Interface SealRecipientInput

A recipient to seal to, pre-resolved OUT OF BAND (workaround while the in-circuit recipient resolver endpoint is broken behind the gateway — collection step [S6]). The SDK still re-verifies the binding before sealing, exactly as it would with directory-served keys, so the cryptographic guarantee is unchanged. This input surface will be removed once the directory endpoint works — identity→key resolution belongs to the directory, not the caller.

interface SealRecipientInput {
    bindingSigB64: string;
    encKeyId: string;
    encPubkeyB64: string;
    signingPubkeyB64: string;
    workspaceId: string;
}

Properties

bindingSigB64: string

The recipient's Ed25519 signature over the canonical (workspace, key id, pubkey) binding.

encKeyId: string
encPubkeyB64: string
signingPubkeyB64: string

The recipient's Ed25519 signing public key (to verify the binding against).

workspaceId: string