Payload class

Relayer presents a VP-signed bootstrap request from an integration holder; the maintainer mints the integration's DIDs and admin credential from a registered DID template and ships the material back HPKE-sealed to the holder's ephemeral did:key. Two ask variants are supported: TemplateBootstrap (mint integration DID + optional admin DID) and AdminRotation (mint only the long-term admin DID).

Constructors

Payload({required BootstrapRequest request, String? context, PayloadAssertion? assertion, int? vcValiditySeconds, bool? createContext, PayloadAdminScope? adminScope, Ext? ext})
const
Payload.fromJson(Map<String, dynamic> json)
Read this payload from a decoded JSON object.
factory

Properties

adminScope → PayloadAdminScope?
How wide the ACL entry the maintainer writes for the minted admin is. context (the default, and what every integration-class consumer wants) binds the admin to context alone. unrestricted binds it to no context at all — the shape an ACL reads as a super-admin, able to act in every context the maintainer holds today and in every one created later — and is what an operator console asks for. context is resolved and authoritative in BOTH cases: it is where the admin DID is minted and the home a consumer stores its own configuration under, so unrestricted widens the grant without making the target context optional. A maintainer MUST refuse unrestricted with provision/integration:forbidden unless the relayer is itself a super-admin, because no admin may confer authority it does not hold. A maintainer that does not implement this member ignores it and writes a context-scoped entry; that is why the outcome is echoed as summary.adminScope rather than assumed from the ask.
final
assertion → PayloadAssertion?
Producer-assertion mode the maintainer should apply to the returned sealed bundle. didSigned (default) — Ed25519 signature over the bundle's domain-bound digest, verified by the holder against the maintainer's published key. pinnedOnly — holder pins the bundle's SHA-256 digest as the sole integrity anchor; for dev/test only. Maintainers MAY support additional modes (e.g. attested for TEE deployments) and respond with provision/integration:assertionUnsupported to unsupported requests.
final
context → String?
The maintainer's context identifier the integration is to be provisioned into. When present, authoritative — overrides any contextHint carried inside request.ask. When ABSENT, the maintainer infers the target context using these rules in order: (1) if the relayer's grant scopes to exactly one context, use that context; (2) if the relayer is a super-admin (Admin role with unrestricted scope) and the maintainer has exactly one context registered, use that context; (3) otherwise reject the request with provision/integration:contextRequired. Wallet-class consumers (browser plugins, mobile companions) that don't know the maintainer's context layout SHOULD omit this field; integration-class consumers (mediator, did-hosting) targeting a specific operational context SHOULD send it explicitly.
final
createContext → bool?
When true, the maintainer provisions the target context inline if it does not already exist. Requires super-admin role on the maintainer; context-admin callers MUST receive provision/integration:forbidden against a missing context. Idempotent when the context already exists.
final
ext → Map<String, dynamic>?
Ecosystem-defined extension members per SPEC.md §4.5.1.
final
hashCode → int
The hash code for this object.
no setterinherited
request → BootstrapRequest
VP-framed bootstrap request signed by the holder's ephemeral did:key. The proof here is independent of, and additional to, the outer Trust Task envelope's proof — it authenticates the holder (the party the sealed bundle is encrypted for), whereas the envelope's proof authenticates the relayer (the party making the call). The two MAY be the same DID in the common case.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
vcValiditySeconds → int?
Caller-preferred validity window for the issued VtaAuthorizationCredential, in seconds. The maintainer's policy applies a floor and ceiling; values outside that range MAY be silently clamped. Defaults to the maintainer's policy default (typically 3600s).
final

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toJson() → Map<String, dynamic>
Serialize to a JSON-encodable map, omitting absent members.
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited