specs/external/credentials/issue/v0_1/payload library

Classes

CredentialScope
What one issuance may do. For storage models, prefix and actions (both required, a rule this schema leaves to the custodian because other models use neither); for s3-static-presign, also objectKey, since a presigned URL is one operation on one object; for oauth2-private-key-jwt, scopes.
Payload
Obtain a short-lived, downscoped provider credential from an external account, sealed to the caller. The outer document members are owned by the framework — SPEC §6.3.
Response
External Credentials — Issue — response payload

Extension Types

ProviderObjectAction
put: write an object. get: read one. delete: remove one. No list, ACL, policy or bucket-level action exists here, so none can be granted.

Constants

payloadSchemaJson → const String
This specification's payload schema, as JSON text.
responsePayloadSchemaJson → const String
As payloadSchemaJson, for the success-response variant.
responseSpec → const SpecPolicy
The SPEC §7.2 policy for the success-response variant.
responseTypeUri → const String
The success-response form of typeUri (SPEC §4.4.1).
spec → const SpecPolicy
The SPEC §7.2 policy for the request variant, taken from this specification's front matter.
typeUri → const String
The Trust Task type URI this library's Payload is carried under.

Typedefs

AccountContextId = String
The custodian context that owns the account. Act scope in this context decides who may manage the account and who may consume it; the account's keys are derived in this context's key space.
AccountId = String
The account's identifier within its context, chosen by whoever creates it. Lowercase letters, digits and hyphens, so that it can be embedded in a certificate subject, a token subject or a provider-side condition without escaping. Unique per context; never reused after deletion while anything that names it (a provider-side trust policy, an audit row) may still exist.
Ext = Map<String, dynamic>
Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
ProviderObjectPrefix = String
An object-key prefix within the account's bucket: one or more segments of lowercase letters, digits, ., _ and -, each beginning with a letter or digit and ending with /. No quote, backslash, wildcard, whitespace, .. segment or empty segment can appear. That is deliberate: the custodian places this value inside a provider policy — an IAM session policy (JSON), a GCS Credential Access Boundary condition (CEL) — and a value able to carry a metacharacter can break out of the string it is placed in and widen the policy. That is a known class of defect (CVE-2026-42811, a CEL injection in downscoped GCS credentials). Even with this pattern, a custodian MUST build provider policies with the provider language's own encoder, never by string interpolation.
SealedTransferBundle = String
A sealed-transfer bundle: OpenPGP-style ASCII armor around an HPKE-sealed SealedPayloadV1 (base mode, X25519-HKDF-SHA256 KEM, HKDF-SHA256 KDF, ChaCha20-Poly1305 AEAD, info string vta-sealed-transfer/v1), with a producer assertion and Bundle-Id, Chunk and Digest-Algo headers bound into the associated data. Each task states the key it is sealed to: a single-use wrapping key from keys/import-wrapping-key for external/accounts/secret/set, and the caller's key-agreement key for external/credentials/issue. Its cleartext is an ExternalSecretPayload or an ExternalCredentialPayload. The only form in which secret material crosses the wire in this family, in either direction: the seal is what keeps a terminating proxy, a relay, a request log or a debug dump of "the response" from ever holding a usable secret, whatever transport carried the document.