Bazaar.Signing.Key (Bazaar v0.3.0)

Copy Markdown View Source

A signing key for UCP HTTP message signatures: EC P-256 (ES256) or Ed25519 (EdDSA), as the spec allows.

Load one from a private JWK or PEM, or generate one for development:

key = Bazaar.Signing.Key.from_pem(File.read!("webhook_key.pem"))
key = Bazaar.Signing.Key.generate(:p256)

Publish its public half in the discovery profile's keys[]:

def business_profile, do: %{"keys" => [Bazaar.Signing.Key.public_jwk(key)]}

The kid defaults to the RFC 7638 thumbprint, so a key republishes under a stable identifier wherever it is loaded.

Summary

Functions

Loads a key from a JWK map. A private key carries d; without it the key can only verify.

Loads a private key from PEM (EC P-256 or Ed25519, SEC 1 or PKCS#8).

Generates a new key, :p256 or :ed25519.

The public JWK to publish in a profile's keys[].

Signs bytes. ES256 signatures are the fixed-width r || s form, not DER.

RFC 7638 thumbprint: required public members, sorted, hashed with SHA-256.

Verifies a signature produced by sign/2.

Types

t()

@type t() :: %Bazaar.Signing.Key{
  crv: String.t(),
  kid: String.t(),
  kty: String.t(),
  private: binary() | nil,
  public: binary()
}

Functions

from_jwk(jwk)

Loads a key from a JWK map. A private key carries d; without it the key can only verify.

from_pem(pem)

Loads a private key from PEM (EC P-256 or Ed25519, SEC 1 or PKCS#8).

generate(atom)

Generates a new key, :p256 or :ed25519.

public_jwk(key)

The public JWK to publish in a profile's keys[].

sign(key, message)

Signs bytes. ES256 signatures are the fixed-width r || s form, not DER.

thumbprint(key)

RFC 7638 thumbprint: required public members, sorted, hashed with SHA-256.

verify(key, message, signature)

Verifies a signature produced by sign/2.