Sigil documentation
ReferenceRust referencesigil-wallet

sigil-wallet · keystore

Source declarations, signatures and documentation for keystore.

Source: sigil/node/sigil-wallet/src/keystore.rs. SHA-256: d3e22c1beb0e692b9a79d8cb711b5802d859d42aaf4d53be849e3274df379d3c.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

keystore::IdentityKind

Kind of identity entity.

#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "lowercase")]
pub enum IdentityKind {
    /// Human root identity.
    Hmr,
    /// Multi-human / machine root identity.
    Mhr,
    /// Enterprise / entity root identity.
    Enr,
    /// Agent identity (derived from a human root).
    Agent,
}

Source line: 42.

keystore::KdfParams

KDF parameters stored alongside the ciphertext.

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct KdfParams {
pub memory_kib: u32,
pub iterations: u32,
pub parallelism: u32
}

Source line: 82.

keystore::CryptoEnvelope

Cryptographic envelope stored in the keystore file.

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct CryptoEnvelope {
pub cipher: String,
pub kdf: String,
pub kdf_params: KdfParams,
/// Base64-encoded ciphertext (encrypted 32-byte signing key).

pub ciphertext: String,
/// Base64-encoded nonce (12 bytes).

pub nonce: String,
/// Base64-encoded salt (16 bytes).

pub salt: String
}

Source line: 100.

keystore::KeystoreEntry

A keystore entry representing one identity on disk.

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct KeystoreEntry {
/// Format version.

pub version: u32,
/// The DID for this identity.

pub did: String,
/// Kind of identity (hmr or agent).

pub kind: IdentityKind,
/// Parent DID (empty for root HMR identities).

#[serde(skip_serializing_if = "Option::is_none")]
pub parent_did: Option<String>,
/// Lineage generation (0 for HMR, 1+ for derived agents).

pub generation: u32,
/// When this identity was created.

pub created_at: DateTime<Utc>,
/// Encrypted key material.

pub crypto: CryptoEnvelope,
/// Hex-encoded Ed25519 public key.

pub public_key: String
}

Source line: 114.

keystore::KeystoreEntry::address_hex

Derive the stable Sigil wallet address for this identity.

Sigil addresses are derived from the canonical DID, not from mutable signing key material, so balances survive key rotation and recovery.

pub fn address_hex(&self) -> WalletResult<String>;

Source line: 139.

keystore::Keystore

The keystore manages encrypted identity files on disk.

pub struct Keystore {

}

Source line: 147.

keystore::Keystore::open_default

Open the keystore at the default location (~/.sigil/keystore/).

pub fn open_default() -> WalletResult<Self>;

Source line: 153.

keystore::Keystore::open

Open or create the keystore at the given directory.

pub fn open(dir: &Path) -> WalletResult<Self>;

Source line: 159.

keystore::Keystore::create_identity

Generate a new identity with a fresh Ed25519 keypair.

The private key is encrypted with the provided passphrase and stored on disk. Returns the created [KeystoreEntry].

pub fn create_identity(
        &self,
        namespace: &str,
        name: &str,
        kind: IdentityKind,
        parent_did: Option<&str>,
        generation: u32,
        passphrase: &str,
    ) -> WalletResult<KeystoreEntry>;

Source line: 170.

keystore::Keystore::derive_identity

Derive a child identity from an existing parent identity.

Generates a fresh keypair for the child. The parent must exist in the keystore; its passphrase is not needed since only the DID lineage is tracked, not key derivation.

pub fn derive_identity(
        &self,
        parent_did: &str,
        name: &str,
        kind: IdentityKind,
        passphrase: &str,
    ) -> WalletResult<KeystoreEntry>;

Source line: 203.

keystore::Keystore::list

List all identities stored in the keystore.

pub fn list(&self) -> WalletResult<Vec<KeystoreEntry>>;

Source line: 235.

keystore::Keystore::load_entry

Load a specific identity by DID.

pub fn load_entry(&self, did: &str) -> WalletResult<KeystoreEntry>;

Source line: 265.

keystore::Keystore::decrypt_signing_key

Decrypt and return the signing key for the given identity.

pub fn decrypt_signing_key(&self, did: &str, passphrase: &str) -> WalletResult<SigningKey>;

Source line: 274.

keystore::Keystore::delete

Delete an identity from the keystore.

pub fn delete(&self, did: &str) -> WalletResult<()>;

Source line: 280.

keystore::Keystore::export

Export a keystore entry to an arbitrary path (for backup / transfer).

pub fn export(&self, did: &str, output: &Path) -> WalletResult<()>;

Source line: 292.

keystore::Keystore::import

Import a keystore entry from an external file.

pub fn import(&self, input: &Path) -> WalletResult<KeystoreEntry>;

Source line: 300.

keystore::format_did

Format a DID string from its components.

Format: did:oas:{namespace}:{kind}:{name}

pub fn format_did(namespace: &str, kind: IdentityKind, name: &str) -> String;

Source line: 546.

On this page