Static ReadonlyRETIRE_The id of the scheduler job that removes retired keys.
Static ReadonlyROW_The key table's row format version; a row of any other is not used.
Static ReadonlySEAL_The keystore label the sealed private keys are counted under.
StaticdecryptionReturns the one sentence every decryption failure is answered with, which deliberately does not say which step failed.
the sentence
StaticdecryptDecrypts a compact JWE, an encrypted ID Token, with the relationship's usable keys; the plaintext is the nested JWS, for the caller to verify.
alg and enc must be the relationship's; a kid selects a key and a
kid it does not hold is no key.
the federation relationship
the JWE in compact serialisation
OptionalnowMs: number
the time to check key grace against; now by default
{ ok: true, plaintext, header, kid, algorithm }, or { ok: false, code, why }
StaticdecryptDecrypts an XML Encryption element (an EncryptedAssertion, EncryptedID, EncryptedAttribute or WS-Federation EncryptedData) with the relationship's usable keys, accepting only the algorithms it publishes.
the federation relationship
the encrypted element, serialised whole
OptionalnowMs: number
the time to check key grace against; now by default
{ ok: true, xml, kid, algorithm }, or { ok: false, code, why }
StatickeyReturns the SAML metadata KeyDescriptor use="encryption" for the current
key, with the encryption methods the relationship accepts.
the federation relationship
the XML, or the empty string when there is no current key
StatickeyReturns the key type a key-management algorithm needs: ec-p256 for ECDH,
rsa-3072 otherwise.
the key-management algorithm
the key type
StaticprivateReturns a key row's private key, unsealed where it is sealed: a node KeyObject for a classical row, the parsed AKP JWK for a post-quantum one (#82).
the federation relationship, for the log line
the key row
the key, or null (logged under STS-FED-0137) when it will not
open or parse
StaticpublicReturns the current key's public JWK with use: enc and the relationship's
alg, as /federation/jwks/{id} serves it.
the federation relationship
the JWK, or null when there is no current key
StaticregisterRegisters the retirement scheduler job, once; it runs per realm every five
minutes while federation.enabled is on.
StaticretireRemoves, in the current realm, every previous key row past its grace period; the scheduler job's body.
OptionalnowMs: number
the time to check against; now by default
{ retired }, how many rows were removed
StaticrotateIssues a new encryption key for a relationship, making it current; the key
it replaces stays usable for federation.encryptionKeyGraceS.
Refuses a relationship that decrypts nothing (STS-FED-0144) and a key
that could not be issued, sealed or written (STS-FED-0142).
the relationship id
Optionalwhy: string
the reason recorded with the write
a promise of { ok: true, kid, message } or { ok: false, errors } with its code marked
StaticstoreWrites a new encryption key as current, keeping the one it replaces
for its grace; sealed where keys persist.
the relationship
the relationship's record
its encryption policy
the key: kid, publicJwk, privateKey, certificate or kem
Optionalwhy: string
the audit sentence
{ ok, kid, message } or { ok: false, errors }
StaticusableReturns the key rows that may decrypt now: the current key and a previous one still inside its grace period, current first.
the federation relationship
OptionalnowMs: number
the time to check against, in milliseconds; now by default
the rows
StaticviewReturns what the relationship page and GET /admin-api/federation show of
its encryption: the policy, the public key table and the current
certificate as PEM, never a private key.
the federation relationship
the view, or null for a relationship that decrypts nothing
A service-provider-side federation relationship's encryption key pair, and the decryption of the encrypted assertions and ID Tokens a partner sends to it.
Each relationship holds its own key, issued under the realm's Intermediate, sealed where keys persist, rotated with a grace period and published in its metadata or JWKS. Every decryption failure is one code,
STS-FED-0138; an algorithm the relationship does not accept isSTS-FED-0139. A static utility class that holds no state.