TypeScript: @dnsid-ai/protocol — interfaces
Part of Protocol core (@dnsid-ai/protocol).
Interfaces
Section titled “Interfaces”AgentStatus
Section titled “AgentStatus”Defined in: packages/protocol/src/types.ts:44
Properties
Section titled “Properties”lastTransitionAt
Section titled “lastTransitionAt”lastTransitionAt: Date;Defined in: packages/protocol/src/types.ts:46
revocationReason?
Section titled “revocationReason?”optional revocationReason?: RevocationReason;Defined in: packages/protocol/src/types.ts:47
state: AgentStatusState;Defined in: packages/protocol/src/types.ts:45
C2spIssuanceEvent
Section titled “C2spIssuanceEvent”Defined in: packages/protocol/src/log-events.ts:64
ISSUANCE shape required by the c2sp-tlog codec and verifier.
Extends
Section titled “Extends”Properties
Section titled “Properties”domain
Section titled “domain”domain: string;Defined in: packages/protocol/src/log-events.ts:30
Inherited from
Section titled “Inherited from”entityKey?
Section titled “entityKey?”optional entityKey?: IssuanceKeySlot;Defined in: packages/protocol/src/log-events.ts:46
Accountable-entity record-signing key (ek) recorded in the event.
Inherited from
Section titled “Inherited from”entitySig?
Section titled “entitySig?”optional entitySig?: string;Defined in: packages/protocol/src/log-events.ts:50
Entity-key signature over the canonical binding (base64url).
Inherited from
Section titled “Inherited from”governanceId
Section titled “governanceId”governanceId: string;Defined in: packages/protocol/src/log-events.ts:31
Inherited from
Section titled “Inherited from”initialEntityAlg
Section titled “initialEntityAlg”initialEntityAlg: string;Defined in: packages/protocol/src/log-events.ts:70
Overrides
Section titled “Overrides”IssuanceEvent.initialEntityAlg
initialEntityKid
Section titled “initialEntityKid”initialEntityKid: string;Defined in: packages/protocol/src/log-events.ts:69
c2sp-tlog encoding of the accountable entity key.
Overrides
Section titled “Overrides”IssuanceEvent.initialEntityKid
initialEntityPublicKey
Section titled “initialEntityPublicKey”initialEntityPublicKey: DnsIdJWK;Defined in: packages/protocol/src/log-events.ts:71
Overrides
Section titled “Overrides”IssuanceEvent.initialEntityPublicKey
initialEntityThumbprint
Section titled “initialEntityThumbprint”initialEntityThumbprint: string;Defined in: packages/protocol/src/log-events.ts:72
Overrides
Section titled “Overrides”IssuanceEvent.initialEntityThumbprint
initialOperationalAlg
Section titled “initialOperationalAlg”initialOperationalAlg: string;Defined in: packages/protocol/src/log-events.ts:66
Overrides
Section titled “Overrides”IssuanceEvent.initialOperationalAlg
initialOperationalKid
Section titled “initialOperationalKid”initialOperationalKid: string;Defined in: packages/protocol/src/log-events.ts:65
c2sp-tlog encoding of the initial operational key.
Overrides
Section titled “Overrides”IssuanceEvent.initialOperationalKid
initialOperationalPublicKey
Section titled “initialOperationalPublicKey”initialOperationalPublicKey: DnsIdJWK;Defined in: packages/protocol/src/log-events.ts:67
Overrides
Section titled “Overrides”IssuanceEvent.initialOperationalPublicKey
initialOperationalThumbprint
Section titled “initialOperationalThumbprint”initialOperationalThumbprint: string;Defined in: packages/protocol/src/log-events.ts:68
Overrides
Section titled “Overrides”IssuanceEvent.initialOperationalThumbprint
optional kid?: string;Defined in: packages/protocol/src/log-events.ts:56
Deprecated
Section titled “Deprecated”superseded by operationalKey/entityKey.
Inherited from
Section titled “Inherited from”newOperationalProof?
Section titled “newOperationalProof?”optional newOperationalProof?: string;Defined in: packages/protocol/src/log-events.ts:13
Base64url new-operational-key proof of possession. Required for c2sp-tlog KEY_ROTATION.
Inherited from
Section titled “Inherited from”IssuanceEvent.newOperationalProof
operationalCountersig?
Section titled “operationalCountersig?”optional operationalCountersig?: string;Defined in: packages/protocol/src/log-events.ts:11
Base64url operational-key countersignature. Required for draft-01 ISSUANCE.
Inherited from
Section titled “Inherited from”IssuanceEvent.operationalCountersig
operationalKey?
Section titled “operationalKey?”optional operationalKey?: IssuanceKeySlot;Defined in: packages/protocol/src/log-events.ts:48
Initial operational key (ku) recorded in the event.
Inherited from
Section titled “Inherited from”operationalSig?
Section titled “operationalSig?”optional operationalSig?: string;Defined in: packages/protocol/src/log-events.ts:52
Operational-key countersignature over the same canonical binding (base64url).
Inherited from
Section titled “Inherited from”publicKey?
Section titled “publicKey?”optional publicKey?: DnsIdJWK;Defined in: packages/protocol/src/log-events.ts:58
Deprecated
Section titled “Deprecated”superseded by operationalKey/entityKey.
Inherited from
Section titled “Inherited from”optional sig?: string;Defined in: packages/protocol/src/log-events.ts:9
Base64url signature. Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”signingKid?
Section titled “signingKid?”optional signingKid?: string;Defined in: packages/protocol/src/log-events.ts:7
Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”thumbprint?
Section titled “thumbprint?”optional thumbprint?: string;Defined in: packages/protocol/src/log-events.ts:60
Deprecated
Section titled “Deprecated”superseded by the slot thumbprints.
Inherited from
Section titled “Inherited from”timestamp
Section titled “timestamp”timestamp: Date;Defined in: packages/protocol/src/log-events.ts:42
Inherited from
Section titled “Inherited from”type: "ISSUANCE";Defined in: packages/protocol/src/log-events.ts:29
Inherited from
Section titled “Inherited from”DelegationEvent
Section titled “DelegationEvent”Defined in: packages/protocol/src/log-events.ts:111
Extends
Section titled “Extends”BaseLogEvent
Properties
Section titled “Properties”delegatee
Section titled “delegatee”delegatee: string;Defined in: packages/protocol/src/log-events.ts:114
domain
Section titled “domain”domain: string;Defined in: packages/protocol/src/log-events.ts:113
expiry
Section titled “expiry”expiry: Date;Defined in: packages/protocol/src/log-events.ts:116
newOperationalProof?
Section titled “newOperationalProof?”optional newOperationalProof?: string;Defined in: packages/protocol/src/log-events.ts:13
Base64url new-operational-key proof of possession. Required for c2sp-tlog KEY_ROTATION.
Inherited from
Section titled “Inherited from”BaseLogEvent.newOperationalProofoperationalCountersig?
Section titled “operationalCountersig?”optional operationalCountersig?: string;Defined in: packages/protocol/src/log-events.ts:11
Base64url operational-key countersignature. Required for draft-01 ISSUANCE.
Inherited from
Section titled “Inherited from”BaseLogEvent.operationalCountersigscope: string;Defined in: packages/protocol/src/log-events.ts:115
optional sig?: string;Defined in: packages/protocol/src/log-events.ts:9
Base64url signature. Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”BaseLogEvent.sigsigningKid?
Section titled “signingKid?”optional signingKid?: string;Defined in: packages/protocol/src/log-events.ts:7
Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”BaseLogEvent.signingKidtimestamp
Section titled “timestamp”timestamp: Date;Defined in: packages/protocol/src/log-events.ts:117
type: "DELEGATION";Defined in: packages/protocol/src/log-events.ts:112
DnsidConfig
Section titled “DnsidConfig”Defined in: packages/protocol/src/types.ts:125
Single core configuration entry point. Omit identity for a verification-only manager.
Properties
Section titled “Properties”identity?
Section titled “identity?”optional identity?: IdentityConfig;Defined in: packages/protocol/src/types.ts:126
transport?
Section titled “transport?”optional transport?: TransportConfig;Defined in: packages/protocol/src/types.ts:128
verification?
Section titled “verification?”optional verification?: VerificationConfig;Defined in: packages/protocol/src/types.ts:127
DnsIdJWK
Section titled “DnsIdJWK”Defined in: packages/protocol/src/types.ts:30
Indexable
Section titled “Indexable”[key: string]: unknownProperties
Section titled “Properties”optional alg?: string;Defined in: packages/protocol/src/types.ts:34
JOSE algorithm metadata. Required for draft-01 live ek/ku keys.
optional crv?: string;Defined in: packages/protocol/src/types.ts:36
optional e?: string;Defined in: packages/protocol/src/types.ts:40
kid: string;Defined in: packages/protocol/src/types.ts:32
kty: string;Defined in: packages/protocol/src/types.ts:31
optional n?: string;Defined in: packages/protocol/src/types.ts:39
optional use?: string;Defined in: packages/protocol/src/types.ts:35
optional x?: string;Defined in: packages/protocol/src/types.ts:37
optional y?: string;Defined in: packages/protocol/src/types.ts:38
DNSResolver
Section titled “DNSResolver”Defined in: packages/protocol/src/dns-resolver.ts:7
Pluggable DNS resolver dependency. Decouples verifyDomain from the system resolver.
Methods
Section titled “Methods”fetchTXT()
Section titled “fetchTXT()”fetchTXT(name, options?): Promise<[TXTRecord[], DNSSECState]>;Defined in: packages/protocol/src/dns-resolver.ts:14
Fetches TXT records for the given DNS owner name.
Parameters
Section titled “Parameters”string
Normalized FQDN without trailing dot (e.g. “_dnsid.agent.example”). MUST be treated as an absolute name — no search-domain expansion.
options?
Section titled “options?”signal?
Section titled “signal?”AbortSignal
Returns
Section titled “Returns”Promise<[TXTRecord[], DNSSECState]>
The record set and the DNSSEC validation state of the response.
FetchResult
Section titled “FetchResult”Defined in: packages/protocol/src/identity-manager.ts:54
Properties
Section titled “Properties”data: unknown;Defined in: packages/protocol/src/identity-manager.ts:55
tlsCert
Section titled “tlsCert”tlsCert: TLSCertificate;Defined in: packages/protocol/src/identity-manager.ts:56
IdentityCache
Section titled “IdentityCache”Defined in: packages/protocol/src/identity-cache.ts:11
Cache for verified domain results. Held by IdentityManager and consulted at the start of every verifyDomain call.
Implementation requirements:
- Get MUST return null for any entry whose VerifiedDomain.expiry() has passed.
- Put MUST derive the entry TTL from result.expiry() and evict automatically when that time arrives.
- Implementations MUST be safe for concurrent use.
Methods
Section titled “Methods”evict()
Section titled “evict()”evict(domain): void;Defined in: packages/protocol/src/identity-cache.ts:19
Removes a domain from the cache immediately.
Parameters
Section titled “Parameters”domain
Section titled “domain”string
Returns
Section titled “Returns”void
get(domain): VerifiedDomain | null;Defined in: packages/protocol/src/identity-cache.ts:13
Returns the cached VerifiedDomain for a domain, or null if not cached or expired.
Parameters
Section titled “Parameters”domain
Section titled “domain”string
Returns
Section titled “Returns”VerifiedDomain | null
put(domain, result): void;Defined in: packages/protocol/src/identity-cache.ts:16
Stores a verified domain result. Entry expires at result.expiry().
Parameters
Section titled “Parameters”domain
Section titled “domain”string
result
Section titled “result”Returns
Section titled “Returns”void
IdentityConfig
Section titled “IdentityConfig”Defined in: packages/protocol/src/types.ts:63
Local identity publication settings (DnsidConfig.identity). Contains no verification or transport policy.
Properties
Section titled “Properties”capabilitiesUrl?
Section titled “capabilitiesUrl?”optional capabilitiesUrl?: string;Defined in: packages/protocol/src/types.ts:83
HTTPS URL for the capabilities document (cu tag).
domain
Section titled “domain”domain: string;Defined in: packages/protocol/src/types.ts:65
FQDN of the DNSid identity. Normalized with normalizeFQDN on construction.
ekUrl?
Section titled “ekUrl?”optional ekUrl?: string;Defined in: packages/protocol/src/types.ts:77
HTTPS URL for the accountable-entity JWKS endpoint (ek tag). Required for draft-01 publishing.
governanceId
Section titled “governanceId”governanceId: string;Defined in: packages/protocol/src/types.ts:67
Registrant domain (gi tag).
kuUrl?
Section titled “kuUrl?”optional kuUrl?: string;Defined in: packages/protocol/src/types.ts:79
HTTPS URL for the identity’s operational/runtime JWKS endpoint (ku tag). Required for draft-01 publishing.
logRef
Section titled “logRef”logRef: string;Defined in: packages/protocol/src/types.ts:69
Log reference for the lr tag. Format: {method}:{entry-ref}.
maxKeyAge?
Section titled “maxKeyAge?”optional maxKeyAge?: MaxKeyAge;Defined in: packages/protocol/src/types.ts:75
Maximum signing key age for the ka tag.
policyFlags?
Section titled “policyFlags?”optional policyFlags?: string;Defined in: packages/protocol/src/types.ts:73
Comma-separated policy flags for the fl tag.
publishProfile?
Section titled “publishProfile?”optional publishProfile?: string;Defined in: packages/protocol/src/types.ts:81
_dnsid behavior profile to emit. Defaults to dnsid-draft-01.
statusUrl
Section titled “statusUrl”statusUrl: string;Defined in: packages/protocol/src/types.ts:71
HTTPS URL for the lifecycle status endpoint (su tag).
IdentityManagerDependencies
Section titled “IdentityManagerDependencies”Defined in: packages/protocol/src/identity-manager.ts:84
Runtime objects injected into IdentityManager. Configuration data lives in DnsidConfig.
Properties
Section titled “Properties”cache?
Section titled “cache?”optional cache?: IdentityCache;Defined in: packages/protocol/src/identity-manager.ts:91
dnsResolver?
Section titled “dnsResolver?”optional dnsResolver?: DNSResolver;Defined in: packages/protocol/src/identity-manager.ts:90
entityKeyProvider?
Section titled “entityKeyProvider?”optional entityKeyProvider?: KeyProvider;Defined in: packages/protocol/src/identity-manager.ts:88
Accountable-entity key provider for _dnsid signing and lifecycle events. Rejected without config.identity.
fetchJson?
Section titled “fetchJson?”optional fetchJson?: JsonFetcher;Defined in: packages/protocol/src/identity-manager.ts:92
keyProvider?
Section titled “keyProvider?”optional keyProvider?: KeyProvider;Defined in: packages/protocol/src/identity-manager.ts:86
Local operational signer. Required with config.identity; rejected without it.
logRegistry?
Section titled “logRegistry?”optional logRegistry?: LogRegistry;Defined in: packages/protocol/src/identity-manager.ts:89
IdentityResolver
Section titled “IdentityResolver”Defined in: packages/protocol/src/identity-manager.ts:95
Extended by
Section titled “Extended by”Methods
Section titled “Methods”verifyDomain()
Section titled “verifyDomain()”verifyDomain( domain, peerCert?, options?): Promise<VerifiedDomain>;Defined in: packages/protocol/src/identity-manager.ts:96
Parameters
Section titled “Parameters”domain
Section titled “domain”string
peerCert?
Section titled “peerCert?”options?
Section titled “options?”Returns
Section titled “Returns”Promise<VerifiedDomain>
IssuanceEvent
Section titled “IssuanceEvent”Defined in: packages/protocol/src/log-events.ts:28
Extends
Section titled “Extends”BaseLogEvent
Extended by
Section titled “Extended by”Properties
Section titled “Properties”domain
Section titled “domain”domain: string;Defined in: packages/protocol/src/log-events.ts:30
entityKey?
Section titled “entityKey?”optional entityKey?: IssuanceKeySlot;Defined in: packages/protocol/src/log-events.ts:46
Accountable-entity record-signing key (ek) recorded in the event.
entitySig?
Section titled “entitySig?”optional entitySig?: string;Defined in: packages/protocol/src/log-events.ts:50
Entity-key signature over the canonical binding (base64url).
governanceId
Section titled “governanceId”governanceId: string;Defined in: packages/protocol/src/log-events.ts:31
initialEntityAlg?
Section titled “initialEntityAlg?”optional initialEntityAlg?: string;Defined in: packages/protocol/src/log-events.ts:39
initialEntityKid?
Section titled “initialEntityKid?”optional initialEntityKid?: string;Defined in: packages/protocol/src/log-events.ts:38
c2sp-tlog encoding of the accountable entity key.
initialEntityPublicKey?
Section titled “initialEntityPublicKey?”optional initialEntityPublicKey?: DnsIdJWK;Defined in: packages/protocol/src/log-events.ts:40
initialEntityThumbprint?
Section titled “initialEntityThumbprint?”optional initialEntityThumbprint?: string;Defined in: packages/protocol/src/log-events.ts:41
initialOperationalAlg?
Section titled “initialOperationalAlg?”optional initialOperationalAlg?: string;Defined in: packages/protocol/src/log-events.ts:34
initialOperationalKid?
Section titled “initialOperationalKid?”optional initialOperationalKid?: string;Defined in: packages/protocol/src/log-events.ts:33
c2sp-tlog encoding of the initial operational key.
initialOperationalPublicKey?
Section titled “initialOperationalPublicKey?”optional initialOperationalPublicKey?: DnsIdJWK;Defined in: packages/protocol/src/log-events.ts:35
initialOperationalThumbprint?
Section titled “initialOperationalThumbprint?”optional initialOperationalThumbprint?: string;Defined in: packages/protocol/src/log-events.ts:36
optional kid?: string;Defined in: packages/protocol/src/log-events.ts:56
Deprecated
Section titled “Deprecated”superseded by operationalKey/entityKey.
newOperationalProof?
Section titled “newOperationalProof?”optional newOperationalProof?: string;Defined in: packages/protocol/src/log-events.ts:13
Base64url new-operational-key proof of possession. Required for c2sp-tlog KEY_ROTATION.
Inherited from
Section titled “Inherited from”BaseLogEvent.newOperationalProofoperationalCountersig?
Section titled “operationalCountersig?”optional operationalCountersig?: string;Defined in: packages/protocol/src/log-events.ts:11
Base64url operational-key countersignature. Required for draft-01 ISSUANCE.
Inherited from
Section titled “Inherited from”BaseLogEvent.operationalCountersigoperationalKey?
Section titled “operationalKey?”optional operationalKey?: IssuanceKeySlot;Defined in: packages/protocol/src/log-events.ts:48
Initial operational key (ku) recorded in the event.
operationalSig?
Section titled “operationalSig?”optional operationalSig?: string;Defined in: packages/protocol/src/log-events.ts:52
Operational-key countersignature over the same canonical binding (base64url).
publicKey?
Section titled “publicKey?”optional publicKey?: DnsIdJWK;Defined in: packages/protocol/src/log-events.ts:58
Deprecated
Section titled “Deprecated”superseded by operationalKey/entityKey.
optional sig?: string;Defined in: packages/protocol/src/log-events.ts:9
Base64url signature. Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”BaseLogEvent.sigsigningKid?
Section titled “signingKid?”optional signingKid?: string;Defined in: packages/protocol/src/log-events.ts:7
Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”BaseLogEvent.signingKidthumbprint?
Section titled “thumbprint?”optional thumbprint?: string;Defined in: packages/protocol/src/log-events.ts:60
Deprecated
Section titled “Deprecated”superseded by the slot thumbprints.
timestamp
Section titled “timestamp”timestamp: Date;Defined in: packages/protocol/src/log-events.ts:42
type: "ISSUANCE";Defined in: packages/protocol/src/log-events.ts:29
IssuanceKeySlot
Section titled “IssuanceKeySlot”Defined in: packages/protocol/src/log-events.ts:19
A key slot recorded in a draft-01 bilateral ISSUANCE event (ek or ku).
Properties
Section titled “Properties”alg: string;Defined in: packages/protocol/src/log-events.ts:25
JWS alg the slot’s signature is produced/verified under.
jwk: DnsIdJWK;Defined in: packages/protocol/src/log-events.ts:20
optional kid?: string;Defined in: packages/protocol/src/log-events.ts:23
thumbprint
Section titled “thumbprint”thumbprint: string;Defined in: packages/protocol/src/log-events.ts:22
RFC 7638 JWK thumbprint of jwk.
JsonFetchOptions
Section titled “JsonFetchOptions”Defined in: packages/protocol/src/identity-manager.ts:74
Properties
Section titled “Properties”allowedHost?
Section titled “allowedHost?”optional allowedHost?: string;Defined in: packages/protocol/src/identity-manager.ts:76
domainBoundary?
Section titled “domainBoundary?”optional domainBoundary?: boolean;Defined in: packages/protocol/src/identity-manager.ts:77
maxResponseBytes?
Section titled “maxResponseBytes?”optional maxResponseBytes?: number;Defined in: packages/protocol/src/identity-manager.ts:78
signal?
Section titled “signal?”optional signal?: AbortSignal;Defined in: packages/protocol/src/identity-manager.ts:75
KeyProvider
Section titled “KeyProvider”Defined in: packages/protocol/src/key-provider.ts:14
Standardized interface for Key Management Systems.
Implementations may wrap local key files, cloud KMS (AWS KMS, GCP Cloud KMS, Azure Key Vault), or HSMs. The SDK never handles private key material directly.
Key states:
- Pending: generated but not yet promoted (excluded from ListKeyIds / JWKS)
- Active: current signing key (in JWKS; used for signing)
- Retained: rotated out; kept for verification/audit (not used for new signing)
Methods
Section titled “Methods”activate()
Section titled “activate()”activate(kid): Promise<void>;Defined in: packages/protocol/src/key-provider.ts:55
Promotes a pending key to active. The previously active key transitions to retained.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”Promise<void>
generateKey()
Section titled “generateKey()”generateKey(): Promise<string>;Defined in: packages/protocol/src/key-provider.ts:50
Generates a new key pair in the pending state. Returns the new key’s kid.
Returns
Section titled “Returns”Promise<string>
jwk(kid): Promise<DnsIdJWK>;Defined in: packages/protocol/src/key-provider.ts:27
Returns the JWK representation of a key by ID (active, pending, or retained). Raises if not found.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”Promise<DnsIdJWK>
listKeyIds()
Section titled “listKeyIds()”listKeyIds(): Promise<string[]>;Defined in: packages/protocol/src/key-provider.ts:33
Returns the IDs of all active and retained keys (pending keys excluded). The active key ID MUST appear first; retained keys follow in any order.
Returns
Section titled “Returns”Promise<string[]>
purge()?
Section titled “purge()?”optional purge(kid): Promise<void>;Defined in: packages/protocol/src/key-provider.ts:63
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”Promise<void>
Deprecated
Section titled “Deprecated”Use supersede().
sign()
Section titled “sign()”sign(payload): Promise<Uint8Array<ArrayBufferLike>>;Defined in: packages/protocol/src/key-provider.ts:39
Signs the given payload with the current active signing key. Returns raw signature bytes.
Parameters
Section titled “Parameters”payload
Section titled “payload”Uint8Array
Returns
Section titled “Returns”Promise<Uint8Array<ArrayBufferLike>>
signingKey()
Section titled “signingKey()”signingKey(): Promise<DnsIdJWK>;Defined in: packages/protocol/src/key-provider.ts:21
Returns the JWK representation of the current active public signing key. The returned kid MUST NOT contain ’#’.
Returns
Section titled “Returns”Promise<DnsIdJWK>
signKey()
Section titled “signKey()”signKey(kid, payload): Promise<Uint8Array<ArrayBufferLike>>;Defined in: packages/protocol/src/key-provider.ts:42
Signs with a specified active or pending key.
Parameters
Section titled “Parameters”string
payload
Section titled “payload”Uint8Array
Returns
Section titled “Returns”Promise<Uint8Array<ArrayBufferLike>>
supersede()
Section titled “supersede()”supersede(kid): Promise<void>;Defined in: packages/protocol/src/key-provider.ts:60
Supersedes and removes a retained key from this provider’s published key set.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”Promise<void>
KeyRotationEvent
Section titled “KeyRotationEvent”Defined in: packages/protocol/src/log-events.ts:75
Extends
Section titled “Extends”BaseLogEvent
Properties
Section titled “Properties”domain
Section titled “domain”domain: string;Defined in: packages/protocol/src/log-events.ts:77
newOperationalAlg
Section titled “newOperationalAlg”newOperationalAlg: string;Defined in: packages/protocol/src/log-events.ts:81
newOperationalKid
Section titled “newOperationalKid”newOperationalKid: string;Defined in: packages/protocol/src/log-events.ts:80
newOperationalProof?
Section titled “newOperationalProof?”optional newOperationalProof?: string;Defined in: packages/protocol/src/log-events.ts:13
Base64url new-operational-key proof of possession. Required for c2sp-tlog KEY_ROTATION.
Inherited from
Section titled “Inherited from”BaseLogEvent.newOperationalProofnewOperationalPublicKey
Section titled “newOperationalPublicKey”newOperationalPublicKey: DnsIdJWK;Defined in: packages/protocol/src/log-events.ts:83
newOperationalThumbprint
Section titled “newOperationalThumbprint”newOperationalThumbprint: string;Defined in: packages/protocol/src/log-events.ts:82
operationalCountersig?
Section titled “operationalCountersig?”optional operationalCountersig?: string;Defined in: packages/protocol/src/log-events.ts:11
Base64url operational-key countersignature. Required for draft-01 ISSUANCE.
Inherited from
Section titled “Inherited from”BaseLogEvent.operationalCountersigpreviousOperationalKid
Section titled “previousOperationalKid”previousOperationalKid: string;Defined in: packages/protocol/src/log-events.ts:78
previousOperationalThumbprint
Section titled “previousOperationalThumbprint”previousOperationalThumbprint: string;Defined in: packages/protocol/src/log-events.ts:79
optional sig?: string;Defined in: packages/protocol/src/log-events.ts:9
Base64url signature. Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”BaseLogEvent.sigsigningKid?
Section titled “signingKid?”optional signingKid?: string;Defined in: packages/protocol/src/log-events.ts:7
Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”BaseLogEvent.signingKidtimestamp
Section titled “timestamp”timestamp: Date;Defined in: packages/protocol/src/log-events.ts:84
type: "KEY_ROTATION";Defined in: packages/protocol/src/log-events.ts:76
Defined in: packages/protocol/src/log.ts:33
Write interface for the agent’s own immutable log. Implementations may wrap a blockchain, CT-style transparency log, SCITT service, or any append-only log.
Implementations may satisfy both Log and LogReader; C2SP uses a separate prepared-event append workflow instead of the generic writeEvent method.
Methods
Section titled “Methods”canonical()
Section titled “canonical()”canonical(event): Promise<Uint8Array<ArrayBufferLike>>;Defined in: packages/protocol/src/log.ts:39
Returns the canonical byte representation of the event for this log method. Called by IdentityManager.signAndWriteEvent to produce the bytes that are signed. MUST produce identical output to LogReader.canonical for the same event.
Parameters
Section titled “Parameters”Returns
Section titled “Returns”Promise<Uint8Array<ArrayBufferLike>>
writeEvent()
Section titled “writeEvent()”writeEvent(event): Promise<string>;Defined in: packages/protocol/src/log.ts:46
Appends a signed event to the log. The event MUST already carry the signatures required by its log method before writeEvent is called. Returns a LogRef identifying the recorded entry.
Parameters
Section titled “Parameters”Returns
Section titled “Returns”Promise<string>
LoggedStateEvidence
Section titled “LoggedStateEvidence”Defined in: packages/protocol/src/log.ts:7
Verified proof boundary accepted for a complete lifecycle-state decision.
Properties
Section titled “Properties”checkpoint
Section titled “checkpoint”checkpoint: Uint8Array;Defined in: packages/protocol/src/log.ts:21
Opaque accepted checkpoint or equivalent log-state evidence.
completenessMode
Section titled “completenessMode”completenessMode: string;Defined in: packages/protocol/src/log.ts:19
Binding-defined completeness mechanism.
completeThrough
Section titled “completeThrough”completeThrough: string;Defined in: packages/protocol/src/log.ts:17
Opaque method-specific position through which completeness was established.
freshnessTime
Section titled “freshnessTime”freshnessTime: Date;Defined in: packages/protocol/src/log.ts:23
Independently verified freshness time.
historyEnd?
Section titled “historyEnd?”optional historyEnd?: string;Defined in: packages/protocol/src/log.ts:15
Method-specific final applied event reference, when one exists.
historyStart
Section titled “historyStart”historyStart: string;Defined in: packages/protocol/src/log.ts:13
Method-specific genesis reference included in the verified history.
loggedState
Section titled “loggedState”loggedState: AgentStatusState;Defined in: packages/protocol/src/log.ts:11
Verified lifecycle state through historyEnd, not current protocol status.
logReference
Section titled “logReference”logReference: string;Defined in: packages/protocol/src/log.ts:9
Complete identity-instance log reference verified by the binding.
LogReader
Section titled “LogReader”Defined in: packages/protocol/src/log.ts:57
Read and verify interface for a specific log entry.
Bound at construction to a full lr value (e.g. “algorand:AGENT_ADDR_BASE32”).
Evidence-returning methods MUST verify the applicable inclusion, timestamp,
append-only consistency, and lifecycle signatures before returning success.
canonical only serializes an event; it does not verify log evidence.
Methods
Section titled “Methods”canonical()
Section titled “canonical()”canonical(event): Promise<Uint8Array<ArrayBufferLike>>;Defined in: packages/protocol/src/log.ts:63
Returns the canonical byte representation of the event for this log method. Used to verify the signatures required by the log method on events read from the log. MUST produce identical output to Log.canonical for the same supported event.
Parameters
Section titled “Parameters”Returns
Section titled “Returns”Promise<Uint8Array<ArrayBufferLike>>
keyTimestamp()
Section titled “keyTimestamp()”keyTimestamp(domain, keyThumbprint): Promise<Date>;Defined in: packages/protocol/src/log.ts:69
Returns the timestamp at which the given key thumbprint was bound to the domain (ISSUANCE or KEY_ROTATION event). Used for ka validation.
Parameters
Section titled “Parameters”domain
Section titled “domain”string
keyThumbprint
Section titled “keyThumbprint”string
Returns
Section titled “Returns”Promise<Date>
readEvent()
Section titled “readEvent()”readEvent(ref): Promise<LogEvent>;Defined in: packages/protocol/src/log.ts:92
Reads a single event by its log reference. MUST verify inclusion proof and timestamp proof before returning.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”Promise<LogEvent>
rebuildHistory()
Section titled “rebuildHistory()”rebuildHistory(domain): Promise<LogEvent[]>;Defined in: packages/protocol/src/log.ts:102
Rebuilds the full event history for the domain in authoritative log order. MUST verify inclusion proofs, timestamp proofs, append-only consistency, and required lifecycle signatures on every returned event. Event signature verification MUST use the public keys valid for that event in the reconstructed lifecycle history. Events with invalid signatures MUST NOT be returned.
Parameters
Section titled “Parameters”domain
Section titled “domain”string
Returns
Section titled “Returns”Promise<LogEvent[]>
verifyBilateralBinding()
Section titled “verifyBilateralBinding()”verifyBilateralBinding( record, entityKey, operationalKey): Promise<{ initialEntityThumbprint: string; initialOperationalThumbprint: string; timestamp: Date;}>;Defined in: packages/protocol/src/log.ts:72
Verifies draft-01 bilateral ISSUANCE binding for the current TXT record.
Parameters
Section titled “Parameters”record
Section titled “record”unknown
entityKey
Section titled “entityKey”unknown
operationalKey
Section titled “operationalKey”unknown
Returns
Section titled “Returns”Promise<{
initialEntityThumbprint: string;
initialOperationalThumbprint: string;
timestamp: Date;
}>
verifyNonRevocation()
Section titled “verifyNonRevocation()”verifyNonRevocation(domain, at): Promise<LoggedStateEvidence>;Defined in: packages/protocol/src/log.ts:86
Verifies that the domain is neither REVOKED nor RETIRED at the given timestamp. Raises on a terminal state or if complete, fresh evidence cannot be established. Returns the accepted proof boundary.
Parameters
Section titled “Parameters”domain
Section titled “domain”string
Date
Returns
Section titled “Returns”Promise<LoggedStateEvidence>
verifyOperationalContinuity()
Section titled “verifyOperationalContinuity()”verifyOperationalContinuity( domain, initialOperationalThumbprint, currentOperationalThumbprint): Promise<void>;Defined in: packages/protocol/src/log.ts:79
Verifies KEY_ROTATION continuity from ISSUANCE to the current operational key.
Parameters
Section titled “Parameters”domain
Section titled “domain”string
initialOperationalThumbprint
Section titled “initialOperationalThumbprint”string
currentOperationalThumbprint
Section titled “currentOperationalThumbprint”string
Returns
Section titled “Returns”Promise<void>
MigrationEvent
Section titled “MigrationEvent”Defined in: packages/protocol/src/log-events.ts:100
Extends
Section titled “Extends”BaseLogEvent
Properties
Section titled “Properties”domain
Section titled “domain”domain: string;Defined in: packages/protocol/src/log-events.ts:102
finalEntryRef
Section titled “finalEntryRef”finalEntryRef: string;Defined in: packages/protocol/src/log-events.ts:105
newLog
Section titled “newLog”newLog: string;Defined in: packages/protocol/src/log-events.ts:104
newOperationalProof?
Section titled “newOperationalProof?”optional newOperationalProof?: string;Defined in: packages/protocol/src/log-events.ts:13
Base64url new-operational-key proof of possession. Required for c2sp-tlog KEY_ROTATION.
Inherited from
Section titled “Inherited from”BaseLogEvent.newOperationalProofoperationalCountersig?
Section titled “operationalCountersig?”optional operationalCountersig?: string;Defined in: packages/protocol/src/log-events.ts:11
Base64url operational-key countersignature. Required for draft-01 ISSUANCE.
Inherited from
Section titled “Inherited from”BaseLogEvent.operationalCountersigpreviousLog
Section titled “previousLog”previousLog: string;Defined in: packages/protocol/src/log-events.ts:103
optional sig?: string;Defined in: packages/protocol/src/log-events.ts:9
Base64url signature. Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”BaseLogEvent.sigsigningKid?
Section titled “signingKid?”optional signingKid?: string;Defined in: packages/protocol/src/log-events.ts:7
Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”BaseLogEvent.signingKidtimestamp
Section titled “timestamp”timestamp: Date;Defined in: packages/protocol/src/log-events.ts:106
type: "MIGRATION";Defined in: packages/protocol/src/log-events.ts:101
OperationalKeyRotationOptions
Section titled “OperationalKeyRotationOptions”Defined in: packages/protocol/src/identity-manager.ts:59
Properties
Section titled “Properties”publishKeySet
Section titled “publishKeySet”publishKeySet: (keySet) => Promise<void>;Defined in: packages/protocol/src/identity-manager.ts:61
Publishes the pending operational JWKS at the configured ku endpoint before continuity is appended.
Parameters
Section titled “Parameters”keySet
Section titled “keySet”Returns
Section titled “Returns”Promise<void>
timestamp?
Section titled “timestamp?”optional timestamp?: Date;Defined in: packages/protocol/src/identity-manager.ts:62
OperationalKeyRotationResult
Section titled “OperationalKeyRotationResult”Defined in: packages/protocol/src/identity-manager.ts:65
Properties
Section titled “Properties”event: KeyRotationEvent;Defined in: packages/protocol/src/identity-manager.ts:66
keySet
Section titled “keySet”keySet: JWKS;Defined in: packages/protocol/src/identity-manager.ts:68
logRef
Section titled “logRef”logRef: string;Defined in: packages/protocol/src/identity-manager.ts:67
RetirementEvent
Section titled “RetirementEvent”Defined in: packages/protocol/src/log-events.ts:94
Extends
Section titled “Extends”BaseLogEvent
Properties
Section titled “Properties”domain
Section titled “domain”domain: string;Defined in: packages/protocol/src/log-events.ts:96
newOperationalProof?
Section titled “newOperationalProof?”optional newOperationalProof?: string;Defined in: packages/protocol/src/log-events.ts:13
Base64url new-operational-key proof of possession. Required for c2sp-tlog KEY_ROTATION.
Inherited from
Section titled “Inherited from”BaseLogEvent.newOperationalProofoperationalCountersig?
Section titled “operationalCountersig?”optional operationalCountersig?: string;Defined in: packages/protocol/src/log-events.ts:11
Base64url operational-key countersignature. Required for draft-01 ISSUANCE.
Inherited from
Section titled “Inherited from”BaseLogEvent.operationalCountersigoptional sig?: string;Defined in: packages/protocol/src/log-events.ts:9
Base64url signature. Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”BaseLogEvent.sigsigningKid?
Section titled “signingKid?”optional signingKid?: string;Defined in: packages/protocol/src/log-events.ts:7
Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”BaseLogEvent.signingKidtimestamp
Section titled “timestamp”timestamp: Date;Defined in: packages/protocol/src/log-events.ts:97
type: "RETIREMENT";Defined in: packages/protocol/src/log-events.ts:95
RetryBackoffOptions
Section titled “RetryBackoffOptions”Defined in: packages/protocol/src/retry.ts:3
Properties
Section titled “Properties”initialDelayMs?
Section titled “initialDelayMs?”optional initialDelayMs?: number;Defined in: packages/protocol/src/retry.ts:7
Delay before the first retry. Default: 100ms.
jitter?
Section titled “jitter?”optional jitter?: boolean;Defined in: packages/protocol/src/retry.ts:13
Apply full jitter in the range [0, delay]. Default: true.
maxAttempts?
Section titled “maxAttempts?”optional maxAttempts?: number;Defined in: packages/protocol/src/retry.ts:5
Total attempts including the initial call. Default: 3.
maxDelayMs?
Section titled “maxDelayMs?”optional maxDelayMs?: number;Defined in: packages/protocol/src/retry.ts:9
Maximum delay between attempts. Default: 2000ms.
multiplier?
Section titled “multiplier?”optional multiplier?: number;Defined in: packages/protocol/src/retry.ts:11
Exponential multiplier applied after each failed attempt. Default: 2.
shouldRetry?
Section titled “shouldRetry?”optional shouldRetry?: (error, attempt) => boolean;Defined in: packages/protocol/src/retry.ts:15
Optional policy override. Defaults to retrying transient VerificationError only.
Parameters
Section titled “Parameters”unknown
attempt
Section titled “attempt”number
Returns
Section titled “Returns”boolean
sleep?
Section titled “sleep?”optional sleep?: (ms) => Promise<void>;Defined in: packages/protocol/src/retry.ts:17
Test hook for sleeping.
Parameters
Section titled “Parameters”number
Returns
Section titled “Returns”Promise<void>
RevocationEvent
Section titled “RevocationEvent”Defined in: packages/protocol/src/log-events.ts:87
Extends
Section titled “Extends”BaseLogEvent
Properties
Section titled “Properties”domain
Section titled “domain”domain: string;Defined in: packages/protocol/src/log-events.ts:89
newOperationalProof?
Section titled “newOperationalProof?”optional newOperationalProof?: string;Defined in: packages/protocol/src/log-events.ts:13
Base64url new-operational-key proof of possession. Required for c2sp-tlog KEY_ROTATION.
Inherited from
Section titled “Inherited from”BaseLogEvent.newOperationalProofoperationalCountersig?
Section titled “operationalCountersig?”optional operationalCountersig?: string;Defined in: packages/protocol/src/log-events.ts:11
Base64url operational-key countersignature. Required for draft-01 ISSUANCE.
Inherited from
Section titled “Inherited from”BaseLogEvent.operationalCountersigreason
Section titled “reason”reason: | "keyCompromise" | "policyViolation" | "superseded" | "cessationOfOperation";Defined in: packages/protocol/src/log-events.ts:91
optional sig?: string;Defined in: packages/protocol/src/log-events.ts:9
Base64url signature. Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”BaseLogEvent.sigsigningKid?
Section titled “signingKid?”optional signingKid?: string;Defined in: packages/protocol/src/log-events.ts:7
Set by IdentityManager.signAndWriteEvent; leave undefined when constructing.
Inherited from
Section titled “Inherited from”BaseLogEvent.signingKidtimestamp
Section titled “timestamp”timestamp: Date;Defined in: packages/protocol/src/log-events.ts:90
type: "REVOCATION";Defined in: packages/protocol/src/log-events.ts:88
SigningIdentityManager
Section titled “SigningIdentityManager”Defined in: packages/protocol/src/identity-manager.ts:99
Extends
Section titled “Extends”Properties
Section titled “Properties”config
Section titled “config”config: object;Defined in: packages/protocol/src/identity-manager.ts:100
identity?
Section titled “identity?”optional identity?: object;identity.domain
Section titled “identity.domain”domain: string;Methods
Section titled “Methods”getKeyProvider()
Section titled “getKeyProvider()”getKeyProvider(): KeyProvider;Defined in: packages/protocol/src/identity-manager.ts:101
Returns
Section titled “Returns”verifyDomain()
Section titled “verifyDomain()”verifyDomain( domain, peerCert?, options?): Promise<VerifiedDomain>;Defined in: packages/protocol/src/identity-manager.ts:96
Parameters
Section titled “Parameters”domain
Section titled “domain”string
peerCert?
Section titled “peerCert?”options?
Section titled “options?”Returns
Section titled “Returns”Promise<VerifiedDomain>
Inherited from
Section titled “Inherited from”TLSCertificate
Section titled “TLSCertificate”Defined in: packages/protocol/src/types.ts:50
Properties
Section titled “Properties”notAfter
Section titled “notAfter”notAfter: Date;Defined in: packages/protocol/src/types.ts:51
san: string[];Defined in: packages/protocol/src/types.ts:52
TransportConfig
Section titled “TransportConfig”Defined in: packages/protocol/src/types.ts:105
SDK-managed DNS and HTTPS deployment settings (DnsidConfig.transport). Never alters protocol semantics.
Properties
Section titled “Properties”caBundlePath?
Section titled “caBundlePath?”optional caBundlePath?: string;Defined in: packages/protocol/src/types.ts:109
Path to a PEM CA bundle appended to the system root certificates for TLS verification.
dnsServer?
Section titled “dnsServer?”optional dnsServer?: string;Defined in: packages/protocol/src/types.ts:107
Custom DNS server (host, host:port, or [ipv6]:port). Omit to use the system resolver.
privateAddressHosts?
Section titled “privateAddressHosts?”optional privateAddressHosts?: readonly string[];Defined in: packages/protocol/src/types.ts:121
Hostnames, or leading-dot suffixes such as .test, whose SDK-managed HTTPS destinations may
resolve to loopback or private-use addresses. An exact entry matches only that name; .test
matches test and every name beneath it on a DNS-label boundary, case-insensitively and
ignoring a trailing dot. Link-local, multicast, reserved, and mixed public/private resolutions
stay rejected, IP-literal URLs are never exempted, and every redirect hop is matched
independently. Nothing is allowed by default; there is no built-in .test exemption. Entries
are validated at construction (IP literals, ports, schemes, paths, credentials → ArgumentError).
Applies only to the default fetcher; rejected when fetchJson is injected. Not a DNSid protocol
field.
TrustedEntity
Section titled “TrustedEntity”Defined in: packages/protocol/src/types.ts:87
One counterparty allowlist entry. Exact gi match; optional pins on the current record-signing key.
Properties
Section titled “Properties”entityKeyThumbprints?
Section titled “entityKeyThumbprints?”optional entityKeyThumbprints?: string[];Defined in: packages/protocol/src/types.ts:91
Unpadded base64url RFC 7638 SHA-256 thumbprints the current ek signing key must match. Non-empty when present.
governanceId
Section titled “governanceId”governanceId: string;Defined in: packages/protocol/src/types.ts:89
Accountable-entity governance domain. Normalized with normalizeFQDN on construction.
TXTRecord
Section titled “TXTRecord”Defined in: packages/protocol/src/types.ts:57
Properties
Section titled “Properties”strings
Section titled “strings”strings: string[];Defined in: packages/protocol/src/types.ts:58
ttl: number;Defined in: packages/protocol/src/types.ts:59
VerificationConfig
Section titled “VerificationConfig”Defined in: packages/protocol/src/types.ts:95
Protocol verification and counterparty acceptance settings (DnsidConfig.verification).
Properties
Section titled “Properties”dnssecMode?
Section titled “dnssecMode?”optional dnssecMode?: DNSSECMode;Defined in: packages/protocol/src/types.ts:99
DNSSEC enforcement mode. Default: ‘auto’.
statusCheckInterval?
Section titled “statusCheckInterval?”optional statusCheckInterval?: number;Defined in: packages/protocol/src/types.ts:97
Maximum age (seconds) of cached status before re-fetching su. Default: 0 (re-fetch every call).
trustedEntities?
Section titled “trustedEntities?”optional trustedEntities?: TrustedEntity[];Defined in: packages/protocol/src/types.ts:101
Counterparty allowlist. Absent: no acceptance decision. []: deny all.
VerificationOptions
Section titled “VerificationOptions”Defined in: packages/protocol/src/verification-budget.ts:3
Properties
Section titled “Properties”signal?
Section titled “signal?”optional signal?: AbortSignal;Defined in: packages/protocol/src/verification-budget.ts:6
timeoutMs?
Section titled “timeoutMs?”optional timeoutMs?: number;Defined in: packages/protocol/src/verification-budget.ts:5
Overall invocation budget, including all discovery and evidence. Default: 30 seconds.