ak.profile.signal_peer_relay.v1
ak.profile.signal_peer_relay.v1
role
"server" description
"Optional symmetric Station profile for the encrypted Signal Extension single-hop peer relay. It does not imply durable Event federation and does not advertise any product signal kind." enforcement_phases
[
"conformance",
"startup_claim_guard"
] operation_requirements
[
{
"direction": "provide",
"operation_id": "ak.server.read.describe.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.self.signal.command.send.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.self.signal.stream.subscribe.v1",
"binding_kind": "http_json"
},
{
"direction": "provide",
"operation_id": "ak.peer.signal.command.relay.v1",
"binding_kind": "http_json"
}
] required_event_kinds
[] rejected_event_kinds
[] required_schemas
[
"ak.schema.signal_envelope.v1",
"ak.schema.signal_relay.v1"
] required_fixtures
[
"signal-federation-fixture.json"
] optional_extensions
[] prose_requirement_coverage
[
{
"requirement": "source current exact-account device authentication, destination peer/outer admission without remote device verification, recipient independent producer authentication, single-hop current joined-member ActorId routing and unchanged envelope",
"coverage": [
"ak.peer.signal.command.relay.v1",
"signal-federation-fixture.json"
]
},
{
"requirement": "opaque request-level outcome and anti-enumeration",
"coverage": [
"ak.schema.signal_relay.v1",
"signal-federation-fixture.json"
]
},
{
"requirement": "bounded batch/body/signature window and drop-unconfirmed retry behavior",
"coverage": [
"ak.peer.signal.command.relay.v1",
"signal-federation-fixture.json"
]
}
] feature_discovery
{
"required": [
"service_id",
"transport_bindings",
"supported_operation_bundles",
"supported_profiles"
],
"unsupported_optional": "omit ak.profile.signal_peer_relay.v1 and ak.peer.signal.command.relay.v1; local Signal and durable federation remain independently usable"
} additional_requirements
{
"encrypted_only_must": "Every relayed item MUST be ak.schema.signal_envelope.v1; plaintext or unencrypted ephemeral inputs fail closed with signal_plaintext_forbidden.",
"source_authority_must": "Source MUST authenticate exact-account current device authority and producer signature at local ingress and freshly before queued outbound dispatch, together with current scope/membership/action/TTL and MLS basis.",
"destination_admission_must": "Destination MUST authenticate peer source/body, sender routing projection, closed proof transcript/digest and outer scope/RealmCommit/current membership/action/TTL/MLS basis; it MUST NOT require a remote device directory, producer signature verification, remote PCR replay or an MLS public-tree tracker to relay.",
"recipient_authentication_must": "Relay acceptance is not device authentication. Recipient MUST independently verify current exact-account device trust, producer signature, winning MLS state and active-leaf actor/device/key/authorization binding, AAD/AEAD, plaintext schema and replay before display or effects; known revoked authority fails even before leaf Remove.",
"single_hop_must": "A destination MUST NOT relay a peer-received SignalEnvelope to a third service. The original sender-side service performs one direct request per eligible destination service.",
"no_kind_advertisement_must": "Describe MUST advertise only this profile and operation support; exact product signal kind and target remain encrypted and MUST NOT appear in supported-kinds or routing metadata.",
"opaque_outcome_must": "A valid authenticated request returns only {accepted:true}; no recipient, binding, capability, count or per-item outcome is exposed.",
"retry_must": "The operation forbids Idempotency-Key, is retry_safe=false and uses uncertain_outcome.strategy=drop_unconfirmed. A lost response MUST NOT cause automatic request replay.",
"scope_authority_cut_must": "Circle Signal MUST bind independent exact accepted scope and parent Realm cuts in proof/AAD, validate historical and current parent membership/capability and scope membership/MLS in one authority read, and fail closed on current revoke/reset/ownership/join changes or missing current lineage/coverage. Realm Signal MUST omit the parent field. No cross-stream position or wall-clock causal inference is allowed."
}