Interface Wrap

The data key (DK) wrapped via HPKE for ONE recipient. Only their private key unwraps it.

interface Wrap {
    hpke_enc_b64: string;
    kid_fingerprint: string;
    recipient_enc_key_id: string;
    recipient_workspace_id: string;
    wrapped_dk_b64: string;
}

Properties

hpke_enc_b64: string

The HPKE encapsulated key (enc), base64 — 32 bytes for X25519.

kid_fingerprint: string

sha256:<hex> of the recipient's public key (so they can confirm it is their lock).

recipient_enc_key_id: string
recipient_workspace_id: string
wrapped_dk_b64: string

The wrapped DK (HPKE ciphertext), base64 — 48 bytes (DK 32 + tag 16).