# Bounded Authority Protocol v0.1.1 - Table of Contents

> Deterministic protocol verification for cryptographically bounded proof-of-possession authority.

## Pages

- [bounded_authority_protocol](readme.md)
- [Changelog](changelog.md)
- [LICENSE](license.md)
- [NOTICE](notice.md)
- [Security policy](security.md)
- [Usage rules](usage-rules.md)
- [Bounded Authority Protocol v1 wire profile](protocol-v1.md)
- [Release-candidate contract](release-candidate-contract.md)
- [1. Public protocol verifier and private authority runtime](0001-public-protocol-verifier-boundary.md)
- [ADR 0002: Normative v1 parsing profile](0002-normative-v1-parsing-profile.md)
- [ADR 0003: Standard JWS signing and verified grant facts](0003-standard-jws-and-verified-grant-results.md)
- [ADR 0004: Consumption-chain rollover and anchored-export verification](0004-consumption-chain-rollover-and-anchored-export-verification.md)
- [ADR 0005: Portable conformance corpus and verifier CLI](0005-portable-conformance-corpus-and-verifier-cli.md)
- [ADR 0006: Standards evolution, suite identity, and delegation posture](0006-standards-evolution-suite-identity-and-delegation-posture.md)
- [ADR 0007: Normative requirement identifiers](0007-normative-requirement-identifiers.md)
- [ADR 0008: Release-candidate contract](0008-release-candidate-contract.md)
- [ADR 0009: Cryptographic suite succession and cross-suite evidence longevity](0009-cryptographic-suite-succession-and-cross-suite-evidence-longevity.md)
- [ADR 0010: Delegation with attenuation](0010-delegation-with-attenuation.md)
- [ADR 0011: Published governance](0011-published-governance.md)
- [ADR 0012: Security-release accelerated deprecation window](0012-security-release-accelerated-deprecation-window.md)
- [ADR 0013: Capability-authorization extension proposal](0013-capability-authorization-extension.md)
- [ADR 0014: Cross-language verifier SDKs](0014-cross-language-verifier-sdks.md)
- [ADR 0015: SDK graduation and publish topology](0015-sdk-graduation-and-publish-topology.md)
- [ADR 0016: Offline-eligible grant claims (floor limits + freshness bound)](0016-offline-eligible-grant-claims.md)
- [ADR 0017: Inter-SDK behavioral contract — fail-closure, type strictness, pre-hash validation](0017-inter-sdk-behavioral-contract.md)
- [ADR 0018: SDK bounds contract — caller-tightenable limits through the expected structs](0018-sdk-bounds-contract.md)
- [ADR 0019: Corpus artifact distribution — per-SDK binding until first graduation](0019-corpus-artifact-distribution.md)
- [ADR 0020: Bounds-aware assembly and issuer-mediated reauthorization posture](0020-bounds-aware-assembly-and-issuer-reauthorization-posture.md)
- [Errata registry](errata.md)
- [Governance policy](governance.md)
- [Conformance contract](conformance-contract.md)
- [Offline authorization — protocol requirements (BAP side)](offline-authorization-requirements.md)
- [Protocol charter](protocol-charter.md)
- [Protocol registries](registries.md)
- [BAP-10 requirement-to-conformance map](requirement-map.md)
- [Standards track charter](standards-track.md)
- [Threat model](threat-model.md)

## Modules

- [BoundedAuthorityProtocol](BoundedAuthorityProtocol.md): Deterministic protocol verification for cryptographically bounded
proof-of-possession authority.
- [BoundedAuthorityProtocol.Conformance.Cli](BoundedAuthorityProtocol.Conformance.Cli.md): Deterministic offline verifier CLI for the v1 conformance corpus.
- [BoundedAuthorityProtocol.Conformance.Corpus](BoundedAuthorityProtocol.Conformance.Corpus.md): Pure loader and integrity verifier for the portable conformance corpus.
- [BoundedAuthorityProtocol.Conformance.Report](BoundedAuthorityProtocol.Conformance.Report.md): Pure report builder for the loaded corpus and runner results.
- [BoundedAuthorityProtocol.Conformance.Runner](BoundedAuthorityProtocol.Conformance.Runner.md): Pure case executor for the loaded corpus.
- [BoundedAuthorityProtocol.V1](BoundedAuthorityProtocol.V1.md): Explicit entry point for the immutable v1 wire profile.
- [BoundedAuthorityProtocol.V1.AnchorFacts](BoundedAuthorityProtocol.V1.AnchorFacts.md): Closed redacted non-authorizing historical-anchor facts.
- [BoundedAuthorityProtocol.V1.AnchoredExportFacts](BoundedAuthorityProtocol.V1.AnchoredExportFacts.md): Closed redacted non-authorizing atomic anchored-export facts.
- [BoundedAuthorityProtocol.V1.AnchoredExportInput](BoundedAuthorityProtocol.V1.AnchoredExportInput.md): Raw rows and compact JWS values presented for deterministic archive framing.
- [BoundedAuthorityProtocol.V1.ArchivedObject](BoundedAuthorityProtocol.V1.ArchivedObject.md): Raw stored-object chunks and exact observed object-store version.
- [BoundedAuthorityProtocol.V1.Base64Url](BoundedAuthorityProtocol.V1.Base64Url.md): Strict bounded canonical base64url decoding for v1.
- [BoundedAuthorityProtocol.V1.BoundaryAnchor](BoundedAuthorityProtocol.V1.BoundaryAnchor.md): Closed deterministic boundary-anchor signing input.
- [BoundedAuthorityProtocol.V1.Bounds](BoundedAuthorityProtocol.V1.Bounds.md): Resource ceilings for the v1 wire profile.
- [BoundedAuthorityProtocol.V1.ChainFacts](BoundedAuthorityProtocol.V1.ChainFacts.md): Closed redacted non-authorizing consumption-chain facts.
- [BoundedAuthorityProtocol.V1.ChainInput](BoundedAuthorityProtocol.V1.ChainInput.md): Raw canonical consumption rows presented for chain verification.
- [BoundedAuthorityProtocol.V1.ConsumptionEntry](BoundedAuthorityProtocol.V1.ConsumptionEntry.md): Closed deterministic consumption-chain row producer input.
- [BoundedAuthorityProtocol.V1.Credentials](BoundedAuthorityProtocol.V1.Credentials.md): Closed raw compact grant and proof credentials.
- [BoundedAuthorityProtocol.V1.DecodedGrant](BoundedAuthorityProtocol.V1.DecodedGrant.md): Closed bounded decoded grant with explicitly unevaluated verification.
- [BoundedAuthorityProtocol.V1.DecodedProof](BoundedAuthorityProtocol.V1.DecodedProof.md): Closed bounded decoded proof with explicitly unevaluated verification.
- [BoundedAuthorityProtocol.V1.EncodedAnchoredExport](BoundedAuthorityProtocol.V1.EncodedAnchoredExport.md): Exact archive chunks, complete digest, and byte count from deterministic framing.
- [BoundedAuthorityProtocol.V1.EncodedConsumptionEntry](BoundedAuthorityProtocol.V1.EncodedConsumptionEntry.md): Exact canonical consumption row bytes and domain-separated row hash.
- [BoundedAuthorityProtocol.V1.EnvelopeFacts](BoundedAuthorityProtocol.V1.EnvelopeFacts.md): Closed value-bearing, redacted, non-authorizing verified envelope facts.
- [BoundedAuthorityProtocol.V1.ExpectedAnchor](BoundedAuthorityProtocol.V1.ExpectedAnchor.md): Exact expected context for one historical boundary anchor.
- [BoundedAuthorityProtocol.V1.ExpectedAnchoredExport](BoundedAuthorityProtocol.V1.ExpectedAnchoredExport.md): Mandatory caller context for atomic anchored-export verification.
- [BoundedAuthorityProtocol.V1.ExpectedChain](BoundedAuthorityProtocol.V1.ExpectedChain.md): Mandatory caller-derived boundaries for one nonempty consumption-chain range.
- [BoundedAuthorityProtocol.V1.ExpectedExport](BoundedAuthorityProtocol.V1.ExpectedExport.md): Exact semantic context required before deterministic archive framing.
- [BoundedAuthorityProtocol.V1.ExpectedGrant](BoundedAuthorityProtocol.V1.ExpectedGrant.md): Explicit expected context for standalone raw-grant verification.
- [BoundedAuthorityProtocol.V1.ExpectedKeyTransition](BoundedAuthorityProtocol.V1.ExpectedKeyTransition.md): Exact expected context for one authenticated historical-key transition.
- [BoundedAuthorityProtocol.V1.ExpectedRequest](BoundedAuthorityProtocol.V1.ExpectedRequest.md): Explicit expected context for combined raw-envelope verification.
- [BoundedAuthorityProtocol.V1.Grant](BoundedAuthorityProtocol.V1.Grant.md): Closed deterministic grant producer input.
- [BoundedAuthorityProtocol.V1.GrantFacts](BoundedAuthorityProtocol.V1.GrantFacts.md): Closed value-bearing, redacted, non-authorizing verified grant facts.
- [BoundedAuthorityProtocol.V1.HistoricalKeyChain](BoundedAuthorityProtocol.V1.HistoricalKeyChain.md): Ordered nonempty caller-supplied historical public-key chain.
- [BoundedAuthorityProtocol.V1.HistoricalPublicKey](BoundedAuthorityProtocol.V1.HistoricalPublicKey.md): One exact caller-supplied historical public key and validity window.
- [BoundedAuthorityProtocol.V1.Jcs](BoundedAuthorityProtocol.V1.Jcs.md): Bounded RFC 8785 serialization for the closed v1 tagged JSON algebra.

- [BoundedAuthorityProtocol.V1.Json](BoundedAuthorityProtocol.V1.Json.md): Bounded JSON decoder preserving object order and rejecting duplicate binary names.
- [BoundedAuthorityProtocol.V1.Jwk](BoundedAuthorityProtocol.V1.Jwk.md): Exact public Ed25519 JWK encoding, decoding, and RFC 7638 thumbprints.

- [BoundedAuthorityProtocol.V1.KeyLocator](BoundedAuthorityProtocol.V1.KeyLocator.md): An untrusted key identifier hint.
- [BoundedAuthorityProtocol.V1.KeyTransition](BoundedAuthorityProtocol.V1.KeyTransition.md): Closed deterministic historical-key transition signing input.
- [BoundedAuthorityProtocol.V1.KeyTransitionFacts](BoundedAuthorityProtocol.V1.KeyTransitionFacts.md): Closed redacted non-authorizing authenticated key-transition facts.
- [BoundedAuthorityProtocol.V1.Operation](BoundedAuthorityProtocol.V1.Operation.md): Closed producer input for one named operation and its ordered selectors.
- [BoundedAuthorityProtocol.V1.Proof](BoundedAuthorityProtocol.V1.Proof.md): Closed deterministic holder-proof producer input.
- [BoundedAuthorityProtocol.V1.Selector](BoundedAuthorityProtocol.V1.Selector.md): Closed selector type used by `BoundedAuthorityProtocol.V1.Operation`.
- [BoundedAuthorityProtocol.V1.SigningInput](BoundedAuthorityProtocol.V1.SigningInput.md): Closed deterministic standard-JWS signing input.
- [BoundedAuthorityProtocol.V1.TrustedIssuer](BoundedAuthorityProtocol.V1.TrustedIssuer.md): Caller-supplied already-trusted issuer key context.
- [BoundedAuthorityProtocol.V1.Uri](BoundedAuthorityProtocol.V1.Uri.md): Pure bounded normalization for hierarchical HTTPS DPoP target URIs.

