specs/provision/integration/v0_2/payload library

Classes

AdminRotationAsk
Admin-only mint. No integration DID is produced. Used by holders that bring (or will mint elsewhere) their own integration-side identity and only need an admin credential at this maintainer.
BootstrapRequest
W3C Verifiable Presentation 2.0 (§6.1: VPs MAY omit verifiableCredential). Custom members nonce, validUntil, label, and ask sit alongside the standard VP fields and are covered by the same DataIntegrityProof.
DataIntegrityProof
W3C Data Integrity proof. Spec body pins cryptosuite and proofPurpose; this schema permits the standard property bag so future cryptosuites can ride the same shape.
DidTemplateRef
Reference to a DID template already registered at the maintainer. Inline template definitions are deliberately not supported — templates must be uploaded out-of-band first (operator-authored or built-in) so the maintainer can validate vars against the template's declared schema.
Payload
Relayer presents a VP-signed bootstrap request from an integration holder; the maintainer mints the integration's DIDs and admin credential from a registered DID template and ships the material back HPKE-sealed to the holder's ephemeral did:key. Two ask variants are supported: TemplateBootstrap (mint integration DID + optional admin DID) and AdminRotation (mint only the long-term admin DID).
ProvisionSummary
Audit-grade metadata about the provisioning outcome. Mirrors the existing vta_sdk::provision_integration::http::ProvisionSummary Rust type but uses camelCase wire fields per Trust Task convention.
Response
Carried in a Trust Task document whose type is https://trusttasks.org/spec/provision/integration/0.1#response. The sealed bundle is the secret-bearing artefact; summary is non-secret audit metadata.
TemplateBootstrapAsk
Mint an integration DID from template, and (when adminTemplate is present) atomically roll over the holder to a fresh long-term admin DID minted from adminTemplate.

Extension Types

PayloadAssertion
Producer-assertion mode the maintainer should apply to the returned sealed bundle. didSigned (default) — Ed25519 signature over the bundle's domain-bound digest, verified by the holder against the maintainer's published key. pinnedOnly — holder pins the bundle's SHA-256 digest as the sole integrity anchor; for dev/test only. Maintainers MAY support additional modes (e.g. attested for TEE deployments) and respond with provision/integration:assertionUnsupported to unsupported requests.

Constants

payloadSchemaJson → const String
This specification's payload schema, as JSON text.
responsePayloadSchemaJson → const String
As payloadSchemaJson, for the success-response variant.
responseSpec → const SpecPolicy
The SPEC §7.2 policy for the success-response variant.
responseTypeUri → const String
The success-response form of typeUri (SPEC §4.4.1).
spec → const SpecPolicy
The SPEC §7.2 policy for the request variant, taken from this specification's front matter.
typeUri → const String
The Trust Task type URI this library's Payload is carried under.

Typedefs

BootstrapAsk = Object?
Discriminated union of bootstrap intents. Extensible — future minor versions MAY add variants.
Ext = Map<String, dynamic>
Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.