C8Human Guide

Source-qualified discovery inventory

Keys cryptography

Logical Keys, identifiers, cryptographic components, algorithms, purposes, prohibitions, and custody.

Open raw data editor03-keys-cryptography.json

Document context

How to read this page

Every value below mirrors the JSON document. Friendly labels and explanations add context without replacing the exact field name or recorded value. Follow any “raw record” link to inspect or edit the same data.

Schema versionschema_version

Version of the discovery-inventory document shape.

0.1.0
Catalogue statuscatalogue_status

Maturity of this catalogue data, not implementation status.

discovery_inventory
Authorityauthority

How this document may be used and what it must not be mistaken for.

Evidence-derived inventory; not a final implementation-governing SSOT. Preserve source modality and consult conflicts.json.
Categorycategory

Stable subject area used to organize the inventory.

keys_cryptography
Descriptiondescription

Human-language explanation preserved by the inventory.

Logical Keys, identifiers, cryptographic components, algorithms, purposes, prohibitions, and custody.

Structured collection

Items

8 top-level entries. Nested values are expanded inside each entry.

Open this raw section →

Security principal

Logical CRE8 Key

Open editable raw record →

Logical principal comprising a public Credential ID plus four purpose-separated keypairs.

What this represents

This entry is recorded as Security principal in the Items section.

Statement status: Source description

This records how the historical source describes the system.

IdidStable catalogue identity. Ordinary edits should preserve it.
key.logical
NamenameRecorded inventory field; its exact name and structure are preserved.
Logical CRE8 Key
KindkindStructural role of this entry within the catalogue.
security_principal
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Logical principal comprising a public Credential ID plus four purpose-separated keypairs.
ModalitymodalityStrength or status of the source statement.
source_description
SubcomponentssubcomponentsRecorded inventory field; its exact name and structure are preserved.
  1. Credential ID
  2. Authentication keypair
  3. Delegation keypair
  4. Authorship keypair
  5. Confidentiality/Box keypair

Public identifier

Credential ID

Open editable raw record →

Random immutable public identifier used to locate the logical Key, versions, public keys, status, policy, lineage, and historical signatures; never a bearer secret.

What this represents

This entry is recorded as Public identifier in the Items section.

Statement status: Explicit immutable

The source explicitly presents this as immutable or non-configurable.

IdidStable catalogue identity. Ordinary edits should preserve it.
key.credential_id
NamenameRecorded inventory field; its exact name and structure are preserved.
Credential ID
KindkindStructural role of this entry within the catalogue.
public_identifier
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Random immutable public identifier used to locate the logical Key, versions, public keys, status, policy, lineage, and historical signatures; never a bearer secret.
ModalitymodalityStrength or status of the source statement.
explicit_immutable
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Credential_Payload.txtlines 145-163 · open exact evidence
ExampleexampleRecorded inventory field; its exact name and structure are preserved.
cre8_k_7PK1BHZ4...

Cryptographic component

Authentication keypair

Open editable raw record →

Ed25519 K_auth pair for request signing and possession proof; binds method, path, body digest, timestamp, nonce, and Credential ID. Cannot mint, change permission, author-sign, or decrypt.

What this represents

This entry is recorded as Cryptographic component in the Items section.

Statement status: Source description

This records how the historical source describes the system.

IdidStable catalogue identity. Ordinary edits should preserve it.
key.authentication
NamenameRecorded inventory field; its exact name and structure are preserved.
Authentication keypair
KindkindStructural role of this entry within the catalogue.
cryptographic_component
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Ed25519 K_auth pair for request signing and possession proof; binds method, path, body digest, timestamp, nonce, and Credential ID. Cannot mint, change permission, author-sign, or decrypt.
ModalitymodalityStrength or status of the source statement.
source_description
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Credential_Payload.txtlines 5-23 · open exact evidence
AlgorithmalgorithmRecorded inventory field; its exact name and structure are preserved.
Ed25519
FieldsfieldsRecorded inventory field; its exact name and structure are preserved.
  1. K_auth_private
  2. K_auth_public

Cryptographic component

Delegation keypair

Open editable raw record →

Ed25519 K_delegate pair for child minting, permissions, reductions, rotation, suspension/revocation requests; alone cannot perform ordinary operations, publish, or decrypt.

What this represents

This entry is recorded as Cryptographic component in the Items section.

Statement status: Source description

This records how the historical source describes the system.

IdidStable catalogue identity. Ordinary edits should preserve it.
key.delegation
NamenameRecorded inventory field; its exact name and structure are preserved.
Delegation keypair
KindkindStructural role of this entry within the catalogue.
cryptographic_component
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Ed25519 K_delegate pair for child minting, permissions, reductions, rotation, suspension/revocation requests; alone cannot perform ordinary operations, publish, or decrypt.
ModalitymodalityStrength or status of the source statement.
source_description
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Credential_Payload.txtlines 40-58 · open exact evidence
AlgorithmalgorithmRecorded inventory field; its exact name and structure are preserved.
Ed25519
FieldsfieldsRecorded inventory field; its exact name and structure are preserved.
  1. K_delegate_private
  2. K_delegate_public

Cryptographic component

Authorship keypair

Open editable raw record →

Ed25519 K_author pair for signed objects, credentials/statements, versions, amendments, co-signatures, and provenance.

What this represents

This entry is recorded as Cryptographic component in the Items section.

Statement status: Source description

This records how the historical source describes the system.

IdidStable catalogue identity. Ordinary edits should preserve it.
key.authorship
NamenameRecorded inventory field; its exact name and structure are preserved.
Authorship keypair
KindkindStructural role of this entry within the catalogue.
cryptographic_component
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Ed25519 K_author pair for signed objects, credentials/statements, versions, amendments, co-signatures, and provenance.
ModalitymodalityStrength or status of the source statement.
source_description
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Credential_Payload.txtlines 75-93 · open exact evidence
AlgorithmalgorithmRecorded inventory field; its exact name and structure are preserved.
Ed25519
FieldsfieldsRecorded inventory field; its exact name and structure are preserved.
  1. K_author_private
  2. K_author_public

Cryptographic component

Confidentiality/Box keypair

Open editable raw record →

X25519 K_box pair for encrypted messages/shares/keyring packages and shared secrets; cannot authenticate, sign, mint, or change policy.

What this represents

This entry is recorded as Cryptographic component in the Items section.

Statement status: Source description

This records how the historical source describes the system.

IdidStable catalogue identity. Ordinary edits should preserve it.
key.box
NamenameRecorded inventory field; its exact name and structure are preserved.
Confidentiality/Box keypair
KindkindStructural role of this entry within the catalogue.
cryptographic_component
DescriptiondescriptionHuman-language explanation preserved by the inventory.
X25519 K_box pair for encrypted messages/shares/keyring packages and shared secrets; cannot authenticate, sign, mint, or change policy.
ModalitymodalityStrength or status of the source statement.
source_description
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Credential_Payload.txtlines 110-128 · open exact evidence
AlgorithmalgorithmRecorded inventory field; its exact name and structure are preserved.
X25519
FieldsfieldsRecorded inventory field; its exact name and structure are preserved.
  1. K_box_private
  2. K_box_public

Client payload

Nine-field credential bundle

Open editable raw record →

Credential ID and eight private/public component values; legacy field naming conflicts with purpose-oriented K_auth/K_delegate/K_author/K_box names.

What this represents

This entry is recorded as Client payload in the Items section.

Statement status: Source description

This records how the historical source describes the system.

IdidStable catalogue identity. Ordinary edits should preserve it.
key.bundle
NamenameRecorded inventory field; its exact name and structure are preserved.
Nine-field credential bundle
KindkindStructural role of this entry within the catalogue.
client_payload
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Credential ID and eight private/public component values; legacy field naming conflicts with purpose-oriented K_auth/K_delegate/K_author/K_box names.
ModalitymodalityStrength or status of the source statement.
source_description
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Description.txtlines 55-65 · open exact evidence
Legacy fieldslegacy_fieldsRecorded inventory field; its exact name and structure are preserved.
  1. credential_id
  2. assertion_private_key
  3. assertion_public_key
  4. delegation_private_key
  5. delegation_public_key
  6. access_private_key
  7. access_public_key
  8. control_private_key
  9. control_public_key

Security boundary

Client private-key custody

Open editable raw record →

Server should never persist CRE8/long-lived Author private keys; client custody and component-limited blast radius are central.

What this represents

This entry is recorded as Security boundary in the Items section.

Statement status: Explicit immutable

The source explicitly presents this as immutable or non-configurable.

IdidStable catalogue identity. Ordinary edits should preserve it.
key.private_custody
NamenameRecorded inventory field; its exact name and structure are preserved.
Client private-key custody
KindkindStructural role of this entry within the catalogue.
security_boundary
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Server should never persist CRE8/long-lived Author private keys; client custody and component-limited blast radius are central.
ModalitymodalityStrength or status of the source statement.
explicit_immutable