ak.profile.applet_service.v1
ak.profile.applet_service.v1
enforcement_phases
[
"conformance",
"startup_claim_guard"
] operation_requirements
[
{
"direction": "provide",
"operation_id": "ak.edge.applet.read.describe.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.edge.applet.read.ping.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.edge.applet.command.transaction.v1",
"binding_kind": "http_json"
}
] required_event_kinds
[
"ak.applet.registration"
] rejected_event_kinds
[] required_schemas
[
"ak.schema.event.v1",
"ak.schema.event_payload.v1",
"ak.schema.applet_package.v1",
"ak.schema.applet_registration_epoch_transcript.v1"
] required_fixtures
[
"applet-registration-epoch-fixture.json"
] optional_extensions
[] feature_discovery
{
"required": [
"claimed_profiles",
"supported_protocols",
"namespace",
"service_id",
"transaction_delivery_authentication_record",
"transaction_replay_binding"
],
"unsupported_optional": "return unsupported_feature"
} additional_requirements
{
"transaction_push_per_delivery_signature_must": "ak.edge.applet.command.transaction.v1 MUST require a per-delivery RFC 9421 HTTP Message Signature in both node->Applet and app/bridge->arkret inbound directions; pure bearer-only transaction push MUST be rejected with http_signature_required.",
"transaction_push_covered_components_must": {
"signature_scenario_id": "ak.http_signature.scenario.applet_transaction.v1",
"covered_components": [
"@authority",
"@method",
"@target-uri",
"arkret-operation",
"content-digest",
"destination-service-id",
"idempotency-key",
"source-service-id"
],
"freshness_profile_id": "ak.http_signature.freshness.v1",
"statement": "Signature-Input MUST cover every component listed here. The list is a projection of http_signature_contract_registry in contract-registry.json and is compared to it by gate; it is a minimum, not a closed set. created/expires MUST satisfy the shared window in zh/sync/service-http-binding.md section 8.3. A request whose Arkret-Operation header is present but not signed MUST be rejected with http_signature_invalid."
},
"transaction_push_delivery_authentication_record_must": "Receivers MUST derive and persist the closed delivery_authentication_record from verified inputs, including operation/direction, source/destination, signature label, verification method/key digest/algorithm, registration epoch, idempotency key, content digest, ordered covered components, created and expires. They MUST recompute delivery_authentication_record_digest with domain ak.applet.delivery_authentication_record.v1; neither value is caller supplied.",
"transaction_push_replay_binding_must": "The idempotency identity MUST include operation_id, direction, Source-Service-ID, Destination-Service-ID and Idempotency-Key; the cached record MUST bind canonical body digest, delivery_authentication_record and its receiver-recomputed digest. A replay with a different body digest or authentication-record digest MUST fail closed.",
"transaction_push_inbound_registration_must": "For app/bridge->arkret inbound push, Source-Service-ID MUST match an active effective Applet install and Signature-Input keyid MUST equal the current registration webhook_auth.key_ref; missing install or key mismatch MUST fail closed with applet_registration_unauthorized or http_signature_invalid.",
"transaction_push_actor_binding_must": "The source service signature authenticates only the Applet service. Each durable Event in the transaction MUST still verify event proofs, applet_id, authorization_ref, actor_id namespace and capability grants; namespace or actor-source confusion MUST fail closed.",
"managed_authority_contract_must": "Service-only install, 0..N independent Bot/Ghost; exact role creation actions, ordinary Service parent to terminal child and Device content supply follow registry/applet-managed-authority-registry.json and zh/authz/managed-governance.md."
} non_event_grant_authority_rules
[
{
"issuer_action": "ak.realm.admin",
"issuer_owner_authority_allowed": true,
"grantable_action": "ak.applet.bot.provision",
"required_registration_event_kind": "ak.applet.registration",
"required_claimed_profile": "ak.profile.applet_service.v1",
"required_constraint_kind": "authority_control",
"required_constraint_subkind": "applet_authority",
"subject_binding": "registration.service_id",
"scope_binding": "grant.resource_exact_registration_scope",
"epoch_binding": "constraint.registration_epoch_exact_registration",
"requested_action_binding": "grant.action_in_registration.requested_scopes"
}
]