specs/external/credentials/issue/v0_1/payload
library
Classes
-
CredentialScope
-
What one issuance may do. For storage models,
prefix and actions (both
required, a rule this schema leaves to the custodian because other models use
neither); for s3-static-presign, also objectKey, since a presigned URL is one
operation on one object; for oauth2-private-key-jwt, scopes.
-
Payload
-
Obtain a short-lived, downscoped provider credential from an external account,
sealed to the caller. The outer document members are owned by the framework — SPEC
§6.3.
-
Response
-
External Credentials — Issue — response payload
Extension Types
-
ProviderObjectAction
-
put: write an object. get: read one. delete: remove one. No list, ACL, policy
or bucket-level action exists here, so none can be granted.
Typedefs
-
AccountContextId
= String
-
The custodian context that owns the account. Act scope in this context decides who
may manage the account and who may consume it; the account's keys are derived in
this context's key space.
-
AccountId
= String
-
The account's identifier within its context, chosen by whoever creates it.
Lowercase letters, digits and hyphens, so that it can be embedded in a certificate
subject, a token subject or a provider-side condition without escaping. Unique per
context; never reused after deletion while anything that names it (a provider-side
trust policy, an audit row) may still exist.
-
Ext
= Map<String, dynamic>
-
Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a
reverse-DNS namespace; structure under each namespace is opaque to the framework.
-
ProviderObjectPrefix
= String
-
An object-key prefix within the account's bucket: one or more segments of lowercase
letters, digits,
., _ and -, each beginning with a letter or digit and ending
with /. No quote, backslash, wildcard, whitespace, .. segment or empty segment
can appear. That is deliberate: the custodian places this value inside a provider
policy — an IAM session policy (JSON), a GCS Credential Access Boundary condition
(CEL) — and a value able to carry a metacharacter can break out of the string it is
placed in and widen the policy. That is a known class of defect (CVE-2026-42811, a
CEL injection in downscoped GCS credentials). Even with this pattern, a custodian
MUST build provider policies with the provider language's own encoder, never by
string interpolation.
-
SealedTransferBundle
= String
-
A sealed-transfer bundle: OpenPGP-style ASCII armor around an HPKE-sealed
SealedPayloadV1 (base mode, X25519-HKDF-SHA256 KEM, HKDF-SHA256 KDF,
ChaCha20-Poly1305 AEAD, info string vta-sealed-transfer/v1), with a producer
assertion and Bundle-Id, Chunk and Digest-Algo headers bound into the associated
data. Each task states the key it is sealed to: a single-use wrapping key from
keys/import-wrapping-key for external/accounts/secret/set, and the caller's
key-agreement key for external/credentials/issue. Its cleartext is an
ExternalSecretPayload or an ExternalCredentialPayload. The only form in which
secret material crosses the wire in this family, in either direction: the seal is
what keeps a terminating proxy, a relay, a request log or a debug dump of "the
response" from ever holding a usable secret, whatever transport carried the
document.