The canonical (JCS) AAD binding ciphertext to schema/alg/dfid/event/field/content_type/ commitment. Re-derived and compared on open — none of those fields is decorative.
nonce(12) || ciphertext, base64.
Hiding commitment HMAC-SHA256(HKDF(DK), plaintext), lowercase hex — brute-force-proof without the DK.
Declared content type of the sealed value (e.g. text/plain) — bound into the AAD.
On the wire this carries the CLIENT event id (a nonce the sealer picks); the real event id is server-assigned after the POST and linked server-side. It is bound into the AAD.
Which of that workspace's registered signing keys (trust_signing_keys.key_id) signed.
Signature suite (ed25519_jcs_v1). Inside the signed material (anti protocol-ambiguity).
Ed25519 (base64) over the canonical signing string. The ONLY field outside the signed material.
Authorship: the workspace that ASSUMES the sealing (may differ from the submitter in mode A2).
The sealed envelope the server stores — no plaintext, no key.