ak.schema.account_blocklist.v1
ak.schema.account_blocklist.v1 · file: schemas/account-blocklist.schema.json Decrypted plaintext value of the holder-private ak.account.blocklist account-data key. It is written only through ak.account_data.set as an encrypted value; the whole-value replacement uses that write's expected_server_revision CAS and the value carries no revision of its own. Omitting an entry in the next value removes it, and entries=[] clears the list. It never enters shared Realm state or federation payloads.
* $ · object
Decrypted plaintext value of the holder-private ak.account.blocklist account-data key. It is written only through ak.account_data.set as an encrypted value; the whole-value replacement uses that write's expected_server_revision CAS and the value carries no revision of its own. Omitting an entry in the next value removes it, and entries=[] clears the list. It never enters shared Realm state or federation payloads.
* entries · array<object>
items · object
entry_id ·
stringBlocklist entry identity. This is the registered ak:block:<uuidv7> typed id of id-kind-registry.json, not a document-local symbol: the wire form owns the ak: namespace, so common-fields.md 2.1 classifies it as typed_object_id and the terminal MUST pin that form.
pattern:
^ak:block:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* target · object
anyOf · anyOf[0] · object
* kind ·
const "actor"enum:
"actor"anyOf · anyOf[1] · oneOf[2]
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* kind ·
const "device"enum:
"device"object_ref ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$value ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$anyOf · anyOf[2] · object
* kind ·
const "applet"enum:
"applet"* object_ref ·
string · $ref ./event-envelope.schema.json#/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$anyOf · anyOf[3] · object
* kind ·
string (enum)enum:
"handle" "domain" "keyword"* kind ·
string (enum)enum:
"actor" "device" "handle" "domain" "applet" "keyword"actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idobject_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$oneOf · oneOf[1] ·
string · $ref ./event-envelope.schema.json#/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$value ·
string* mode ·
string (enum)block denies a new holder-facing interaction on the selected surfaces and filters shared durable content only after canonical receive/store; mute keeps content visible but suppresses attention surfaces; hide keeps canonical content but omits it from default holder rendering/search. None of the modes revokes a Realm capability or rewrites shared history.
enum:
"block" "mute" "hide"* applies_to · array<string (enum)>
items ·
string (enum)enum:
"messages" "mentions" "dm" "calls" "contacts" "applets" "presence" "notifications" "directory"reason_code ·
string · $ref ./event-payload.schema.json#/$defs/non_empty_stringexpires_at · oneOf[2] · $ref ./event-payload.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[1] ·
null* created_at ·
string (date-time) · format=date-time · $ref ./event-payload.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$updated_at ·
string (date-time) · format=date-time · $ref ./event-payload.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/account-blocklist.schema.json