cursor
One cursor page of query: page(Keyset) for one row more than the page, the look-ahead that decides whether a next page exists. The next token encodes the native position of the page's last row, never a value from the rows, so masking cannot leak into it. A token that does not decode for this model and effective sort is rejected as Invalid cursor. before any I/O.