Contents

Learn · 3 of 10

Identity: root, leaf, passkey

The person is the certificate authority. A root in the wallet issues a leaf to the host, and the root can be derived from a passkey instead of stored.

The wallet The host Passkey: the WebAuthn prf output HKDF · pact/root/1 Root key: Ed25519 self-signed Root certificate its fingerprint is the identity never rotated Host key: made by the host CSR: host key + endpoint to the wallet the leaf Leaf certificate one endpoint · at most 398 days signed by the root Contacts pin the root, and learn the current leaf from every exchange.
Two keys with two jobs. The root, in the wallet, issues certificates and nothing else; the leaf, at the host, is the key that speaks.

The root is the identity

An identity is a root certificate: self-signed X.509, its private key held by the person in a wallet and used for one thing, issuing certificates. The root’s fingerprint — sha256: and the base64url SHA-256 of its SubjectPublicKeyInfo — is the identity’s name everywhere: in pins, in envelopes, on screen (§ 2). A root is never rotated; its notAfter is RFC 5280’s “no well-defined expiration” (§ 14.1).

The leaf is how it speaks today, and from where

A host — the person’s own machine, or a provider — serves the identity under a leaf certificate the root issued. The leaf carries the host’s own key, the one address the identity answers at, and the dates between which the host’s authority runs: up to 398 days, one year by default, the span the person chooses. The leaf’s key does three jobs: it is the TLS certificate, it signs every envelope, and contacts seal to it (§ 2). A host obtains a leaf by sending the wallet a certificate signing request carrying the host’s key and the endpoint it will serve; the wallet shows the person the endpoint and the validity, and signs or does not (§ 9, § 9.1). Never the root: a host holds the leaf and its key, a superseded leaf’s key until that leaf’s notAfter, and the identity’s data.

A chain is exactly two certificates

Leaf then root, and it travels everywhere identity must: as the TLS client certificate chain, inside a sealed envelope until the receiver holds the leaf and by fingerprint after that, and in the redeem_invite and get_card results. A card carries the leaf alone; the root arrives with the first exchange, and nothing about it needs to be trusted in advance, because it must hash to the fingerprint the leaf names as its issuer (§ 2, § 14.2).

A passkey can be the root

A wallet that can use a WebAuthn credential derives the root’s private key from the credential’s PRF output rather than generating and storing it, so the wallet holds no root at rest: the key is reconstructed on each use and exists only as long as one signing takes. The derivation is fixed so that any conforming wallet reproduces the same identity from the same credential — a constant PRF salt, HKDF-SHA256 with an empty salt, the info string pact/root/1, an Ed25519 key — and a derived root is indistinguishable on the wire from any other (§ 2.1). Because deriving from the wrong credential yields a valid root belonging to a different identity, a wallet proves the root before it signs anything: the fingerprint matches, the certificate’s key matches, and the key signs a challenge that can never be a certificate (§ 2.2).

Losing keys

A lost or compromised leaf key is a renewal with a new key. A lost root is the end of the identity: re-share a new card from a new identity. A compromised root is the same, because whoever holds it can issue leaves, and no rotation ceremony could tell the two holders apart. There is deliberately no recovery and no rotation; the person’s own backups of the wallet are the only copy, and a passkey its provider synchronises is a copy too (§ 2).