Skip to content

Go: dnsid — records & keys

Generated from the Go source by scripts/gen-docs.sh — do not edit; run it to regenerate. Canonical deep reference: pkg.go.dev/github.com/dnsid-ai/dnsid-go. Guides and account setup: https://docs.dnsid.ai.

Part of the root package github.com/dnsid-ai/dnsid-go — see Core: IdentityManager for the package overview.

func ParseJWKSet(data []byte) (jwk.Set, error)

ParseJWKSet parses a JWKS JSON document and returns a validated raw JWK set.

func ParseLogRef(lr string) (method, entryRef string, err error)

ParseLogRef splits an lr= log reference of the form “method:entryRef” into its method and entry-reference parts. It returns a *ParseError for malformed references or invalid method names.

DNSRecord matches the OpenAPI DNSRecord schema.

type DNSRecord struct {
Name string `json:"name"`
Type string `json:"type"`
Value string `json:"value"`
TTL int `json:"ttl"`
}

JWK is a typed wrapper over a single JWK with SDK-level helpers.

type JWK struct {
// contains filtered or unexported fields
}

func (k *JWK) Alg() JoseAlg

Alg returns the key’s effective signing algorithm, deriving it from kty/crv when the JWK alg member is absent.

func (k *JWK) Kid() string

Kid returns the key’s kid value, or empty string if unset.

func (k *JWK) Raw() jwk.Key

Raw returns the underlying jwk.Key.

func (k *JWK) SignatureAlg(profile string) (JoseAlg, error)

SignatureAlg returns the signing algorithm allowed by the selected identity-record profile. Unlike JWK.Alg, draft profiles require an explicit alg member that is consistent with the key type. An empty profile selects DefaultPublishProfile.

func (k *JWK) Thumbprint() (string, error)

Thumbprint returns the RFC 7638 SHA-256 thumbprint of this key, base64url-unpadded encoded.

func (k *JWK) Use() string

Use returns the key’s use value, or empty string if unset.

JWKS is a typed wrapper over a JWK Set with SDK-level helpers.

type JWKS struct {
// contains filtered or unexported fields
}

func NewJWKS(set jwk.Set) *JWKS

NewJWKS wraps a jwk.Set into the typed SDK form.

func ParseJWKS(data []byte) (*JWKS, error)

ParseJWKS parses a JWKS JSON document and returns the typed wrapper.

func (j *JWKS) CurrentOperationalSigningKey(profile string) (*JWK, error)

CurrentOperationalSigningKey returns the sole current operational signing key allowed by the selected identity-record profile.

func (j *JWKS) CurrentRecordSigningKey(profile string) (*JWK, error)

CurrentRecordSigningKey returns the sole current record-signing key allowed by the selected identity-record profile.

func (j *JWKS) KeyByID(kid string) *JWK

KeyByID returns the key with the given kid, or nil if not found. This is an unfiltered lookup; the returned key may have use=enc or any other use value. Callers that want a signing-eligible key should filter the result against SigningKeys() or check Use() themselves.

func (j *JWKS) Raw() jwk.Set

Raw returns the underlying jwk.Set.

func (j *JWKS) SigningKeys() []*JWK

SigningKeys returns all keys eligible for signature verification. Keys with unset use or use=sig are eligible.

func (j *JWKS) Validate() error

Validate enforces SDK invariants for signing keys.

func (j *JWKS) ValidateOperational(profile string) error

ValidateOperational verifies that the JWKS satisfies the selected identity-record profile’s operational-key constraints. An empty profile selects DefaultPublishProfile.

func (j *JWKS) ValidateRecordSigning(profile string) error

ValidateRecordSigning verifies that the JWKS satisfies the selected identity-record profile’s record-signing-key constraints. An empty profile selects DefaultPublishProfile.

JoseAlg is the default-deny allowlist of JOSE algorithms DNSid accepts.

type JoseAlg string

The JOSE algorithms DNSid accepts: Ed25519 (EdDSA) and ECDSA over P-256 with SHA-256 (ES256). All other algorithms are rejected.

const (
JoseAlgEdDSA JoseAlg = "EdDSA"
JoseAlgES256 JoseAlg = "ES256"
)

func (a JoseAlg) String() string

String returns the JOSE alg identifier as a string.

func (a JoseAlg) Valid() bool

Valid reports whether a is in the DNSid JOSE algorithm allowlist.

PolicyFlag is a DNSid TXT-record policy flag.

type PolicyFlag string

DNSid TXT-record policy flags understood by the verifier.

const (
PolicyFlagMTLS PolicyFlag = "mtls"
PolicyFlagLogCheck PolicyFlag = "logchk"
)

TXTRecord represents a parsed _dnsid TXT record.

type TXTRecord struct {
Version string // v= — DNSid wire profile
GovernanceID string // gi= — governance identifier
EntityKeyURI string // ek= — accountable-entity record-signing JWKS URI
KeyURI string // ku= — JWKS endpoint URL
LogRef string // lr= — ledger address
StatusURI string // su= — status endpoint URL
Signature string // sg= — base64url owner signature
Flags []string // fl= — parsed flag list (nil if absent)
KeyAge string // ka= — key age policy (empty if absent)
Capabilities string // cu= — Agent Card URL (empty if absent)
UnknownTags map[string]string // syntactically valid extension tags, preserved but ignored semantically
}

func ParseTXTRecord(txt string) (*TXTRecord, error)

ParseTXTRecord parses a concatenated TXT record string into a TXTRecord.

func ParseUnsignedCanonical(txt string) (*TXTRecord, error)

ParseUnsignedCanonical parses registry-supplied unsigned canonical TXT content. It accepts required non-signature inputs and extension tags, but rejects sg=.

func (r *TXTRecord) Canonical() string

Canonical returns the canonical string used for TXT-record signature verification.

func (r *TXTRecord) CanonicalContent() []byte

CanonicalContent returns the canonical byte string for signing under the record’s declared profile. Values are signed as raw ASCII TXT tag values.

func (r *TXTRecord) KnownTagsCanonical() []byte

KnownTagsCanonical returns the canonical byte string for known TXT tags only, excluding sg=. Unknown extension tags are ignored.

func (r *TXTRecord) MarshalTXT() (string, error)

MarshalTXT serializes the record as one _dnsid TXT value for wire output. It emits v= first, then all other tags sorted lexically; signing order is profile-defined and may differ.

func (r *TXTRecord) Serialize() string

Serialize serializes the record as one _dnsid TXT value.

func (r *TXTRecord) Tags() map[string]string

Tags returns the record’s tag-value pairs as a map, excluding empty optional fields. It always emits the current wire tag names.

func (r *TXTRecord) Validate(identityFQDN string) error

Validate checks record-level semantics with identity-domain context.

func (r *TXTRecord) WithSignature(sig string) *TXTRecord

WithSignature returns a copy of the record with Signature set to sig.

TXTRecordRData is one concatenated TXT RDATA value plus resolver metadata.

type TXTRecordRData struct {
Value string
TTL time.Duration
}