A CAWG credential holder: something able to produce a signature over a
SignerPayload on behalf of a credential (e.g. a verified identity,
or an enterprise x509 certificate). Analogous to Signer, but for
a cawg.identity assertion rather than the manifest's own claim signature.
sign, like Signer.sign, always runs on the main thread: it never
crosses into the worker directly. See Builder.sign/
Builder.signAndGetManifestBytes for how it's wired up via reverse-RPC.
A CAWG credential holder: something able to produce a signature over a SignerPayload on behalf of a credential (e.g. a verified identity, or an enterprise x509 certificate). Analogous to Signer, but for a
cawg.identityassertion rather than the manifest's own claim signature.sign, like Signer.sign, always runs on the main thread: it never crosses into the worker directly. SeeBuilder.sign/Builder.signAndGetManifestBytesfor how it's wired up via reverse-RPC.