Interface SealedField

The sealed envelope the server stores — no plaintext, no key.

interface SealedField {
    aad: string;
    alg: string;
    ciphertext_b64: string;
    commitment_sha256: string;
    content_type: string;
    dfid: string;
    event_id: string;
    field_path: string;
    schema: string;
    sealer_key_id: string;
    sealer_sig_alg: string;
    sealer_sig_b64: string;
    sealer_workspace_id: string;
    wraps: Wrap[];
}

Properties

aad: string

The canonical (JCS) AAD binding ciphertext to schema/alg/dfid/event/field/content_type/ commitment. Re-derived and compared on open — none of those fields is decorative.

alg: string
ciphertext_b64: string

nonce(12) || ciphertext, base64.

commitment_sha256: string

Hiding commitment HMAC-SHA256(HKDF(DK), plaintext), lowercase hex — brute-force-proof without the DK.

content_type: string

Declared content type of the sealed value (e.g. text/plain) — bound into the AAD.

dfid: string
event_id: string

On the wire this carries the CLIENT event id (a nonce the sealer picks); the real event id is server-assigned after the POST and linked server-side. It is bound into the AAD.

field_path: string
schema: string
sealer_key_id: string

Which of that workspace's registered signing keys (trust_signing_keys.key_id) signed.

sealer_sig_alg: string

Signature suite (ed25519_jcs_v1). Inside the signed material (anti protocol-ambiguity).

sealer_sig_b64: string

Ed25519 (base64) over the canonical signing string. The ONLY field outside the signed material.

sealer_workspace_id: string

Authorship: the workspace that ASSUMES the sealing (may differ from the submitter in mode A2).

wraps: Wrap[]