time; consumers MUST reject after.
final
ext → Ext?
Ecosystem-defined extension members per SPEC.md §4.5.1.
final
hashCode → int
The hash code for this object.
no setterinherited
id → String
Opaque, server-chosen session identifier. Stable for the lifetime of the session. Consumers MUST treat the value as opaque; no structure is implied.
final
issuedAt → String
ISO-8601 timestamp when the session was created.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
sessionKey → String?
The did:key VID bound to this session by auth/authenticate/0.2, when the producer registered one. Present here so introspection (auth/whoami, auth/sessions/list) can show the binding a client already holds; it is descriptive, not an additional grant — the binding, its scope and its lifetime are governed entirely by the auth/authenticate/0.2 specification that established it. Absent when the session was established without a session key, or by a specification version that does not carry one.
final
subject → String
The authenticated party's VID (typically a DID URL).
final

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toJson() → Map<String, dynamic>
Serialize to a JSON-encodable map, omitting absent members.
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited