Per-device HPKE identity for Android push registration (/api/v1/push/register/).
The hpke_pubkey the Android 448 app sends is its per-install HPKE public key,
not a shared wire constant: a single key would make every igpapi install
correlatable. It is a 65-byte uncompressed EC point (0x04 || X || Y), sent as
standard base64 (88 chars, one = pad). The captured hpke_ciphersuite1001000010000 decomposes as 1|0010|0001|0000 — 0x0010 is the RFC 9180 KEM
DHKEM(P-256, HKDF-SHA256), which matches the 65-byte P-256 public point.
keystoreId is the millisecond timestamp at which the key/keystore entry was
created. In the 448 capture (hpke_keystore_id=1790344446764) it sits ~0.7s
before the request that first sends it, i.e. it is stamped once at generation,
not recomputed per request, so it is persisted with the keypair.
Per-device HPKE identity for Android push registration (
/api/v1/push/register/).The
hpke_pubkeythe Android 448 app sends is its per-install HPKE public key, not a shared wire constant: a single key would make every igpapi install correlatable. It is a 65-byte uncompressed EC point (0x04 || X || Y), sent as standard base64 (88 chars, one=pad). The capturedhpke_ciphersuite1001000010000decomposes as1|0010|0001|0000—0x0010is the RFC 9180 KEMDHKEM(P-256, HKDF-SHA256), which matches the 65-byte P-256 public point.keystoreIdis the millisecond timestamp at which the key/keystore entry was created. In the 448 capture (hpke_keystore_id=1790344446764) it sits ~0.7s before the request that first sends it, i.e. it is stamped once at generation, not recomputed per request, so it is persisted with the keypair.