Type Alias KeyKind

KeyKind: "signing" | "encryption"

Where private keys live. HARD RULE: private key material never leaves the producer's side — it is generated here and stays here. The SDK ships a file keystore (server-side integrations) and an in-memory one (tests, ephemeral flows); an ERP with an HSM implements this interface.

Kinds: signing = Ed25519 seed (authorship — gives ZERO decryption power); encryption = X25519 private key (unwrap/decrypt).