AUTH4D-5 signing and protected-secret behavior
This ticket adds security-library behavior and no HTTP routes. A future protocol route may serve the
tenant-scoped GET /t/{tenantId}/.well-known/jwks.json response with the library’s public JWKS:
RSA signing keys contain kty, stable thumbprint kid, use: "sig", alg: "RS256", n, and e
only. Private RSA parameters and encryption material are never returned.
Access and ID tokens are separately issued and validated as RS256 JWTs with five-minute maximum
lifetimes. Access tokens use JOSE typ: "at+jwt" and payload token_use: "access"; ID tokens use
JOSE typ: "JWT" and payload token_use: "id". Each validator requires its exact issuer and
audience, validates expiry and not-before, and rejects the other token class.
Recoverable secret values use versioned AES-256-GCM envelopes authenticated to both tenant ID and
purpose. The expected tenant and purpose are supplied by the caller when decrypting; mismatch or
tampering fails closed. Key-ring formats and rotation steps are in
scripts/keys/README.md (repository file scripts/keys/README.md).
Source: docs/api-spec/auth4d-5.md