specs/keys/shared/v0_1/sign_algorithm
library
Extension Types
-
SignAlgorithm
-
EdDSA pairs with an ed25519 key; ES256 pairs with a p256 key; ML-DSA-44
and ML-DSA-65 pair with mldsa44 and mldsa65 keys respectively. An x25519
key performs key agreement and can sign nothing, so no algorithm here is valid for
one. These are JOSE algorithm identifiers, externally owned, so they are carried
verbatim and never re-cased (SPEC.md §4.10 rule 5); the ML-DSA names are those RFC
9964 registers in the JOSE Web Signature and Encryption Algorithms registry, which
is why their hyphenated casing differs from the keyType values beside them —
those are specification-defined. The set is expected to grow as algorithms are
registered. The enumeration remains closed: an unrecognised algorithm is refused
rather than silently substituted with a supported one.