The audience is whoever presents the secret whose hash is stored in the grant.
Fields
field | type | required | meaning |
|---|---|---|---|
| literal | yes | Audience kind tag. |
| yes | SHA-256 of the bearer secret. |
Rules
The secret travels in the share link, never in a blob. A peer joins the audience for a connection by presenting the secret during Authenticate; the server hashes it and matches live bearer grants. Bearer grants are read-only by convention; the schema allows higher levels but clients should not issue them. A bearer grant is the one audience that can reach someone with no account yet, which the roadmap's invitation flow needs. Revoking the grant kills every copy of the link.
Today (HM24)
Not expressible; every private read needs a writer capability.
Example
{"kind": "bearer", "hash": {"/": {"bytes": "s2Y5f0...32 bytes"}}}See also
Do you like what you are reading? Subscribe to receive updates.
Unsubscribe anytime