Payload class

Relayer presents a VP-signed bootstrap request from an integration holder; the maintainer mints the integration's DIDs and admin credential from a registered DID template and ships the material back HPKE-sealed to the holder's ephemeral did:key. Two ask variants are supported: TemplateBootstrap (mint integration DID + optional admin DID) and AdminRotation (mint only the long-term admin DID).

Constructors

Payload({required BootstrapRequest request, String? context, PayloadAssertion? assertion, int? vcValiditySeconds, bool? createContext, Ext? ext})
const
Payload.fromJson(Map<String, dynamic> json)
Read this payload from a decoded JSON object.
factory

Properties

assertion → PayloadAssertion?
Producer-assertion mode the maintainer should apply to the returned sealed bundle. didSigned (default) — Ed25519 signature over the bundle's domain-bound digest, verified by the holder against the maintainer's published key. pinnedOnly — holder pins the bundle's SHA-256 digest as the sole integrity anchor; for dev/test only. Maintainers MAY support additional modes (e.g. attested for TEE deployments) and respond with provision/integration:assertionUnsupported to unsupported requests.
final
context → String?
The maintainer's context identifier the integration is to be provisioned into. When present, authoritative — overrides any contextHint carried inside request.ask. When ABSENT, the maintainer infers the target context using these rules in order: (1) if the relayer's grant scopes to exactly one context, use that context; (2) if the relayer is a super-admin (Admin role with unrestricted scope) and the maintainer has exactly one context registered, use that context; (3) otherwise reject the request with provision/integration:contextRequired. Wallet-class consumers (browser plugins, mobile companions) that don't know the maintainer's context layout SHOULD omit this field; integration-class consumers (mediator, did-hosting) targeting a specific operational context SHOULD send it explicitly.
final
createContext → bool?
When true, the maintainer provisions the target context inline if it does not already exist. Requires super-admin role on the maintainer; context-admin callers MUST receive provision/integration:forbidden against a missing context. Idempotent when the context already exists.
final
ext → Map<String, dynamic>?
Ecosystem-defined extension members per SPEC.md §4.5.1.
final
hashCode → int
The hash code for this object.
no setterinherited
request → BootstrapRequest
VP-framed bootstrap request signed by the holder's ephemeral did:key. The proof here is independent of, and additional to, the outer Trust Task envelope's proof — it authenticates the holder (the party the sealed bundle is encrypted for), whereas the envelope's proof authenticates the relayer (the party making the call). The two MAY be the same DID in the common case.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
vcValiditySeconds → int?
Caller-preferred validity window for the issued VtaAuthorizationCredential, in seconds. The maintainer's policy applies a floor and ceiling; values outside that range MAY be silently clamped. Defaults to the maintainer's policy default (typically 3600s).
final

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toJson() → Map<String, dynamic>
Serialize to a JSON-encodable map, omitting absent members.
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited