A production keyset is organised into categories. This guide explains what those categories are for at a conceptual level, so that the structure of the file makes sense. It does not contain values, and it does not attempt to list them exhaustively — categories are grouped by purpose here, not reproduced.
Why categories exist
Different operations in the content pipeline need different material. Header handling, key unwrapping, content decryption and media addressing are distinct tasks served by distinct entries. Grouping them by purpose is what allows a tool to load one file and find the material each stage needs — and it is what makes a missing entry a diagnosable problem rather than a mystery.
Revisions and generations
The same category can exist in more than one revision, because the security system has evolved. Successive key generations introduce new material while some earlier material remains relevant. A keyset therefore carries a revision context, and the content or tool it is used with expects a particular revision to be present.
Described by purpose, never by value. Everything on this page is a description of what a category is for. No key values appear anywhere on this site.
Where these categories are used
The practical consequences show up in two places: the compatibility hub, where a missing category becomes a mismatch, and the troubleshooting hub, where it becomes a specific error. Read this guide alongside those two if you are trying to diagnose something.