nonce property
16 random bytes encoded as base64url-no-pad (22 characters). The maintainer treats
this as the sealed bundle's bundleId (decoded to hex, exposed in
summary.bundleIdHex) and SHOULD enforce one-shot semantics — a second
provisioning with the same nonce MUST be refused as a replay.
Implementation
final String nonce;