跳转到内容

ak.schema.account_device_signer_evidence.v1

← Schemas

Arkret Account Device Signer Evidence
ak.schema.account_device_signer_evidence.v1 · file: schemas/account-device-signer-evidence.schema.json

Immutable account_device evidence for a human device producer. The origin Station persists this complete object before returning a keys/query row or before sending it as authority_forward producer_device_evidence, which it signs fresh for every forwarding attempt; the signer_evidence_ref is SHA-256(RFC 8785 JCS of this object). This sibling does not add a branch or member to AuthenticatedSignerResolutionEvidence. Conformance vector ak.vector.device.account_device_signer_evidence.v1 checks the exact closure and negative mutations.

* $ · object
Immutable account_device evidence for a human device producer. The origin Station persists this complete object before returning a keys/query row or before sending it as authority_forward producer_device_evidence, which it signs fresh for every forwarding attempt; the signer_evidence_ref is SHA-256(RFC 8785 JCS of this object). This sibling does not add a branch or member to AuthenticatedSignerResolutionEvidence. Conformance vector ak.vector.device.account_device_signer_evidence.v1 checks the exact closure and negative mutations.
* device_projection_attestation · object · $ref ./keys-operations.schema.json#/$defs/device_projection_attestation
Complete origin-Station-signed device projection attestation. The detached proof signs the ak.device_projection_attestation_proof.v1 transcript; proof.created_at MUST equal attestation.attested_at.
* attestation · $ref #/$defs/device_projection_attestation_core · $ref #/$defs/device_projection_attestation_core
* proof · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
* service_resolution · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* service_kind · string
pattern: ^[a-z][a-z0-9_]{0,63}$
* method_history_evidence · $ref #/$defs/method_history_evidence · $ref #/$defs/method_history_evidence
* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did · $ref #/$defs/did · $ref #/$defs/did
* contexts · array<oneOf[2]>
items · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · object
* controller_dids · array<$ref #/$defs/did>
items · $ref #/$defs/did · $ref #/$defs/did
* also_known_as · array<string>
items · string
Canonical URI validated by the DID resolver before projection; this array may contain non-network schemes such as acct: and therefore is not a URL field.
pattern: ^[A-Za-z][A-Za-z0-9+.-]*:[^\s]+$
* verification_methods · array<$ref #/$defs/normalized_did_verification_method>
items · $ref #/$defs/normalized_did_verification_method · $ref #/$defs/normalized_did_verification_method
* authentication · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* assertion_methods · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* key_agreements · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* capability_invocations · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* capability_delegations · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* services · array<$ref #/$defs/normalized_did_service>
items · $ref #/$defs/normalized_did_service · $ref #/$defs/normalized_did_service
* metadata · $ref #/$defs/normalized_did_document_metadata · $ref #/$defs/normalized_did_document_metadata
* extensions · array<$ref #/$defs/normalized_did_document_extension>
items · $ref #/$defs/normalized_did_document_extension · $ref #/$defs/normalized_did_document_extension

Source