ak.profile.high_security_organization.v1
ak.profile.high_security_organization.v1
enforcement_phases
[
"build",
"conformance"
] operation_requirements
[
{
"direction": "provide",
"operation_id": "ak.self.realm_state_snapshot.read.by_ref.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.self.realm_state_snapshot.read.manifest_head.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.self.keys.keypackages.command.revoke.v1",
"binding_kind": "http_json"
}
] inherits
[
"ak.profile.organization.v1",
"ak.profile.e2ee_client.v1"
] required_event_kinds
[
"ak.device.revoke",
"ak.mls.commit"
] rejected_event_kinds
[] required_schemas
[
"ak.schema.realm_state_snapshot.v1",
"ak.schema.encrypted_envelope.v1",
"ak.schema.moderation_queue_item.v1",
"ak.schema.key_transparency.v1"
] required_fixtures
[
"privacy-security-fixture.json",
"did-webvh-v1-fixture.json",
"key-transparency-fixture.json"
] optional_extensions
[
"witness_quorum",
"hardware_key_policy"
] feature_discovery
{
"required": [
"snapshot_witness",
"mls_governance_binding",
"revocation_freshness",
"did_webvh_1_0",
"key_transparency_inclusion_proof",
"key_transparency_consistency_proof"
],
"unsupported_optional": "fail closed for high-risk action"
} forbidden_features
[
"ak.feature.mls_last_resort_keypackage.v1"
] additional_requirements
{
"sender_constrained_session_pop_must": "Per RFC 9700 (BCP 240) sender-constrained-token guidance, production current-v1 protected endpoints MUST reject bare Authorization: Bearer presentation unless it is bound by DPoP, an RFC 9421 HTTP Message Signature, detached JWS, mTLS, or equivalent sender-constrained proof. For this high-security profile, every protected ak.self.* operation MUST use RFC 9421 HTTP Message Signature whose signing key is the session's session_public_key delegated by ak.session.grant, binding @method/@target-uri/@authority, content-digest (when body present), and participating Idempotency-Key, with created/expires inside the existing replay window. The ak.self. prefix is the machine-enforceable default-protected surface; new or unknown operations default to fail closed. The operation registry may explicitly allow an unauthenticated public-metadata projection, but without valid proof it MUST return only that public projection and MUST NOT treat bare bearer as session/capability authentication. See api-conventions.md §3.2 and service-http-binding.md §8.",
"mls_last_resort_forbidden_must": "Realms claiming this profile MUST NOT allow last-resort KeyPackage join: services MUST NOT advertise ak.feature.mls_last_resort_keypackage.v1 for those Realms, claim responses MUST NOT return last_resort=true packages, and requesters MUST treat any last_resort=true claim record as profile-forbidden and fail closed.",
"key_transparency_must": "High-risk identity, recovery, service delegation and membership decisions MUST verify ak.schema.key_transparency.v1 inclusion and consistency proofs under ak.profile.key_transparency.v1; missing or invalid proof fails closed.",
"sender_constrained_session_pop_covered_components_must": {
"signature_scenario_id": "ak.http_signature.scenario.client_session_pop.v1",
"covered_components": [
"@authority",
"@method",
"@target-uri",
"arkret-operation",
"content-digest",
"idempotency-key",
"x-arkret-wait-for"
],
"conditional_covered_components": [
{
"component": "content-digest",
"condition": "the request carries a body"
},
{
"component": "idempotency-key",
"condition": "the request participates in idempotency or replay keying"
},
{
"component": "x-arkret-wait-for",
"condition": "the header is present on the request"
}
],
"freshness_profile_id": "ak.http_signature.freshness.v1",
"statement": "For every protected ak.self.* operation the RFC 9421 presentation MUST cover each listed component that applies to the request, including arkret-operation. The list is a projection of http_signature_contract_registry and is compared to it by gate. created/expires MUST satisfy the shared window in zh/sync/service-http-binding.md section 8.3; the RFC 9449 DPoP iat/jti window is a separate contract (ak.dpop.freshness.v1) and MUST NOT be substituted."
}
} identity
{
"principal_method_default": "did:webvh",
"allowed_principal_methods": [
"did:webvh"
],
"service_method_default": "did:webvh",
"allowed_service_methods": [
"did:webvh",
"did:web"
],
"did_method_versions": [
"did:webvh:1.0"
],
"principal_method_downgrade_allowed": false,
"witness_threshold_minimum": 2,
"require_witness_evidence": true
}