specs/vault/release/v0_2/payload
library
Classes
-
ConsumerContext
-
ConsumerContext
-
DidcommAuthcryptEnvelope
-
DIDComm v2 authcrypt JWE (ECDH-1PU + A256CBC-HS512, X25519/P-256 key agreement).
Sender authentication is the JWE's
skid — the producer's DID#keyAgreement. The
maintainer's keyAgreement key is the recipient. Cleartext is JCS-canonical JSON of
the variant's payload type. M2A is the only implementation today; this is also the
canonical default for new code.
-
HpkeArmoredEnvelope
-
OpenPGP-style ASCII-armored HPKE bundle — the existing OpenVTC sealed-transfer wire
form (X25519-HKDF-SHA256 KEM + ChaCha20-Poly1305 AEAD, framed in armor with
Bundle-Id / Digest-Algo headers and a CRC24 checksum). Producer assertion
(
didSigned / attested / pinnedOnly) is the integrity / authenticity anchor.
No open-source implementation reads this yet outside vta-sdk's sealed_transfer
crate; new code SHOULD prefer the DIDComm variant. Defined here for parity with the
existing offline-bundle / cross-VTA workflows that the design plan reserves for
M5+.
-
Payload
-
Consumer requests that the maintainer release the cleartext secret material of a
vault entry. The response carries the secret in a pluggable cipher envelope (see
vault/_shared/0.1/sealed-envelope); the cleartext shape is
vault/_shared/0.1/vault-secret#/$defs/VaultSecret. This is the fallback when
proxy-login is not viable (vault/proxy-login:notProxyable) or when the consumer
needs the raw secret for a flow the maintainer cannot perform (e.g. autofill into a
desktop app, copy-to-clipboard for offline use).
-
Response
-
Vault Release — response payload
-
StepUpProof
-
StepUpProof
-
TspMessageEnvelope
-
Trust Spanning Protocol message
(https://trustoverip.github.io/tswg-tsp-specification/). Reserved variant; no
OpenVTC component reads or emits this today. Listed in the union so implementations
can declare intent to use TSP in discovery and so consumers reject
tspMessage
envelopes explicitly (envelopeUnsupported) until they're wired up — rather than
silently failing in DIDComm parsing.
Extension Types
-
ConsumerContextNetworkClass
-
Producer-supplied network classification. Advisory.
-
HpkeArmoredEnvelopeProducerAssertion
-
Producer-assertion mode per the sealed-transfer framework.
didSigned = Ed25519
signature by issuer; attested = TEE attestation quote (e.g. Nitro); pinnedOnly
= OOB SHA-256 digest only (dev/test, NOT for production).
-
SecretKind
-
Discriminator for the secret type stored in the entry. Definitions: -
password —
username + password (+ optional TOTP seed). - passkey — WebAuthn discoverable
credential (private key + rpId + userHandle). - oauthTokens — OAuth 2.0 refresh +
access token bundle for a specific provider. - didSelfIssued — Self-Issued OpenID
Provider v2 (SIOP) credential: the entry points at a DID + signing key already
managed by the VTA. - didcommPeer — DIDComm peer identity used to authenticate
against a DIDComm-speaking relying party. - bearerToken — opaque bearer token
carried in a maintainer-named header (covers API tokens, long-lived JWTs,
personal-access tokens). - sshKey — SSH private key + comment. - custom —
arbitrary structured fields; release-time consumer responsible for interpretation.
-
StepUpProofKind
-
StepUpProofKind is a closed set of string values defined by this specification's
schema.
Typedefs
-
Ext
= Map<String, dynamic>
-
Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a
reverse-DNS namespace; structure under each namespace is opaque to the framework.
-
SealedEnvelope
= Object?
-
Discriminated by
envelope. Exactly one variant matches per document.
-
SiteTarget
= Object?
-
A single binding target for a vault entry. Tagged union over the discriminator
kind. A VaultEntry's targets array MAY mix any number of these.