ak.member.identity.update· membership· active- wire scope
- durable_event
- reducer input
- yes
- payload
- Realm-scoped MemberIdentity segment replacement event. Append-only log entry that may supersede prior ak.member.identity.update events via payload.replaces[] without overloading ak.profile.update patch semantics. The event always enters the append-only log: proof and replacement validation are consumption/verification-surface semantics, not reducer rejection. When the MemberIdentity proof fails validation (payload_digest mismatch, signature failure, or verification_method not controlled by subject_id), receivers surface reason=member_identity_proof_invalid and MUST NOT promote the event to a verified display identity. When a replaces[] entry payload_digest or (realm_id, member_id, segment) does not match, only that replacement edge is invalid (surface member_identity_replacement_digest_mismatch); receivers MUST NOT remove the referenced event from the effective set on that basis. Only the optional expected_state_digest guard retains reducer semantics: when expected_state_digest does not equal the current effective-set digest, the server/reducer MUST reject or quarantine the event with reason=member_identity_state_mismatch. See zh/sync/client-sync.md §8.1.