Sender/owner root wallet + wallet-owner-signature-v1 envelope | Authorized user device | Canonical TIN-access authorization, local data key derivation, GPRU authority for the exact scope | Wallet rotation creates a new owner binding; old TIN requires re-authorization |
| TIN owner-key commitment | TIN registry (public) | Verification material for route integrity and ownership claims | Bound to the current wallet owner; changes with wallet rotation |
| Mother authority key | Mother / TSN program | Creation of the one-time SettlementDna PDA at the derived opaque slot | Program-governed; rotated via program upgrade or governance instruction |
| Node-signed Ed25519 permit key | TSN Node | Short-lived permit binding opaque slot, commitment, nullifier, lease, amount, mint, recipient, expiry | Per-lease generation; expires no later than the Receiver lease |
| Node/Mother encrypted-binding encryption key | Node/Mother only | Encryption of full payment binding off-chain | Never leaves Node/Mother; rotated via key ceremony or service migration |
| Node-only route reference key | TSN Node | Short-lived recipient-route reference keyed by work ID | Expires and is deleted automatically; not persisted in durable records |
| Cranker Solana fee-payer key | Cranker operator | Transaction submission fees | Standard Solana key rotation; no authorization semantics |
| Owner-held TCAP snapshot key | Authorized user device | AES-GCM decryption of private balance snapshot | Owner-controlled; derived from wallet authorization or local secure storage |