# `nupp.mac.spi` Implementation interfaces for keyed authentication algorithm catalogs. The facade chooses the unique highest priority during initialization. Its entries override matching built-ins and may add names; empty discovery uses the built-in catalog. Descriptors are retained once, so context operations perform no SPI resolution. Importing this declaration creates no keyed or storage state. Algorithm names match their map keys. `digestSize` is a positive fixed byte count; `hmac-sha256` always produces 32 bytes. `create` receives the retained descriptor and a raw-byte key and returns independently owned `State` using the shared digest protocol. Updates must not retain input views. `finish` writes exactly `digestSize` bytes without consuming state; the facade closes state on success and failure. Cleanup consumes ownership without suspension. Providers define private records satisfying the canonical `State` interface rather than substituting its identity. ## Types ### `Algorithm` _interface_ ```nupp interface Algorithm ... ``` Fixed-output authentication algorithm and a factory for keyed state. #### Members | Name | Kind | Description | | --- | --- | --- | | [`name`](#nupp.mac.spi.Algorithm.name) | field | Canonical algorithm name matching the catalog key. | | [`digestSize`](#nupp.mac.spi.Algorithm.digestSize) | field | Fixed output size in bytes. | | [`create`](#nupp.mac.spi.Algorithm.create) | method | Creates independent owned state from the raw-byte secret key. | #### `name` _field_ ```nupp name: string ``` `@readonly` Canonical algorithm name matching the catalog key. #### `digestSize` _field_ ```nupp digestSize: integer ``` `@readonly` Fixed output size in bytes. #### `create` _method_ ```nupp create: function(self: Algorithm, key: string): State ``` Creates independent owned state from the raw-byte secret key. ##### Arguments | Name | Type | Description | | --- | --- | --- | | `self` | `Algorithm` | | | `key` | `string` | | ##### Returns | Type | Description | | --- | --- | | `State` | | ### `Provider` _interface_ ```nupp interface Provider ... ``` A selectable catalog of keyed algorithm descriptors. #### Members | Name | Kind | Description | | --- | --- | --- | | [`priority`](#nupp.mac.spi.Provider.priority) | field | | | [`algorithms`](#nupp.mac.spi.Provider.algorithms) | field | Algorithms keyed by canonical name; additional descriptor fields are allowed. | #### `priority` _field_ ```nupp priority: integer? ``` `@readonly` #### `algorithms` _field_ ```nupp algorithms: {[string]: Algorithm} ``` `@readonly` Algorithms keyed by canonical name; additional descriptor fields are allowed.