Skip to content

Glossary

TermMeaning
Auth planeA boundary for one kind of authority, such as app login, Wallet Session, capability grant, delegation grant, or API credential.
CredentialA proof input used by policy, such as passkey, Email OTP, VoiceID, device proof, org role proof, wallet proof, or configured external credential.
Deriver A / Deriver BSplit server roles used during derivation-time operations such as registration, export, refresh, recovery, and activation.
Delegated-agent laneA distinct signing lane issued to an agent or service under policy.
Holder shareThe user, device, agent, or auth-method side of a threshold key.
Linked-device laneA distinct signing lane issued to another user-controlled device.
MandateA scoped, signed authority object that defines what a subject may do under policy.
Policy epochVersioned policy state used for revocation-sensitive decisions.
RouterThe public service boundary for auth, policy, replay, quota, budget, and request routing.
Server shareThe hosted or self-hosted server side of a threshold key.
SigningWorkerThe hot normal-signing server role that uses activated server signing material.
Wallet Session quotaA bounded reusable allowance with TTL and remaining uses for signing.
Capability grantOne-operation authority bound to an exact capability and intent.
Signing laneThe exact signing capability selected for one operation.
Signed mandateA user, org, wallet, device, or agent authority object bound to policy.
Streaming YaoThe fixed-circuit two-party computation used by Deriver A and Deriver B for Ed25519 lifecycle ceremonies. Garbled tables stream directly from A to B.
Threshold sessionCurve/session-specific signing authority.
Typed intent digestCanonical digest of the exact action being approved or executed.
Wallet SessionA wallet-user operation authority used by signing and budget routes.