Skip to main content
Every request binds: The SDK signs the CINDER-API\0\x00\x01 fixed-width big-endian encoding. Do not sign displayed JSON, human-readable messages, a native venue payload or an arbitrary digest instead. Fresh attestation verifies AWS trust, approved PCR0/1/2 and manifest, network/deployment, challenge, boot, channel key, handle and expiry before private authentication. Policy and SDK/WASM code must come from independently trusted distribution. Current permissions, epoch and journal freshness are checked before lookup or idempotent replay. Economic identity includes domain/account/id/policy and exact command; changing the financial deadline changes the intent. A fresh session/authentication expiry may re-sign the same intent, but does not authorize a new economic attempt. No self-service signup or bearer tokens. Agent authority is limited by grant; native pooled credentials are never customer credentials.