Principal
A public key that identifies an account or space, stored in blobs as the raw bytes of a multicodec prefix plus the key and shown to people as a base58 string starting with z6Mk.

Extends

A principal is how Hypermedia names a person, an organisation or a device: by public key, with no registry in between. The same key is the account, the identity that signs, and the space, the namespace hm://<principal>/… it owns.

This page defines the principal value type, an alias of bytes used for the signer of every blob and for space, delegate, subject, account and alias fields. Its formal schema is attached as the schemaDefinition in this document's metadata, so the app can show it.

The bytes are an unsigned-varint multicodec code followed by the raw public key. For Ed25519 the code is 0xed, so a principal is 34 bytes: ed 01 plus the 32-byte key. The string form is multibase base58btc of those bytes, which is why every account you see starts with z6Mk. It is exactly the did:key encoding of an Ed25519 key. The daemon also registers ECDSA P-256 (compressed 33-byte key), whose string form would start with zDn, so that browser session keys made with WebCrypto can sign. Every key the daemon itself creates is Ed25519. In CBOR a principal is a byte string, never text.

A short form of the principal, the first 7 bytes of its SHA-256 read as a little-endian 56-bit number, is the actor component of every op id inside a document. Identity covers how keys are derived from a mnemonic, stored, and delegated to other keys.

See also

    Identity: accounts, keys and delegation.

    signature: what a principal's key produces.

    blob: the signer field.

    Keys: key files and the keyring.

    authority: a key that owns a namespace.

Do you like what you are reading? Subscribe to receive updates.

Unsubscribe anytime