> For the complete documentation index, see [llms.txt](https://docs.talus.network/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.talus.network/talus-docs-v2.1.0/reference/move/nexus_registry/network_auth.md).

# network\_auth

* [Struct `NetworkAuth`](#struct-networkauth)
* [Struct `NetworkAuthInnerV1`](#struct-networkauthinnerv1)
* [Struct `KeyBinding`](#struct-keybinding)
* [Struct `KeyBindingInnerV1`](#struct-keybindinginnerv1)
* [Struct `KeyRecord`](#struct-keyrecord)
* [Struct `ProofOfIdentity`](#struct-proofofidentity)
* [Struct `ProofOfKey`](#struct-proofofkey)
* [Struct `NetworkAuthCreatedEvent`](#struct-networkauthcreatedevent)
* [Struct `KeyBindingCreatedEvent`](#struct-keybindingcreatedevent)
* [Struct `KeyRegisteredEvent`](#struct-keyregisteredevent)
* [Struct `KeyRevokedEvent`](#struct-keyrevokedevent)
* [Struct `ActiveKeyUpdatedEvent`](#struct-activekeyupdatedevent)
* [Enum `IdentityKey`](#enum-identitykey)
* [Constants](#constants)
* [Function `prove_leader`](#function-prove_leader)
* [Function `prove_offchain_tool`](#function-prove_offchain_tool)
* [Function `proof_identity`](#function-proof_identity)
* [Function `identity_key_leader`](#function-identity_key_leader)
* [Function `identity_key_tool`](#function-identity_key_tool)
* [Function `new_proof_of_key`](#function-new_proof_of_key)
* [Function `binding_address`](#function-binding_address)
* [Function `binding_exists`](#function-binding_exists)
* [Function `registered_key_witness`](#function-registered_key_witness)
* [Function `create_binding`](#function-create_binding)
* [Function `key_binding_identity`](#function-key_binding_identity)
* [Function `key_binding_active_key_id`](#function-key_binding_active_key_id)
* [Function `key_binding_next_key_id`](#function-key_binding_next_key_id)
* [Function `key_binding_key`](#function-key_binding_key)
* [Function `active_key_is_usable`](#function-active_key_is_usable)
* [Function `verify_active_key_signature`](#function-verify_active_key_signature)
* [Function `register_key`](#function-register_key)
* [Function `revoke_key`](#function-revoke_key)
* [Function `set_active_key`](#function-set_active_key)

### Struct `NetworkAuth`

Shared registry for identity key bindings.

```move
public struct NetworkAuth has key
```

<details>

<summary>Fields</summary>

`id: sui::object::UID`Object ID of the registry.

</details>

#### Struct `NetworkAuthInnerV1`

Version one stored layout for \[[`NetworkAuth`](#nexus_registry_network_auth_NetworkAuth)].

```move
public struct NetworkAuthInnerV1 has store
```

<details>

<summary>Fields</summary>

[`registered_key_witness`](#nexus_registry_network_auth_registered_key_witness)`: sui::object::UID`Singleton witness for the registered key verifier.`identities: sui::vec_set::VecSet<`[`nexus_registry::network_auth::IdentityKey`](#nexus_registry_network_auth_IdentityKey)`>`Discoverable set of identities that have a \[KeyBinding]. This enables indexers/tooling to enumerate which identities have created bindings, without needing to guess identities and derived addresses.

</details>

#### Struct `KeyBinding`

Per-identity key binding stored at a deterministic derived address.

This object holds the full key lifecycle state for one identity:

* key registration (with PoP),
* active key selection (the only key verifiers accept),
* revocations (for incident response / decommissioning).

```move
public struct KeyBinding has key, store
```

<details>

<summary>Fields</summary>

`id: sui::object::UID`Object ID of the binding.

</details>

#### Struct `KeyBindingInnerV1`

Version one stored layout for \[[`KeyBinding`](#nexus_registry_network_auth_KeyBinding)].

```move
public struct KeyBindingInnerV1 has store
```

<details>

<summary>Fields</summary>

`identity:` [`nexus_registry::network_auth::IdentityKey`](#nexus_registry_network_auth_IdentityKey)Identity this binding belongs to.`description: std::option::Option<vector<u8>>`Optional description for operators and tooling.`next_key_id: u64`Monotonically increasing key identifier. This is used as the key id for the next registration and as the PoP nonce to prevent replay of PoP signatures.`active_key_id: std::option::Option<u64>`Active key identifier for verification. Offchain verifiers MUST accept signatures from this key only. This allows key rotation while keeping verification unambiguous.`keys: sui::table::Table<u64,` [`nexus_registry::network_auth::KeyRecord`](#nexus_registry_network_auth_KeyRecord)`>`Key records indexed by key id.

</details>

#### Struct `KeyRecord`

Single key record stored in a binding.

Keys are append only (registered under a new `key_id`) and can be revoked.

```move
public struct KeyRecord has store
```

<details>

<summary>Fields</summary>

`scheme: u8`Key scheme identifier (Ed25519 only).`public_key: vector<u8>`Raw public key bytes.`added_at_ms: u64`Timestamp when the key was registered.`revoked_at_ms: std::option::Option<u64>`Timestamp when the key was revoked, if any.

</details>

#### Struct `ProofOfIdentity`

Ephemeral proof that the caller is authorized to act for an identity.

This prevents unauthorized parties from creating bindings or registering keys for identities they do not control.

```move
public struct ProofOfIdentity has drop
```

<details>

<summary>Fields</summary>

`identity:` [`nexus_registry::network_auth::IdentityKey`](#nexus_registry_network_auth_IdentityKey)Identity proven by on-chain capabilities.

</details>

#### Struct `ProofOfKey`

Ephemeral proof that a key is controlled by the signer.

This proves possession of the private key corresponding to `public_key` without revealing it, and is valid only for a single registration slot (bound to \[KeyBinding::next\_key\_id]).

```move
public struct ProofOfKey has drop
```

<details>

<summary>Fields</summary>

`scheme: u8`Key scheme identifier (Ed25519 only).`public_key: vector<u8>`Public key proven by proof-of-possession.`key_id: u64`Key id this proof is valid for. This must match \[KeyBinding::next\_key\_id] when registering the key.

</details>

#### Struct `NetworkAuthCreatedEvent`

Emitted when a new network auth registry is created.

```move
public struct NetworkAuthCreatedEvent has copy, drop
```

<details>

<summary>Fields</summary>

`registry: sui::object::ID`Registry object ID.[`registered_key_witness`](#nexus_registry_network_auth_registered_key_witness)`: sui::object::ID`Registered key verifier witness ID.

</details>

#### Struct `KeyBindingCreatedEvent`

Emitted when a new key binding is created.

```move
public struct KeyBindingCreatedEvent has copy, drop
```

<details>

<summary>Fields</summary>

`binding: sui::object::ID`Binding object ID.`identity:` [`nexus_registry::network_auth::IdentityKey`](#nexus_registry_network_auth_IdentityKey)Identity associated with the binding.

</details>

#### Struct `KeyRegisteredEvent`

Emitted when a key is registered.

```move
public struct KeyRegisteredEvent has copy, drop
```

<details>

<summary>Fields</summary>

`binding: sui::object::ID`Binding object ID.`key_id: u64`Registered key identifier.`scheme: u8`Key scheme identifier.`public_key: vector<u8>`Public key bytes.`added_at_ms: u64`Timestamp when the key was registered.

</details>

#### Struct `KeyRevokedEvent`

Emitted when a key is revoked.

```move
public struct KeyRevokedEvent has copy, drop
```

<details>

<summary>Fields</summary>

`binding: sui::object::ID`Binding object ID.`key_id: u64`Revoked key identifier.`revoked_at_ms: u64`Timestamp when the key was revoked.

</details>

#### Struct `ActiveKeyUpdatedEvent`

Emitted when the active key changes.

```move
public struct ActiveKeyUpdatedEvent has copy, drop
```

<details>

<summary>Fields</summary>

`binding: sui::object::ID`Binding object ID.`active_key_id: std::option::Option<u64>`New active key identifier, or none if cleared.

</details>

#### Enum `IdentityKey`

Canonical identity key namespace for key bindings.

This value is used as:

* the key for the derived \[KeyBinding] address, and
* the identity commitment inside PoP signatures (via `bcs(`[`IdentityKey`](#nexus_registry_network_auth_IdentityKey)`)`).

```move
public enum IdentityKey has copy, drop, store
```

<details>

<summary>Variants</summary>

Variant `Leader`Leader identity keyed by leader capability ID.`leader_cap_id: sui::object::ID`ID of the leader's `CloneableOwnerCap<`[`leader_cap::OverNetwork`](/talus-docs-v2.1.0/reference/move/nexus_registry/leader_cap.md#nexus_registry_leader_cap_OverNetwork)`>` capability object.Variant `Tool`Tool identity keyed by stable Tool object ID.`tool_id: sui::object::ID`

</details>

#### Constants

Required byte length of an Ed25519 public key.

```move
const ED25519_PUBLIC_KEY_LEN: u64 = 32;
```

Required byte length of an Ed25519 signature.

```move
const ED25519_SIGNATURE_LEN: u64 = 64;
```

```move
#[error]
const EUnsupportedKeyScheme: vector<u8> = b"Only Ed25519 keys are supported";
```

```move
#[error]
const EInvalidPublicKey: vector<u8> = b"Invalid Ed25519 public key length";
```

```move
#[error]
const EInvalidSignature: vector<u8> = b"Invalid Ed25519 signature length";
```

```move
#[error]
const EInvalidProofOfPossession: vector<u8> = b"Invalid proof of possession";
```

```move
#[error]
const EBindingAlreadyExists: vector<u8> = b"Key binding already exists";
```

```move
#[error]
const EIdentityMismatch: vector<u8> = b"Proof identity does not match key binding";
```

```move
#[error]
const EKeyNotFound: vector<u8> = b"Key not found";
```

```move
#[error]
const EKeyAlreadyRevoked: vector<u8> = b"Key already revoked";
```

```move
#[error]
const EKeyIdMismatch: vector<u8> = b"Proof key id does not match binding slot";
```

Identifier for Ed25519 keys.

```move
const KEY_SCHEME_ED25519: u8 = 0;
```

Default domain separator for proof-of-possession.

```move
const POP_DOMAIN: vector<u8> = vector[110, 101, 120, 117, 115, 95, 114, 101, 103, 105, 115, 116, 114, 121, 46, 110, 101, 116, 119, 111, 114, 107, 95, 97, 117, 116, 104, 46, 112, 111, 112, 95, 118, 49];
```

#### Function `prove_leader`

Create proof for the leader (sender) using its leader capability.

The leader capability serves as the on-chain authorization to act as a Leader identity and register/rotate keys for `IdentityKey::Leader { leader_cap_id: object::id(`[`leader_cap`](/talus-docs-v2.1.0/reference/move/nexus_registry/leader_cap.md#nexus_registry_leader_cap)`) }`.

```move
public fun prove_leader(leader_registry: &nexus_registry::leader::LeaderRegistry, leader_cap: &nexus_primitives::owner_cap::CloneableOwnerCap<nexus_registry::leader_cap::OverNetwork>): nexus_registry::network_auth::ProofOfIdentity
```

#### Function `prove_offchain_tool`

Creates identity proof for an off-chain Tool using its owner capability.

The owner cap is validated against the Tool object before binding its stable ID.

```move
public fun prove_offchain_tool(tool: &nexus_tool::tool_registry::Tool, owner_cap: &mut nexus_primitives::owner_cap::CloneableOwnerCap<nexus_tool::tool_authority::OverTool>): nexus_registry::network_auth::ProofOfIdentity
```

#### Function `proof_identity`

Return the identity proven by the proof.

```move
public fun proof_identity(self: &nexus_registry::network_auth::ProofOfIdentity): nexus_registry::network_auth::IdentityKey
```

#### Function `identity_key_leader`

Build a leader identity key from a leader capability id.

```move
public fun identity_key_leader(leader_cap_id: sui::object::ID): nexus_registry::network_auth::IdentityKey
```

#### Function `identity_key_tool`

Build a tool identity key from a stable Tool object ID.

```move
public fun identity_key_tool(tool_id: sui::object::ID): nexus_registry::network_auth::IdentityKey
```

#### Function `new_proof_of_key`

Create proof\_of\_possession for registering the given public key. Only Ed25519 keys are supported.

The signature must verify over [`POP_DOMAIN`](#nexus_registry_network_auth_POP_DOMAIN) `|| bcs(`[`IdentityKey`](#nexus_registry_network_auth_IdentityKey)`) || bcs(key_id) || public_key` using the same public key, proving control of the private key for this specific identity and key-id slot.

```move
public fun new_proof_of_key(binding: &nexus_registry::network_auth::KeyBinding, identity: &nexus_registry::network_auth::ProofOfIdentity, public_key: vector<u8>, signature: vector<u8>): nexus_registry::network_auth::ProofOfKey
```

#### Function `binding_address`

Deterministic derived address for the key binding.

Uses the registry object ID and the identity as the derivation key.

This allows any caller to deterministically compute where the \[KeyBinding] for an identity lives on-chain.

```move
public fun binding_address(registry: &nexus_registry::network_auth::NetworkAuth, identity: nexus_registry::network_auth::IdentityKey): address
```

#### Function `binding_exists`

Check whether a binding has been created for the given identity.

```move
public fun binding_exists(registry: &nexus_registry::network_auth::NetworkAuth, identity: nexus_registry::network_auth::IdentityKey): bool
```

#### Function `registered_key_witness`

Returns the singleton registered key verifier witness ID.

```move
public fun registered_key_witness(self: &nexus_registry::network_auth::NetworkAuth): sui::object::ID
```

#### Function `create_binding`

Create a new key binding for the given identity.

This claims the derived object ID, initializes the binding state, and inserts the identity into the registry's discovery set.

```move
public fun create_binding(registry: &mut nexus_registry::network_auth::NetworkAuth, identity: nexus_registry::network_auth::ProofOfIdentity, description: std::option::Option<vector<u8>>, ctx: &mut sui::tx_context::TxContext): nexus_registry::network_auth::KeyBinding
```

#### Function `key_binding_identity`

Return the identity associated with a key binding.

```move
public fun key_binding_identity(self: &nexus_registry::network_auth::KeyBinding): nexus_registry::network_auth::IdentityKey
```

#### Function `key_binding_active_key_id`

Return the active key id for a binding.

Offchain verifiers must accept signatures from this key only.

```move
public fun key_binding_active_key_id(self: &nexus_registry::network_auth::KeyBinding): std::option::Option<u64>
```

#### Function `key_binding_next_key_id`

Return the next key id that will be assigned on registration.

This value is also committed into PoP signatures to make them one-time-use.

```move
public fun key_binding_next_key_id(self: &nexus_registry::network_auth::KeyBinding): u64
```

#### Function `key_binding_key`

Borrow a key record by id.

```move
public fun key_binding_key(self: &nexus_registry::network_auth::KeyBinding, key_id: u64): &nexus_registry::network_auth::KeyRecord
```

#### Function `active_key_is_usable`

Returns whether the current active slot is a live, correctly-sized Ed25519 key.

```move
public fun active_key_is_usable(binding: &nexus_registry::network_auth::KeyBinding): bool
```

#### Function `verify_active_key_signature`

Verify an Ed25519 signature against the currently active key for this binding.

Returns `false` unless:

* the active key record exists and is not revoked,
* the key scheme and sizes are valid Ed25519 values, and
* signature verification succeeds.

```move
public fun verify_active_key_signature(binding: &nexus_registry::network_auth::KeyBinding, signature: &vector<u8>, message: &vector<u8>): bool
```

#### Function `register_key`

Register a new key and set it as active.

This assigns a monotonically increasing key id, stores the key record, and updates the active key pointer.

```move
public fun register_key(binding: &mut nexus_registry::network_auth::KeyBinding, identity: &nexus_registry::network_auth::ProofOfIdentity, proof_of_key: nexus_registry::network_auth::ProofOfKey, clock: &sui::clock::Clock)
```

#### Function `revoke_key`

Revoke an existing key.

This sets the revocation timestamp and clears the active key if needed.

```move
public fun revoke_key(binding: &mut nexus_registry::network_auth::KeyBinding, identity: &nexus_registry::network_auth::ProofOfIdentity, key_id: u64, clock: &sui::clock::Clock)
```

#### Function `set_active_key`

Set the active key to an existing, non-revoked key.

This switches the active key pointer without altering key records.

```move
public fun set_active_key(binding: &mut nexus_registry::network_auth::KeyBinding, identity: &nexus_registry::network_auth::ProofOfIdentity, key_id: u64)
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.talus.network/talus-docs-v2.1.0/reference/move/nexus_registry/network_auth.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
