Weave documentation
Weave Crypto

Discovery Keys and Namespaces

Discovery tags, namespace bounds, and feature-gated HKDF helpers.

Discovery and namespaces

discovery_key(public_key) hashes the bytes weave followed by the public key with Blake2s256. It is an unkeyed deterministic tag, not an HMAC or an authorization token. Anyone who knows the public key can derive it.

namespace(name, count_or_indices) first hashes the name, then hashes that digest with a single-byte index. Indices are cast to u8, so indices separated by 256 collide. Restrict a namespace to distinct indices in 0..=255; a count greater than 256 does not yield distinct tags.

use weave_crypto::{discovery_key, key_pair, namespace};

let keys = key_pair(None);
let discovery = discovery_key(&keys.public_key);
let tags = namespace("application.events.v1", 4usize);
assert_eq!(tags.len(), 4);

HKDF feature boundary

hkdf_sha256 and derive_nonce are available when both hkdf and sha2 features are enabled. derive_nonce(label, seed) returns 24 deterministic bytes. Reusing the same label and seed repeats that nonce; it is not a counter or a complete session protocol. Public keys and public namespace tags do not become secret encryption keys by passing through HKDF.

Source reference

Exact declarations and source provenance · Package features and manifest.

On this page