stream module ships in @peaqos/peaq-os-sdk and peaq-os-sdk, and its exports are flagged @experimental. It is the cryptographic core of Stream: it signs the data a machine produces, chunks and encrypts it, and re-wraps chunk keys so a buyer can decrypt only what they bought. You hand it a payload and it returns signed, verifiable, encrypted artifacts. Topic subscription and transport on a robot are handled by the ROS 2 Edge Agent, which produces its own peaqos-stream-envelope@v1 packages (Ed25519 signatures, X25519 field encryption) from a Data Event Map. Those envelopes are not the EIP-191 / AES-256-GCM data packages this module produces, so verify each with its own pipeline.
Selling and shipping the encrypted chunks (purchases, payment rails, and S3 / P2P delivery) is the distribution surface.
Module location
Functions
Python exposes the same surface in snake_case (
build_signed_data_package, verify_data_package, build_chunk_chain, verify_chunk_chain, create_buyer_access_entry, build_buyer_access_files, decrypt_chunk, compute_chunk_id).
Types
SigningContext ({ privateKey, backend: "tee" | "software", did, keyId }, whose toJSON redacts the key so it never leaks through serialization) and field-level encryption in an EncryptionContext ({ encryptionKey, algorithm: "AES-256-GCM" }). The field layer uses AES-256-GCM; the per-chunk layer (inside buildChunkChain) uses XChaCha20-Poly1305.
Chunking defaults: chunkSize 262144 bytes (256 KiB), hashAlgorithm "sha-256", via ChunkingConfig. The full envelope shape is documented under Data streams → The chunk envelope.
Example
Sign a reading, verify it, chunk-and-encrypt, then grant a buyer access:buildChunkChain returns the chain plus encryptedData, a map of ciphertext bytes keyed by chunk index. The ciphertext is a pre-upload sidecar: callers store the bytes wherever they distribute from and set each chunk’s storageRef. The buyer decrypts with decryptChunk({ chunk, recipientPrivateKeyHex, recipientEntry, encryptedData }), or decrypt_chunk(chunk=…, recipient_private_key_hex=…, recipient_entry=…, encrypted_data=…) in Python, passing the chunk’s stored ciphertext bytes plus a KeyRecipient from chunk.encryption.keyRecipients or from a buyer access entry. The data itself is never re-encrypted when access is granted.
From the terminal, the same publish and grant flows are peaqos stream publish and peaqos stream grant.
Errors
Solana signing
OWS mnemonic-derived wallets carry a account (ed25519, derivation pathm/44'/501'/0'/0') for cross-chain payments and for machines homed on Solana. This is wallet signing, separate from Stream data signing, which uses EIP-191.
The vault signs Solana transactions natively. PeaqosClient.solanaSignerFromWallet(nameOrId) (Python: solana_signer_from_wallet()) returns a signer for that wallet’s Solana account. transferToken uses it for SPL and native transfers when paying for stream data (peaqos stream pay --chain solana from the terminal), and the same signer signs management writes and event submission for a machine homed on Solana. Solana onboarding (peaqos activate --chain solana) signs its owner stages with the same wallet. See SDK JS: Solana, SDK Python: Solana and Onboard a machine on Solana.
Machine Market orders quoted in Solana tokens are paid externally with your Solana wallet; Scale is paused, so no order can be placed today.

