Principal
An opaque, caller-verified identity for the peer on a connection — e.g. an authenticated device id or user id the host established out of band (token, TLS client cert, signed header) before admitting the peer.
Distinct from any self-asserted identity a joiner announces in its handshake preamble (a Hello / MeshHello PeerId). A Principal is what the host vouches for; kuilt treats the wrapped value as opaque and never parses or transmits it on the wire.