# `nupp.mac.spi`
Implementation interfaces for keyed authentication algorithm catalogs.
The facade chooses the unique highest priority during initialization. Its entries
override matching built-ins and may add names; empty discovery uses the built-in
catalog. Descriptors are retained once, so context operations perform no SPI
resolution. Importing this declaration creates no keyed or storage state.
Algorithm names match their map keys. `digestSize` is a positive fixed byte
count; `hmac-sha256` always produces 32 bytes. `create` receives the retained
descriptor and a raw-byte key and returns independently owned `State` using the
shared digest protocol. Updates must not retain input views. `finish` writes
exactly `digestSize` bytes without consuming state; the facade closes state on
success and failure. Cleanup consumes ownership without suspension. Providers
define private records satisfying the canonical `State` interface rather than
substituting its identity.
## Types
### `Algorithm` _interface_
```nupp
interface Algorithm ...
```
Fixed-output authentication algorithm and a factory for keyed state.
#### Members
| Name | Kind | Description |
| --- | --- | --- |
| [`name`](#nupp.mac.spi.Algorithm.name) | field | Canonical algorithm name matching the catalog key. |
| [`digestSize`](#nupp.mac.spi.Algorithm.digestSize) | field | Fixed output size in bytes. |
| [`create`](#nupp.mac.spi.Algorithm.create) | method | Creates independent owned state from the raw-byte secret key. |
#### `name` _field_
```nupp
name: string
```
`@readonly`
Canonical algorithm name matching the catalog key.
#### `digestSize` _field_
```nupp
digestSize: integer
```
`@readonly`
Fixed output size in bytes.
#### `create` _method_
```nupp
create: function(self: Algorithm, key: string): State
```
Creates independent owned state from the raw-byte secret key.
##### Arguments
| Name | Type | Description |
| --- | --- | --- |
| `self` | `Algorithm` | |
| `key` | `string` | |
##### Returns
| Type | Description |
| --- | --- |
| `State` | |
### `Provider` _interface_
```nupp
interface Provider ...
```
A selectable catalog of keyed algorithm descriptors.
#### Members
| Name | Kind | Description |
| --- | --- | --- |
| [`priority`](#nupp.mac.spi.Provider.priority) | field | |
| [`algorithms`](#nupp.mac.spi.Provider.algorithms) | field | Algorithms keyed by canonical name; additional descriptor fields are allowed. |
#### `priority` _field_
```nupp
priority: integer?
```
`@readonly`
#### `algorithms` _field_
```nupp
algorithms: {[string]: Algorithm}
```
`@readonly`
Algorithms keyed by canonical name; additional descriptor fields are allowed.