Assemble MY OWN recipient bundle for out-of-band sharing (the [S6] workaround): everything a sealer needs to address me — public keys and the signed binding, pulled from the server's own listings (never recomputed locally, so what you share is exactly what the directory serves). Send the result to whoever will seal for you; their SDK re-verifies the binding before use. Contains ONLY public material.
Full item view (membership-gated: members see raw fields, others get a uniform 404).
Public item view (skeleton + commitments; personal identifiers masked). No auth.
Grant an existing participant access to an already-sealed field (re-wrap).
Grant read access through a link (capability token).
Partner ingestion (X-API-Key only — a Bearer here is a config mistake and fails fast).
With preview: true it dry-runs: nothing written, nothing anchored. Items land in the
circuit bound to the API key.
Log in with workspace credentials; stores the bearer for subsequent calls.
Who am I — user + workspace of the current bearer.
Open a sealed field addressed to this workspace: fetch the envelope, unwrap the DK with the LOCAL private key, decrypt, and verify commitment + sealer signature. All decryption happens here — the server only ever handed over the padlocked envelope.
Resolve an item by domain identifier (SISBOV, chip, …).
OptionalcircuitId: stringRevoke a grant (forward-only: cuts future access, never un-reads the past).
Seal one field of an item: encrypt client-side so that ONLY the addressed recipients can ever read it — the DeFarm server stores the envelope and is structurally blind. Defaults are the safe ones: no recipients = sealed for yourself only; your own key is always included unless you explicitly opt out; visibility is private.
Every recipient's key binding is RE-VERIFIED here before sealing — a key whose binding does
not close is refused (RecipientBindingError), even if it came from the DeFarm directory.
Public verification of a DFID via the aggregator (GET /v1/verify/{dfid} — no auth). Returns
the raw report plus best-effort extractions. For fully independent verification (Horizon,
IPFS, hash recomputation) use the open-source defarm-repo/defarm-verify tooling — deep
parity is planned for this SDK.
Generate (client-side, first time only) and register this workspace's key pairs: Ed25519 for authorship and X25519 for encryption, the public halves only, the encryption key carrying its signed binding. Idempotent AND race-safe (issue #8): concurrent calls on the same client share one in-flight promise, and the keystore's
getOrCreateruns the whole get→generate→put cycle under its lock — two racingensureKeys()must never register two key pairs and keep only one on disk (a field sealed to the dropped key would be unopenable forever). The DeFarm server is a DIRECTORY, not an authority: it never sees a private key, and this method never returns one.