The wallet descriptor it came from. Public — persist it with the artifact; contractSigner resolves it back to a signer.
Persist preimage with the artifact: this wallet cannot re-derive it.
True when the caller supplied P, or when the signer cannot sign
deterministically. When false the preimage re-derives from the seed —
given preimageSalt, where there is one — and nothing secret
needs to be stored.
sha256(preimage) — what the contract commits to.
OptionalpreimageThe salt preimage was derived from, when it came from the salted arm. Public — the opposite of preimage above: persist it with the artifact in the clear, because without it a wallet holding the seed still cannot re-derive P.
Absent on the other two arms: an HD child descriptor already names one artifact, and a stored preimage needs no derivation input.
x-only pubkey to bind into the covenant.
A claim key together with the preimage it claims with.
pkScriptandaddressare excluded: a claim leg funds nothing, so it names no refund destination.