specs/keys/shared/v0_1/sign_algorithm library

Extension Types

SignAlgorithm
EdDSA pairs with an ed25519 key; ES256 pairs with a p256 key; ML-DSA-44 and ML-DSA-65 pair with mldsa44 and mldsa65 keys respectively. An x25519 key performs key agreement and can sign nothing, so no algorithm here is valid for one. These are JOSE algorithm identifiers, externally owned, so they are carried verbatim and never re-cased (SPEC.md §4.10 rule 5); the ML-DSA names are those RFC 9964 registers in the JOSE Web Signature and Encryption Algorithms registry, which is why their hyphenated casing differs from the keyType values beside them — those are specification-defined. The set is expected to grow as algorithms are registered. The enumeration remains closed: an unrecognised algorithm is refused rather than silently substituted with a supported one.