ak.schema.account_operations.v1
ak.schema.account_operations.v1 · file: schemas/account-operations.schema.json Closed request and response DTOs for account self-service operations and Account Authority issuer-ledger account-status publication and resolution.
* $ · anyOf[20]
Closed request and response DTOs for account self-service operations and Account Authority issuer-ledger account-status publication and resolution.
anyOf · anyOf[0] · object · $ref #/$defs/account_view
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$primary_handle_claim · object · $ref ./handle-claim.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* schema ·
const "ak.schema.handle_claim.v1"enum:
"ak.schema.handle_claim.v1"* claim ·
$ref #/$defs/handle_claim_core · $ref #/$defs/handle_claim_core* status ·
string (enum)enum:
"pending" "verified" "revoked"* as_of ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verifier_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verified_at ·
$ref #/$defs/nullable_timestamp · $ref #/$defs/nullable_timestamp* revocation · oneOf[2]
oneOf · oneOf[0] ·
$ref #/$defs/handle_claim_revocation · $ref #/$defs/handle_claim_revocationoneOf · oneOf[1] ·
null* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* status_proof · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
stringproof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$allOf · allOf[1] · object
* domain ·
const "ak.handle_claim_status.v1"enum:
"ak.handle_claim_status.v1"* proof_purpose ·
const "status_attestation"enum:
"status_attestation"primary_handle_claim_ref ·
string · $ref #/$defs/handle_claim_refOpaque reference to a signed ak.schema.handle_claim.v1 claim, such as an event ref, issuer-local receipt ref, or content-addressed artifact ref.
handle_claim_digests · array<$ref #/$defs/digest> · $ref #/$defs/handle_claim_digests
items ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* state ·
string (enum) · $ref #/$defs/account_stateAccount lifecycle projection; mirrors zh/identity/account-lifecycle.md §3.
enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"* devices · array<$ref #/$defs/device_summary> · $ref #/$defs/device_summaries
items · object · $ref #/$defs/device_summary
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?* device_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref #/$defs/display_nameNFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$* status ·
string (enum)Lifecycle projection only, matching device-lifecycle.md section 14.1. revocation_pending is authority-derived from a durable accepted ak.device.revoke security transaction; trust/evidence quality is reported separately in verification_state.
enum:
"active" "revocation_pending" "revoked" "expired" "generation_fenced"* verification_state ·
string (enum)Trust verification of the device authorization evidence, separate from lifecycle status. A consumer MUST NOT interpret lifecycle status=active as usable authority unless verification_state=verified.
enum:
"verified" "unresolved" "stale"verification_source ·
string (enum)Closed provenance of the verification checkpoint behind verification_state, per device-lifecycle.md section 10.1. genesis is the PCR genesis first device, pairing_code an accepted-device pairing or re-verification ceremony, and recovery an accepted recovery unit replacement device. Login factors, SSO sessions, ordinary session grants and bare server projections MUST NOT mint a checkpoint. Required when verification_state is verified, retained when a previously verified checkpoint went stale, and absent when verification_state is unresolved.
enum:
"genesis" "pairing_code" "recovery"authorized_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$authorized_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$last_seen_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$revoked_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$revocation_states · array<$ref ./device-revocation-state.schema.json#/$defs/device_revocation_gate_record>
All gate-relevant durable revoke records for the exact device/generation, sorted by acceptance_seq and Event id. At most 128 distinct unresolved transactions may be admitted; exact replay consumes no slot, a terminal rejected result removes one pending slot, and an already revoked generation accepts no new transaction. Committing one record makes lifecycle status revoked but MUST NOT hide other surviving pending records.
items · oneOf[2] · $ref ./device-revocation-state.schema.json#/$defs/device_revocation_gate_record
Gate-relevant durable state for an exact device generation. Rejected records are audit history and are excluded; pending and revoked records remain visible together so committing one transaction cannot hide another surviving pending transaction.
oneOf · oneOf[0] ·
$ref #/$defs/device_revocation_pending_state · $ref #/$defs/device_revocation_pending_stateoneOf · oneOf[1] ·
$ref #/$defs/device_revoked_state · $ref #/$defs/device_revoked_stateprofile · allOf[2] · $ref #/$defs/account_materialized_profile
Materialized Actor Profile returned on the account surface. id is the actor_profile ID derived by retyping the accepted ak.profile.create Event ID; realm_id is the exact Principal Control Realm that carries the profile Event lineage.
allOf · allOf[0] · object · $ref ./actor-profile.schema.json
allOf · allOf[0] ·
?id ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:actor_profile:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.actor_profile.v1"enum:
"ak.schema.actor_profile.v1"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* actor_kind ·
string (enum)Closed Actor classification. agent is reserved exclusively for a controller-provisioned Agent; Applet-created or Applet-hosted automation uses bot; Ghost Actor is provenance rather than an actor_kind and uses integration for an external account/integration mirror or bot for an external bot mirror. MUST NOT include device: a device is an endpoint rather than an Actor principal. actor_kind alone grants no authority; authorization still requires the normative DID, provisioning/registration, Grant and Constraint evidence. See zh/models/actor.md.
enum:
"user" "organization" "team" "agent" "bot" "service" "integration"* display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_128NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$handle ·
string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref string-profiles.schema.json#/$defs/canonical_handleCanonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern:
^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$agent_slug ·
string (arkret-agent-slug) · format=arkret-agent-slug · $ref string-profiles.schema.json#/$defs/agent_slugCanonical controller-scoped Agent Agent selector slug. Maximum 64 Unicode code points in prepared form.
pattern:
^[^\s:@/#?\\]+$avatar_blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$accountable_principal_ids · array<$ref #/$defs/did_core_id>
items ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$resolution · object · $ref ./identity-resolution.schema.json#/$defs/resolution_projection
Read-only current principal did projection derived from the PCR identity resolution typed current result. It is not writable through Actor Profile create/update patches and is not an authorization root.
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$profile_fields · object
bio ·
stringstatus_message ·
stringapplet_interaction ·
$ref #/$defs/applet_interaction · $ref #/$defs/applet_interaction* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$updated_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$allOf · allOf[1] ·
?is_server_admin ·
booleanTrue when the authenticated principal is a deployment server administrator (the server's configured admin principal set). Operator-only product surfaces (e.g. organization creation) gate their UI on this. Reducer/config-derived, not a stored account field; absent or false means non-admin.
anyOf · anyOf[1] · object · $ref #/$defs/account_handoff_request_body
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* proof · object · $ref #/$defs/account_handoff_authentication_proof
OIDC authorization-code exchange proof used only to create a DPoP-bound account handoff. The signature is made by the same Ed25519 holder key as the request DPoP proof over utf8('ak.account_handoff_authentication_proof.v1\n') || RFC8785_JCS(this object with signature omitted).
* proof_kind ·
const "oidc_code_exchange"enum:
"oidc_code_exchange"* challenge ·
stringAccount Authority-generated challenge persisted with the OIDC authorization transaction and consumed by this exchange.
* request_canonical_digest ·
string · $ref #/$defs/sha256_digestsha256:<lowercase-hex> of SHA-256 over RFC 8785 JCS bytes of the complete account_handoff_request_body with proof.request_canonical_digest and proof.signature omitted.
pattern:
^sha256:[0-9a-f]{64}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* issuer_uri ·
string (uri) · format=uri* client_id · allOf[2]
allOf · allOf[0] ·
string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)* redirect_uri ·
string (uri) · format=uri* state ·
string* nonce ·
string* authorization_code ·
string · $ref #/$defs/non_empty_string* code_verifier ·
string* signature ·
string64-byte Ed25519 signature encoded base64url without padding.
pattern:
^[A-Za-z0-9_-]{86}$anyOf · anyOf[2] · object · $ref #/$defs/account_handoff_outcome
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_handle ·
string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref ./handle-claim.schema.json#/$defs/handle_claim_core/properties/handleCanonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern:
^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$* account_subject ·
string · $ref #/$defs/account_subjectStable subject for the authenticated service account. The client freezes this value from the DPoP-bound handoff and MUST require the identity-binding challenge to echo it byte-for-byte before signing.
pattern:
^sha256:[0-9a-f]{64}$preferred_locale ·
string (enum)Optional private UI-language preference of the authenticated service account. It is returned only in this DPoP-bound handoff response so the client can continue the just-completed authentication flow in the selected language; it MUST NOT be copied into a public actor profile.
enum:
"en" "zh"* account_handoff_grant ·
stringOpaque, short-lived credential bound to the request DPoP key. It is not ak.session.grant and has no refresh-token semantics.
* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* allowed_operations ·
const ["ak.gate.account.command.issue_identity_binding_challenge.v1","ak.gate.account.command.issue_did_binding_challenge.v1","ak.gate.account.command.abandon_identity_creation.v1","ak.gate.account.command.register.v1","ak.gate.account.command.finalize_device_pairing.v1","ak.gate.account.command.issue_session_grant.v1","ak.gate.account.command.issue_recovery_completion_grant.v1"]Closed set of operations this handoff may be presented at. The abandonment command is a member because a never-accepted PCR leaves the holder without a principal, so no principal-bound ak.session.grant can carry them. The device-pairing finalize command is a member for the mirror reason: a fresh device of an already bound account has no accepted-device signer yet, so this handoff is the only sender-constrained credential that can supply the exact AccountId its target proof must sign. Membership here does not widen the handoff into a session credential.
enum:
["ak.gate.account.command.issue_identity_binding_challenge.v1","ak.gate.account.command.issue_did_binding_challenge.v1","ak.gate.account.command.abandon_identity_creation.v1","ak.gate.account.command.register.v1","ak.gate.account.command.finalize_device_pairing.v1","ak.gate.account.command.issue_session_grant.v1","ak.gate.account.command.issue_recovery_completion_grant.v1"]* binding · oneOf[3] · $ref #/$defs/account_handoff_binding
oneOf · oneOf[0] · object
* state ·
const "identity_creation_active"enum:
"identity_creation_active"* identity_creation_lease · object · $ref #/$defs/identity_creation_lease
* identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* fence ·
integer* state ·
string (enum)Account-Authority-authored durable identity-creation saga state. Clients MUST derive their onboarding phase from this value and MUST NOT infer a phase from local checkpoint presence. reserved_identity MUST be absent only in active and present in every later state.
enum:
"active" "reserved" "did_published" "pcr_accepted" "account_bound" "completed"* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$reserved_identity · object · $ref #/$defs/reserved_identity_creation
Server-persisted identity-creation checkpoint, readable only by the authenticated current holder of the owning service account's identity-creation lease. It is NOT public: an unfinished reservation would otherwise leak that a specific account is mid-registration, and abandoning it would leave a permanent public trace. Once registration completes the public artifact is the published method-native anchor itself, so this checkpoint never needs to become public. It contains the exact unpublished or already-published registration anchor, never recovery words, seed material, private keys, or an encrypted root export.
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* registration_anchor_digest ·
string · $ref #/$defs/sha256_digestsha256:<lowercase-hex> of SHA-256 over RFC 8785 JCS bytes of the complete principal_registration_anchor object.
pattern:
^sha256:[0-9a-f]{64}$* principal_registration_anchor · oneOf[1] · $ref ./principal-registration-anchor.schema.json
Closed WebVH registration anchor for a v1 human principal. It is the single primary method-native material that human registration and PCR genesis both consume. v1 human registration supports exactly the active did:webvh adapter and anchor_kind=webvh_registration; every other DID method, including did:key and did:web, fails closed with unsupported_did_method before method-specific parsing. The anchor carries originals, never receipts: a verifier reconstructs did, method_history_head, version_id, the exact normalized DID document and the root verification method/key from the branch material alone, offline, without a current resolver, a database row or an Account Authority attestation. registration_did_evidence and identity_creation_control_proof keep their own registration anti-replay and control-intent roles and never substitute for this object. Adding another branch requires a separately registered publication-proof or independent-witness trust model, threat model and conformance vectors. Complete canonical anchor bytes MUST NOT exceed 1 MiB.
oneOf · oneOf[0] ·
$ref #/$defs/webvh_registration_anchor · $ref #/$defs/webvh_registration_anchoroneOf · oneOf[1] · object
* state ·
const "identity_creation_busy"enum:
"identity_creation_busy"* retry_after_ms ·
integer* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[2] · object
* state ·
const "bound"enum:
"bound"* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$anyOf · anyOf[3] · object · $ref #/$defs/account_onboarding_state
* handoff_request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_subject ·
string · $ref #/$defs/account_subjectpattern:
^sha256:[0-9a-f]{64}$* observed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* binding · oneOf[3] · $ref #/$defs/account_handoff_binding
oneOf · oneOf[0] · object
* state ·
const "identity_creation_active"enum:
"identity_creation_active"* identity_creation_lease · object · $ref #/$defs/identity_creation_lease
* identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* fence ·
integer* state ·
string (enum)Account-Authority-authored durable identity-creation saga state. Clients MUST derive their onboarding phase from this value and MUST NOT infer a phase from local checkpoint presence. reserved_identity MUST be absent only in active and present in every later state.
enum:
"active" "reserved" "did_published" "pcr_accepted" "account_bound" "completed"* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$reserved_identity · object · $ref #/$defs/reserved_identity_creation
Server-persisted identity-creation checkpoint, readable only by the authenticated current holder of the owning service account's identity-creation lease. It is NOT public: an unfinished reservation would otherwise leak that a specific account is mid-registration, and abandoning it would leave a permanent public trace. Once registration completes the public artifact is the published method-native anchor itself, so this checkpoint never needs to become public. It contains the exact unpublished or already-published registration anchor, never recovery words, seed material, private keys, or an encrypted root export.
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* registration_anchor_digest ·
string · $ref #/$defs/sha256_digestsha256:<lowercase-hex> of SHA-256 over RFC 8785 JCS bytes of the complete principal_registration_anchor object.
pattern:
^sha256:[0-9a-f]{64}$* principal_registration_anchor · oneOf[1] · $ref ./principal-registration-anchor.schema.json
Closed WebVH registration anchor for a v1 human principal. It is the single primary method-native material that human registration and PCR genesis both consume. v1 human registration supports exactly the active did:webvh adapter and anchor_kind=webvh_registration; every other DID method, including did:key and did:web, fails closed with unsupported_did_method before method-specific parsing. The anchor carries originals, never receipts: a verifier reconstructs did, method_history_head, version_id, the exact normalized DID document and the root verification method/key from the branch material alone, offline, without a current resolver, a database row or an Account Authority attestation. registration_did_evidence and identity_creation_control_proof keep their own registration anti-replay and control-intent roles and never substitute for this object. Adding another branch requires a separately registered publication-proof or independent-witness trust model, threat model and conformance vectors. Complete canonical anchor bytes MUST NOT exceed 1 MiB.
oneOf · oneOf[0] ·
$ref #/$defs/webvh_registration_anchor · $ref #/$defs/webvh_registration_anchoroneOf · oneOf[1] · object
* state ·
const "identity_creation_busy"enum:
"identity_creation_busy"* retry_after_ms ·
integer* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[2] · object
* state ·
const "bound"enum:
"bound"* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* goal · object · $ref #/$defs/account_onboarding_goal
* goal ·
const "complete_identity"enum:
"complete_identity"anyOf · anyOf[4] · object · $ref #/$defs/identity_binding_challenge_request_body
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* lease_fence ·
integer* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* principal_registration_anchor · oneOf[1] · $ref ./principal-registration-anchor.schema.json
Closed WebVH registration anchor for a v1 human principal. It is the single primary method-native material that human registration and PCR genesis both consume. v1 human registration supports exactly the active did:webvh adapter and anchor_kind=webvh_registration; every other DID method, including did:key and did:web, fails closed with unsupported_did_method before method-specific parsing. The anchor carries originals, never receipts: a verifier reconstructs did, method_history_head, version_id, the exact normalized DID document and the root verification method/key from the branch material alone, offline, without a current resolver, a database row or an Account Authority attestation. registration_did_evidence and identity_creation_control_proof keep their own registration anti-replay and control-intent roles and never substitute for this object. Adding another branch requires a separately registered publication-proof or independent-witness trust model, threat model and conformance vectors. Complete canonical anchor bytes MUST NOT exceed 1 MiB.
oneOf · oneOf[0] ·
$ref #/$defs/webvh_registration_anchor · $ref #/$defs/webvh_registration_anchor* pcr_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* realm_create_payload_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* founding_authorize_payload_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* initial_session_request_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$anyOf · anyOf[5] · object · $ref #/$defs/identity_binding_challenge_outcome
Only fresh challenge material and domain separation. The authority durably retains the full request, account/handoff subject, lease/fence, DID operation and independently derived pins, PCR/genesis/session digests, audience/origin/trust-domain, and rechecks all of them atomically at registration. The client reconstructs the proof from its frozen submission and authenticated onboarding context.
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* challenge_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* challenge ·
string* purpose ·
const "account_binding_and_pcr_genesis"enum:
"account_binding_and_pcr_genesis"* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$anyOf · anyOf[6] · object · $ref #/$defs/account_register_request_body
Canonical account binding request. Exactly one branch is required: proof binds an already-published did, while identity_creation carries the account-first DID operation and PCR genesis unit. In either branch every repeated principal_id and did in the selected proof/creation objects and genesis initial_resolution MUST equal the outer values byte-for-byte, and the Account Authority MUST independently require project(did)=principal_id before any write.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref #/$defs/display_nameNFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$device_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$proof · object · $ref #/$defs/account_registration_control_proof
Closed control proof for binding an already-published did to principal_id through account register. OIDC, passkey, or agent authentication alone is insufficient to establish DID control. The Account Authority resolves did at high freshness, requires project(did)=principal_id, and selects the current active update key of the entry pinned by did_version_id from verified method history rather than from request-supplied key material. The signature covers every field except signature as canonical JSON with domain separator ak.account_registration_control_proof.v1 and MUST replay the durable challenge issued by ak.gate.account.command.issue_did_binding_challenge.v1.
* proof_kind ·
const "did_bound_signature"enum:
"did_bound_signature"* challenge_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* challenge ·
string* purpose ·
const "account_binding_for_published_did"enum:
"account_binding_for_published_did"* request_canonical_digest ·
string · $ref #/$defs/sha256_digestSHA-256 over RFC 8785 JCS of the complete account_register_request_body with proof.request_canonical_digest and proof.signature omitted.
pattern:
^sha256:[0-9a-f]{64}$* account_subject ·
string · $ref #/$defs/non_empty_stringService account subject this identity is being bound to. Signed so the proof cannot be replayed to bind the same identity to a different account.
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* did_version_id · allOf[2]
Adapter-defined versionId of the entry whose current active update key signed this proof.
allOf · allOf[0] ·
string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)* control_key_digest ·
string · $ref #/$defs/sha256_digestSHA-256 over the canonical multikey bytes of the verified current active update key.
pattern:
^sha256:[0-9a-f]{64}$* dpop_jkt ·
string · $ref #/$defs/dpop_jktRFC 7638 SHA-256 JWK thumbprint of the holder key, encoded base64url without padding.
pattern:
^[A-Za-z0-9_-]{43}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* origin ·
string (uri) · format=uri · $ref ./common-ids.schema.json#/$defs/web_originCanonical HTTP(S) Web Origin: lowercase scheme/host plus an optional valid non-default effective port. Userinfo, path (including a trailing slash), query, fragment, explicit :80 on HTTP, and explicit :443 on HTTPS are forbidden.
pattern:
^(?:http://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!80$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?|https://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!443$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?)$* trust_domain ·
string · $ref ./common-ids.schema.json#/$defs/trust_domainpattern:
^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verification_method ·
string · $ref #/$defs/did_urlCurrent active update-key DID URL under did. The verifier parses its bare DID component with the registered adapter and requires the projected did_core_id to equal principal_id; it never appends a fragment to principal_id.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$witness_evidence ·
string · $ref #/$defs/non_empty_stringMethod-native witness / freshness evidence digest for the external DID, required by deployments that do not host the DID themselves.
* signature ·
string · $ref #/$defs/non_empty_stringidentity_creation · object · $ref #/$defs/identity_creation_registration
allOf · allOf[0] · allOf[1] · $ref #/$defs/registration_anchor_control_proof_pairing
allOf · allOf[0] ·
?* identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* lease_fence ·
integer* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* principal_registration_anchor · oneOf[1] · $ref ./principal-registration-anchor.schema.json
Closed WebVH registration anchor for a v1 human principal. It is the single primary method-native material that human registration and PCR genesis both consume. v1 human registration supports exactly the active did:webvh adapter and anchor_kind=webvh_registration; every other DID method, including did:key and did:web, fails closed with unsupported_did_method before method-specific parsing. The anchor carries originals, never receipts: a verifier reconstructs did, method_history_head, version_id, the exact normalized DID document and the root verification method/key from the branch material alone, offline, without a current resolver, a database row or an Account Authority attestation. registration_did_evidence and identity_creation_control_proof keep their own registration anti-replay and control-intent roles and never substitute for this object. Adding another branch requires a separately registered publication-proof or independent-witness trust model, threat model and conformance vectors. Complete canonical anchor bytes MUST NOT exceed 1 MiB.
oneOf · oneOf[0] ·
$ref #/$defs/webvh_registration_anchor · $ref #/$defs/webvh_registration_anchor* registration_did_evidence_draft · object · $ref ./registration-did-evidence.schema.json#/$defs/registration_did_evidence_draft
Client-authored historical DID evidence before Account Authority acceptance. control_proof signs canonical_json({context:'ak.registration_did_evidence_control_proof.v1',principal_id,did,adapter_version,method_history_head,version_id,control_key_digest,method_evidence_digest,verification_method,created_at}); method_evidence_digest is sha256 over RFC 8785 JCS of method_evidence. accepted_at is deliberately absent: the Account Authority adds it only after the exact did_operation has been accepted by the registry.
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref ./common-ids.schema.json#/$defs/webvh_didCanonical bare did:webvh identifier used at method-native registration, document and evidence boundaries. Role admission is enforced separately.
pattern:
^did:webvh:[^\s:/?#]+:[^\s/?#]+$* adapter_version ·
const "did:webvh:1.0"enum:
"did:webvh:1.0"* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* control_key_digest ·
stringpattern:
^sha256:[0-9a-f]{64}$* method_evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
const "ak.did.binding_evidence.v1"enum:
"ak.did.binding_evidence.v1"* method ·
$ref #/$defs/method_token · $ref #/$defs/method_token* document_digest ·
string · $ref #/$defs/digestDigest of the resolver's verified normalized DID Document projection (did-usage-and-verification.md section 5.1); never the raw response bytes (those use the differently named raw_document_digest).
pattern:
^(sha256|blake3):[0-9a-f]{64}$* method_proofs · array<$ref #/$defs/webvh_log_evidence>
Closed per-method proof rows; empty for proofless methods (did:key, bare did:web). v1 registers exactly one row kind (webvh_log); receiving any unregistered proof kind fails closed. Rows never reuse resolver response order: each row kind registers its own canonical sort and duplicate-rejection rules.
items ·
$ref #/$defs/webvh_log_evidence · $ref #/$defs/webvh_log_evidence* control_proof · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* control_proof · object · $ref #/$defs/identity_creation_control_proof
Fresh proof signed by the WebVH registration root control key. The verifier derives that key from the accepted did:webvh entry's parameters.updateKeys[0] in principal_registration_anchor and MUST NOT treat a request-supplied key or a DID Document verificationMethod as authority. proof_kind is fixed to did_webvh_inception_update_key and MUST agree with anchor_kind=webvh_registration. The Ed25519 signature covers every field except signature as canonical JSON with domain separator ak.identity_creation_control_proof.v1; signature_algorithm is part of those signed bytes.
* proof_kind ·
string (enum)Closed registration root-key derivation discriminator. v1 permits only did_webvh_inception_update_key paired with anchor_kind=webvh_registration.
enum:
"did_webvh_inception_update_key"* challenge_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* challenge ·
string* purpose ·
const "account_binding_and_pcr_genesis"enum:
"account_binding_and_pcr_genesis"* account_subject ·
string · $ref #/$defs/account_subjectpattern:
^sha256:[0-9a-f]{64}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* registration_anchor_digest ·
string · $ref #/$defs/sha256_digestSHA-256 over RFC 8785 JCS of the complete principal_registration_anchor. The verifier recomputes it from the submitted anchor.
pattern:
^sha256:[0-9a-f]{64}$* did_version_id ·
stringpattern:
^(?!ak:)* control_key_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* pcr_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* realm_create_payload_digest ·
string · $ref #/$defs/sha256_digestCanonical digest of the ak.realm.create payload only. Event ids and envelope digests are forbidden from this transcript.
pattern:
^sha256:[0-9a-f]{64}$* founding_authorize_payload_digest ·
string · $ref #/$defs/sha256_digestCanonical digest of the founding ak.device.authorize payload only. Event ids and envelope digests are forbidden from this transcript.
pattern:
^sha256:[0-9a-f]{64}$* initial_session_request_digest ·
string · $ref #/$defs/sha256_digestSHA-256 digest of RFC 8785 JCS InitialSessionGrantRequest. The embedded session_public_key MUST thumbprint to dpop_jkt; this binds the first Standard grant intent without turning it into a separate root-signed object.
pattern:
^sha256:[0-9a-f]{64}$* genesis_unit_kinds · array · $ref #/$defs/pcr_genesis_unit_kinds
Closed ordered declaration copied into the identity-root creation transcript.
[0] ·
const "ak.realm.create"enum:
"ak.realm.create"[1] ·
const "ak.device.authorize"enum:
"ak.device.authorize"* identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* lease_fence ·
integer* dpop_jkt ·
string · $ref #/$defs/dpop_jktRFC 7638 SHA-256 JWK thumbprint of the holder key, encoded base64url without padding.
pattern:
^[A-Za-z0-9_-]{43}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* origin ·
string (uri) · format=uri · $ref ./common-ids.schema.json#/$defs/web_originCanonical HTTP(S) Web Origin: lowercase scheme/host plus an optional valid non-default effective port. Userinfo, path (including a trailing slash), query, fragment, explicit :80 on HTTP, and explicit :443 on HTTPS are forbidden.
pattern:
^(?:http://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!80$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?|https://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!443$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?)$* trust_domain ·
string · $ref ./common-ids.schema.json#/$defs/trust_domainpattern:
^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verification_key_multibase ·
stringpattern:
^z[1-9A-HJ-NP-Za-km-z]+$* signature_algorithm ·
const "Ed25519"enum:
"Ed25519"* signature ·
string64-byte Ed25519 identity-root signature encoded base64url without padding.
pattern:
^[A-Za-z0-9_-]{86}$* pcr_genesis_unit · object · $ref ./principal-operations.schema.json#/$defs/pcr_genesis_unit
Exact ordered, atomic PCR genesis unit. The first Event is identity-root signed ak.realm.create; the second is founding-device signed ak.device.authorize. Neither signer has an accepted Arkret signer projection before this unit, so neither producer proof is resolved through the ordinary device directory. The first key is resolved only from principal_registration_anchor, registration_did_evidence and identity_creation_control_proof; the second key is resolved only from the root-signed founding descriptor, authorize payload and unit-local candidate overlay. For the second Event proof.verification_method, the verifier parses the DID URL, requires the registered adapter to project its bare DID component to principal_id, and requires its fragment to equal device_id (the complete ak:device UUID string); constructing a DID URL by appending to did_core_id is forbidden, and did:key is not accepted for this slot. The verifier MUST NOT consult or mutate the durable device directory until every check succeeds. These Events are replayable only inside this complete unit and its accepted receipt closure, never as standalone shared-history Events. No partial acceptance is permitted.
* events · array
[0] · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.realm.create"enum:
"ak.realm.create"payload · object
* object ·
object[1] · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.device.authorize"enum:
"ak.device.authorize"* initial_session · object · $ref ./service-operation-dtos.schema.json#/$defs/InitialSessionGrantIntent
Initial Standard SessionGrant intent embedded in identity_creation registration. It reuses the DPoP holder key established by account handoff; Account Authority recomputes RFC 7638 thumbprint of session_public_key and requires equality with the handoff/control-proof dpop_jkt. It is not a separate authorization or credential.
* device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* session_public_key ·
string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcsExact RFC 8785 JCS public JWK for the existing handoff DPoP holder key. Private members are forbidden.
* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$policy_evidence · object · $ref #/$defs/account_registration_policy_evidence
verification_code ·
string · $ref #/$defs/non_empty_stringorganization ·
string · $ref #/$defs/non_empty_stringinvitation_token ·
string · $ref #/$defs/non_empty_stringanyOf · anyOf[7] · object · $ref #/$defs/account_register_outcome
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* state ·
string (enum) · $ref #/$defs/account_stateAccount lifecycle projection; mirrors zh/identity/account-lifecycle.md §3.
enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"* devices · array<$ref #/$defs/device_summary> · $ref #/$defs/device_summaries
items · object · $ref #/$defs/device_summary
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?* device_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref #/$defs/display_nameNFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$* status ·
string (enum)Lifecycle projection only, matching device-lifecycle.md section 14.1. revocation_pending is authority-derived from a durable accepted ak.device.revoke security transaction; trust/evidence quality is reported separately in verification_state.
enum:
"active" "revocation_pending" "revoked" "expired" "generation_fenced"* verification_state ·
string (enum)Trust verification of the device authorization evidence, separate from lifecycle status. A consumer MUST NOT interpret lifecycle status=active as usable authority unless verification_state=verified.
enum:
"verified" "unresolved" "stale"verification_source ·
string (enum)Closed provenance of the verification checkpoint behind verification_state, per device-lifecycle.md section 10.1. genesis is the PCR genesis first device, pairing_code an accepted-device pairing or re-verification ceremony, and recovery an accepted recovery unit replacement device. Login factors, SSO sessions, ordinary session grants and bare server projections MUST NOT mint a checkpoint. Required when verification_state is verified, retained when a previously verified checkpoint went stale, and absent when verification_state is unresolved.
enum:
"genesis" "pairing_code" "recovery"authorized_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$authorized_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$last_seen_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$revoked_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$revocation_states · array<$ref ./device-revocation-state.schema.json#/$defs/device_revocation_gate_record>
All gate-relevant durable revoke records for the exact device/generation, sorted by acceptance_seq and Event id. At most 128 distinct unresolved transactions may be admitted; exact replay consumes no slot, a terminal rejected result removes one pending slot, and an already revoked generation accepts no new transaction. Committing one record makes lifecycle status revoked but MUST NOT hide other surviving pending records.
items · oneOf[2] · $ref ./device-revocation-state.schema.json#/$defs/device_revocation_gate_record
Gate-relevant durable state for an exact device generation. Rejected records are audit history and are excluded; pending and revoked records remain visible together so committing one transaction cannot hide another surviving pending transaction.
oneOf · oneOf[0] ·
$ref #/$defs/device_revocation_pending_state · $ref #/$defs/device_revocation_pending_stateoneOf · oneOf[1] ·
$ref #/$defs/device_revoked_state · $ref #/$defs/device_revoked_stateprimary_handle_claim · object · $ref ./handle-claim.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* schema ·
const "ak.schema.handle_claim.v1"enum:
"ak.schema.handle_claim.v1"* claim ·
$ref #/$defs/handle_claim_core · $ref #/$defs/handle_claim_core* status ·
string (enum)enum:
"pending" "verified" "revoked"* as_of ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verifier_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verified_at ·
$ref #/$defs/nullable_timestamp · $ref #/$defs/nullable_timestamp* revocation · oneOf[2]
oneOf · oneOf[0] ·
$ref #/$defs/handle_claim_revocation · $ref #/$defs/handle_claim_revocationoneOf · oneOf[1] ·
null* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* status_proof · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
stringproof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$allOf · allOf[1] · object
* domain ·
const "ak.handle_claim_status.v1"enum:
"ak.handle_claim_status.v1"* proof_purpose ·
const "status_attestation"enum:
"status_attestation"primary_handle_claim_ref ·
string · $ref #/$defs/handle_claim_refOpaque reference to a signed ak.schema.handle_claim.v1 claim, such as an event ref, issuer-local receipt ref, or content-addressed artifact ref.
handle_claim_digests · array<$ref #/$defs/digest> · $ref #/$defs/handle_claim_digests
items ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$profile · allOf[2] · $ref #/$defs/account_materialized_profile
Materialized Actor Profile returned on the account surface. id is the actor_profile ID derived by retyping the accepted ak.profile.create Event ID; realm_id is the exact Principal Control Realm that carries the profile Event lineage.
allOf · allOf[0] · object · $ref ./actor-profile.schema.json
allOf · allOf[0] ·
?id ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:actor_profile:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.actor_profile.v1"enum:
"ak.schema.actor_profile.v1"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* actor_kind ·
string (enum)Closed Actor classification. agent is reserved exclusively for a controller-provisioned Agent; Applet-created or Applet-hosted automation uses bot; Ghost Actor is provenance rather than an actor_kind and uses integration for an external account/integration mirror or bot for an external bot mirror. MUST NOT include device: a device is an endpoint rather than an Actor principal. actor_kind alone grants no authority; authorization still requires the normative DID, provisioning/registration, Grant and Constraint evidence. See zh/models/actor.md.
enum:
"user" "organization" "team" "agent" "bot" "service" "integration"* display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_128NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$handle ·
string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref string-profiles.schema.json#/$defs/canonical_handleCanonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern:
^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$agent_slug ·
string (arkret-agent-slug) · format=arkret-agent-slug · $ref string-profiles.schema.json#/$defs/agent_slugCanonical controller-scoped Agent Agent selector slug. Maximum 64 Unicode code points in prepared form.
pattern:
^[^\s:@/#?\\]+$avatar_blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$accountable_principal_ids · array<$ref #/$defs/did_core_id>
items ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$resolution · object · $ref ./identity-resolution.schema.json#/$defs/resolution_projection
Read-only current principal did projection derived from the PCR identity resolution typed current result. It is not writable through Actor Profile create/update patches and is not an authorization root.
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$profile_fields · object
bio ·
stringstatus_message ·
stringapplet_interaction ·
$ref #/$defs/applet_interaction · $ref #/$defs/applet_interaction* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$updated_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$allOf · allOf[1] ·
?registration_audit · object · $ref #/$defs/account_registration_audit
* outcome ·
string (enum) · $ref #/$defs/account_registration_audit_outcomeenum:
"accepted" "registration_closed" "verification_code_required" "verification_code_invalid" "organization_not_allowed" "invitation_required" "invitation_invalid" "rate_limited" "duplicate_conflict"* policy_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* evidence · object · $ref #/$defs/account_registration_evidence_summary
verification_code_present ·
booleanexample:
falseinvitation_token_present ·
booleanexample:
falseorganization ·
string · $ref #/$defs/non_empty_stringretry_after_ms ·
integer* binding_receipt · object · $ref #/$defs/account_binding_receipt
allOf · allOf[0] ·
?* binding_state ·
const "bound"enum:
"bound"* binding_kind ·
string (enum)Discriminates the already-published DID proof branch from account-first identity creation.
enum:
"published_did" "identity_creation"* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_subject ·
string · $ref #/$defs/account_subjectpattern:
^sha256:[0-9a-f]{64}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* did_version_id · allOf[2]
Adapter-defined version identifier pinned when the account binding was accepted.
allOf · allOf[0] ·
string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)* control_key_digest ·
string · $ref #/$defs/sha256_digestDigest of the verified current control key that authorized this binding.
pattern:
^sha256:[0-9a-f]{64}$identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idPresent only when binding_kind=identity_creation. The published_did branch creates no identity-creation lease.
pattern:
^[A-Za-z0-9_-]{22,128}$lease_fence ·
integerPresent only when binding_kind=identity_creation.
* operation_status ·
string (enum)enum:
"accepted" "duplicate"* registration_anchor_digest ·
string · $ref #/$defs/sha256_digestSHA-256 of RFC 8785 JCS of the complete frozen typed principal_registration_anchor, including the exact method-native material of the selected branch. For binding_kind=identity_creation it is the submitted anchor; for published_did the Account Authority freezes the anchor it reconstructed from the verified method history at did_version_id. The verifier MUST recompute it from that typed object; serializing a raw JSON transport with different optional-member treatment is not equivalent.
pattern:
^sha256:[0-9a-f]{64}$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
stringproof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$session_grant_outcome · object · $ref ./service-operation-dtos.schema.json#/$defs/SessionGrantOutcome
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$device_id ·
stringpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* session_grant ·
stringShort-lived bearer/session grant bound to the requested principal, device and audience.
* expires_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* session_grant_id ·
string · $ref ./common-ids.schema.json#/$defs/session_grant_idStable id of the issued or rotated session grant. Returned for every grant so the client can reference, refresh, introspect or revoke this exact grant without re-parsing the opaque session_grant.
pattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$* session_public_key ·
string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcsJWK of the holder/session key the grant is bound to (the device holder key). The client needs this to perform RFC 9421 PoP and to derive the DPoP cnf.jkt for /_arkret/self/* requests (api-conventions.md §3.2 / §3.3); returning it avoids a mandatory introspect round-trip before the first self-path request.
* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* granted_scope · array<string>
items ·
stringprevious_session_grant_id ·
string · $ref ./common-ids.schema.json#/$defs/session_grant_idPresent only on refresh. The predecessor grant atomically superseded by this successor.
pattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$pcr_genesis_commits · array
Optional authorized disclosure of the two PCR genesis RealmCommit objects in registered unit order.
[0] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · anyOf[20] · $ref #
Closed request and response DTOs for account self-service operations and Account Authority issuer-ledger account-status publication and resolution.
anyOf · anyOf[0] · object · $ref #/$defs/account_view
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$primary_handle_claim · object · $ref ./handle-claim.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* schema ·
const "ak.schema.handle_claim.v1"enum:
"ak.schema.handle_claim.v1"* claim ·
$ref #/$defs/handle_claim_core · $ref #/$defs/handle_claim_core* status ·
string (enum)enum:
"pending" "verified" "revoked"* as_of ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verifier_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verified_at ·
$ref #/$defs/nullable_timestamp · $ref #/$defs/nullable_timestamp* revocation · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* status_proof · allOf[2]
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
primary_handle_claim_ref ·
string · $ref #/$defs/handle_claim_refOpaque reference to a signed ak.schema.handle_claim.v1 claim, such as an event ref, issuer-local receipt ref, or content-addressed artifact ref.
handle_claim_digests · array<$ref #/$defs/digest> · $ref #/$defs/handle_claim_digests
items ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* state ·
string (enum) · $ref #/$defs/account_stateAccount lifecycle projection; mirrors zh/identity/account-lifecycle.md §3.
enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"* devices · array<$ref #/$defs/device_summary> · $ref #/$defs/device_summaries
items · object · $ref #/$defs/device_summary
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
* device_id ·
…recursion truncated at depth 8; see source schema for full shape
display_name ·
…recursion truncated at depth 8; see source schema for full shape
* status ·
…recursion truncated at depth 8; see source schema for full shape
* verification_state ·
…recursion truncated at depth 8; see source schema for full shape
verification_source ·
…recursion truncated at depth 8; see source schema for full shape
authorized_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
authorized_at ·
…recursion truncated at depth 8; see source schema for full shape
last_seen_at ·
…recursion truncated at depth 8; see source schema for full shape
revoked_at ·
…recursion truncated at depth 8; see source schema for full shape
revocation_states ·
…recursion truncated at depth 8; see source schema for full shape
profile · allOf[2] · $ref #/$defs/account_materialized_profile
Materialized Actor Profile returned on the account surface. id is the actor_profile ID derived by retyping the accepted ak.profile.create Event ID; realm_id is the exact Principal Control Realm that carries the profile Event lineage.
allOf · allOf[0] · object · $ref ./actor-profile.schema.json
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
id ·
…recursion truncated at depth 8; see source schema for full shape
* schema ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* actor_kind ·
…recursion truncated at depth 8; see source schema for full shape
* display_name ·
…recursion truncated at depth 8; see source schema for full shape
handle ·
…recursion truncated at depth 8; see source schema for full shape
agent_slug ·
…recursion truncated at depth 8; see source schema for full shape
avatar_blob_ref ·
…recursion truncated at depth 8; see source schema for full shape
accountable_principal_ids ·
…recursion truncated at depth 8; see source schema for full shape
resolution ·
…recursion truncated at depth 8; see source schema for full shape
profile_fields ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
updated_by ·
…recursion truncated at depth 8; see source schema for full shape
updated_at ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
?is_server_admin ·
booleanTrue when the authenticated principal is a deployment server administrator (the server's configured admin principal set). Operator-only product surfaces (e.g. organization creation) gate their UI on this. Reducer/config-derived, not a stored account field; absent or false means non-admin.
anyOf · anyOf[1] · object · $ref #/$defs/account_handoff_request_body
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* proof · object · $ref #/$defs/account_handoff_authentication_proof
OIDC authorization-code exchange proof used only to create a DPoP-bound account handoff. The signature is made by the same Ed25519 holder key as the request DPoP proof over utf8('ak.account_handoff_authentication_proof.v1\n') || RFC8785_JCS(this object with signature omitted).
* proof_kind ·
const "oidc_code_exchange"enum:
"oidc_code_exchange"* challenge ·
stringAccount Authority-generated challenge persisted with the OIDC authorization transaction and consumed by this exchange.
* request_canonical_digest ·
string · $ref #/$defs/sha256_digestsha256:<lowercase-hex> of SHA-256 over RFC 8785 JCS bytes of the complete account_handoff_request_body with proof.request_canonical_digest and proof.signature omitted.
pattern:
^sha256:[0-9a-f]{64}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* issuer_uri ·
string (uri) · format=uri* client_id · allOf[2]
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* redirect_uri ·
string (uri) · format=uri* state ·
string* nonce ·
string* authorization_code ·
string · $ref #/$defs/non_empty_string* code_verifier ·
string* signature ·
string64-byte Ed25519 signature encoded base64url without padding.
pattern:
^[A-Za-z0-9_-]{86}$anyOf · anyOf[2] · object · $ref #/$defs/account_handoff_outcome
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_handle ·
string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref ./handle-claim.schema.json#/$defs/handle_claim_core/properties/handleCanonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern:
^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$* account_subject ·
string · $ref #/$defs/account_subjectStable subject for the authenticated service account. The client freezes this value from the DPoP-bound handoff and MUST require the identity-binding challenge to echo it byte-for-byte before signing.
pattern:
^sha256:[0-9a-f]{64}$preferred_locale ·
string (enum)Optional private UI-language preference of the authenticated service account. It is returned only in this DPoP-bound handoff response so the client can continue the just-completed authentication flow in the selected language; it MUST NOT be copied into a public actor profile.
enum:
"en" "zh"* account_handoff_grant ·
stringOpaque, short-lived credential bound to the request DPoP key. It is not ak.session.grant and has no refresh-token semantics.
* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* allowed_operations ·
const ["ak.gate.account.command.issue_identity_binding_challenge.v1","ak.gate.account.command.issue_did_binding_challenge.v1","ak.gate.account.command.abandon_identity_creation.v1","ak.gate.account.command.register.v1","ak.gate.account.command.finalize_device_pairing.v1","ak.gate.account.command.issue_session_grant.v1","ak.gate.account.command.issue_recovery_completion_grant.v1"]Closed set of operations this handoff may be presented at. The abandonment command is a member because a never-accepted PCR leaves the holder without a principal, so no principal-bound ak.session.grant can carry them. The device-pairing finalize command is a member for the mirror reason: a fresh device of an already bound account has no accepted-device signer yet, so this handoff is the only sender-constrained credential that can supply the exact AccountId its target proof must sign. Membership here does not widen the handoff into a session credential.
enum:
["ak.gate.account.command.issue_identity_binding_challenge.v1","ak.gate.account.command.issue_did_binding_challenge.v1","ak.gate.account.command.abandon_identity_creation.v1","ak.gate.account.command.register.v1","ak.gate.account.command.finalize_device_pairing.v1","ak.gate.account.command.issue_session_grant.v1","ak.gate.account.command.issue_recovery_completion_grant.v1"]* binding · oneOf[3] · $ref #/$defs/account_handoff_binding
oneOf · oneOf[0] · object
* state ·
…recursion truncated at depth 8; see source schema for full shape
* identity_creation_lease ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* state ·
…recursion truncated at depth 8; see source schema for full shape
* retry_after_ms ·
…recursion truncated at depth 8; see source schema for full shape
* expires_at ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* state ·
…recursion truncated at depth 8; see source schema for full shape
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* did ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[3] · object · $ref #/$defs/account_onboarding_state
* handoff_request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_subject ·
string · $ref #/$defs/account_subjectpattern:
^sha256:[0-9a-f]{64}$* observed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* binding · oneOf[3] · $ref #/$defs/account_handoff_binding
oneOf · oneOf[0] · object
* state ·
…recursion truncated at depth 8; see source schema for full shape
* identity_creation_lease ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* state ·
…recursion truncated at depth 8; see source schema for full shape
* retry_after_ms ·
…recursion truncated at depth 8; see source schema for full shape
* expires_at ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* state ·
…recursion truncated at depth 8; see source schema for full shape
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* did ·
…recursion truncated at depth 8; see source schema for full shape
* goal · object · $ref #/$defs/account_onboarding_goal
* goal ·
const "complete_identity"enum:
"complete_identity"anyOf · anyOf[4] · object · $ref #/$defs/identity_binding_challenge_request_body
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* lease_fence ·
integer* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* principal_registration_anchor · oneOf[1] · $ref ./principal-registration-anchor.schema.json
Closed WebVH registration anchor for a v1 human principal. It is the single primary method-native material that human registration and PCR genesis both consume. v1 human registration supports exactly the active did:webvh adapter and anchor_kind=webvh_registration; every other DID method, including did:key and did:web, fails closed with unsupported_did_method before method-specific parsing. The anchor carries originals, never receipts: a verifier reconstructs did, method_history_head, version_id, the exact normalized DID document and the root verification method/key from the branch material alone, offline, without a current resolver, a database row or an Account Authority attestation. registration_did_evidence and identity_creation_control_proof keep their own registration anti-replay and control-intent roles and never substitute for this object. Adding another branch requires a separately registered publication-proof or independent-witness trust model, threat model and conformance vectors. Complete canonical anchor bytes MUST NOT exceed 1 MiB.
oneOf · oneOf[0] ·
$ref #/$defs/webvh_registration_anchor · $ref #/$defs/webvh_registration_anchor* pcr_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* realm_create_payload_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* founding_authorize_payload_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* initial_session_request_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$anyOf · anyOf[5] · object · $ref #/$defs/identity_binding_challenge_outcome
Only fresh challenge material and domain separation. The authority durably retains the full request, account/handoff subject, lease/fence, DID operation and independently derived pins, PCR/genesis/session digests, audience/origin/trust-domain, and rechecks all of them atomically at registration. The client reconstructs the proof from its frozen submission and authenticated onboarding context.
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* challenge_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* challenge ·
string* purpose ·
const "account_binding_and_pcr_genesis"enum:
"account_binding_and_pcr_genesis"* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$anyOf · anyOf[6] · object · $ref #/$defs/account_register_request_body
Canonical account binding request. Exactly one branch is required: proof binds an already-published did, while identity_creation carries the account-first DID operation and PCR genesis unit. In either branch every repeated principal_id and did in the selected proof/creation objects and genesis initial_resolution MUST equal the outer values byte-for-byte, and the Account Authority MUST independently require project(did)=principal_id before any write.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref #/$defs/display_nameNFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$device_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$proof · object · $ref #/$defs/account_registration_control_proof
Closed control proof for binding an already-published did to principal_id through account register. OIDC, passkey, or agent authentication alone is insufficient to establish DID control. The Account Authority resolves did at high freshness, requires project(did)=principal_id, and selects the current active update key of the entry pinned by did_version_id from verified method history rather than from request-supplied key material. The signature covers every field except signature as canonical JSON with domain separator ak.account_registration_control_proof.v1 and MUST replay the durable challenge issued by ak.gate.account.command.issue_did_binding_challenge.v1.
* proof_kind ·
const "did_bound_signature"enum:
"did_bound_signature"* challenge_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* challenge ·
string* purpose ·
const "account_binding_for_published_did"enum:
"account_binding_for_published_did"* request_canonical_digest ·
string · $ref #/$defs/sha256_digestSHA-256 over RFC 8785 JCS of the complete account_register_request_body with proof.request_canonical_digest and proof.signature omitted.
pattern:
^sha256:[0-9a-f]{64}$* account_subject ·
string · $ref #/$defs/non_empty_stringService account subject this identity is being bound to. Signed so the proof cannot be replayed to bind the same identity to a different account.
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* did_version_id · allOf[2]
Adapter-defined versionId of the entry whose current active update key signed this proof.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* control_key_digest ·
string · $ref #/$defs/sha256_digestSHA-256 over the canonical multikey bytes of the verified current active update key.
pattern:
^sha256:[0-9a-f]{64}$* dpop_jkt ·
string · $ref #/$defs/dpop_jktRFC 7638 SHA-256 JWK thumbprint of the holder key, encoded base64url without padding.
pattern:
^[A-Za-z0-9_-]{43}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* origin ·
string (uri) · format=uri · $ref ./common-ids.schema.json#/$defs/web_originCanonical HTTP(S) Web Origin: lowercase scheme/host plus an optional valid non-default effective port. Userinfo, path (including a trailing slash), query, fragment, explicit :80 on HTTP, and explicit :443 on HTTPS are forbidden.
pattern:
^(?:http://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!80$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?|https://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!443$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?)$* trust_domain ·
string · $ref ./common-ids.schema.json#/$defs/trust_domainpattern:
^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verification_method ·
string · $ref #/$defs/did_urlCurrent active update-key DID URL under did. The verifier parses its bare DID component with the registered adapter and requires the projected did_core_id to equal principal_id; it never appends a fragment to principal_id.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$witness_evidence ·
string · $ref #/$defs/non_empty_stringMethod-native witness / freshness evidence digest for the external DID, required by deployments that do not host the DID themselves.
* signature ·
string · $ref #/$defs/non_empty_stringidentity_creation · object · $ref #/$defs/identity_creation_registration
allOf · allOf[0] · allOf[1] · $ref #/$defs/registration_anchor_control_proof_pairing
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* lease_fence ·
integer* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* principal_registration_anchor · oneOf[1] · $ref ./principal-registration-anchor.schema.json
Closed WebVH registration anchor for a v1 human principal. It is the single primary method-native material that human registration and PCR genesis both consume. v1 human registration supports exactly the active did:webvh adapter and anchor_kind=webvh_registration; every other DID method, including did:key and did:web, fails closed with unsupported_did_method before method-specific parsing. The anchor carries originals, never receipts: a verifier reconstructs did, method_history_head, version_id, the exact normalized DID document and the root verification method/key from the branch material alone, offline, without a current resolver, a database row or an Account Authority attestation. registration_did_evidence and identity_creation_control_proof keep their own registration anti-replay and control-intent roles and never substitute for this object. Adding another branch requires a separately registered publication-proof or independent-witness trust model, threat model and conformance vectors. Complete canonical anchor bytes MUST NOT exceed 1 MiB.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* registration_did_evidence_draft · object · $ref ./registration-did-evidence.schema.json#/$defs/registration_did_evidence_draft
Client-authored historical DID evidence before Account Authority acceptance. control_proof signs canonical_json({context:'ak.registration_did_evidence_control_proof.v1',principal_id,did,adapter_version,method_history_head,version_id,control_key_digest,method_evidence_digest,verification_method,created_at}); method_evidence_digest is sha256 over RFC 8785 JCS of method_evidence. accepted_at is deliberately absent: the Account Authority adds it only after the exact did_operation has been accepted by the registry.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* did ·
…recursion truncated at depth 8; see source schema for full shape
* adapter_version ·
…recursion truncated at depth 8; see source schema for full shape
* method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* version_id ·
…recursion truncated at depth 8; see source schema for full shape
* control_key_digest ·
…recursion truncated at depth 8; see source schema for full shape
* method_evidence ·
…recursion truncated at depth 8; see source schema for full shape
* control_proof ·
…recursion truncated at depth 8; see source schema for full shape
* control_proof · object · $ref #/$defs/identity_creation_control_proof
Fresh proof signed by the WebVH registration root control key. The verifier derives that key from the accepted did:webvh entry's parameters.updateKeys[0] in principal_registration_anchor and MUST NOT treat a request-supplied key or a DID Document verificationMethod as authority. proof_kind is fixed to did_webvh_inception_update_key and MUST agree with anchor_kind=webvh_registration. The Ed25519 signature covers every field except signature as canonical JSON with domain separator ak.identity_creation_control_proof.v1; signature_algorithm is part of those signed bytes.
* proof_kind ·
…recursion truncated at depth 8; see source schema for full shape
* challenge_id ·
…recursion truncated at depth 8; see source schema for full shape
* challenge ·
…recursion truncated at depth 8; see source schema for full shape
* purpose ·
…recursion truncated at depth 8; see source schema for full shape
* account_subject ·
…recursion truncated at depth 8; see source schema for full shape
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* did ·
…recursion truncated at depth 8; see source schema for full shape
* registration_anchor_digest ·
…recursion truncated at depth 8; see source schema for full shape
* did_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* control_key_digest ·
…recursion truncated at depth 8; see source schema for full shape
* pcr_realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_create_payload_digest ·
…recursion truncated at depth 8; see source schema for full shape
* founding_authorize_payload_digest ·
…recursion truncated at depth 8; see source schema for full shape
* initial_session_request_digest ·
…recursion truncated at depth 8; see source schema for full shape
* genesis_unit_kinds ·
…recursion truncated at depth 8; see source schema for full shape
* identity_creation_lease_id ·
…recursion truncated at depth 8; see source schema for full shape
* lease_fence ·
…recursion truncated at depth 8; see source schema for full shape
* dpop_jkt ·
…recursion truncated at depth 8; see source schema for full shape
* audience_id ·
…recursion truncated at depth 8; see source schema for full shape
* origin ·
…recursion truncated at depth 8; see source schema for full shape
* trust_domain ·
…recursion truncated at depth 8; see source schema for full shape
* issued_at ·
…recursion truncated at depth 8; see source schema for full shape
* expires_at ·
…recursion truncated at depth 8; see source schema for full shape
* verification_key_multibase ·
…recursion truncated at depth 8; see source schema for full shape
* signature_algorithm ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
* pcr_genesis_unit · object · $ref ./principal-operations.schema.json#/$defs/pcr_genesis_unit
Exact ordered, atomic PCR genesis unit. The first Event is identity-root signed ak.realm.create; the second is founding-device signed ak.device.authorize. Neither signer has an accepted Arkret signer projection before this unit, so neither producer proof is resolved through the ordinary device directory. The first key is resolved only from principal_registration_anchor, registration_did_evidence and identity_creation_control_proof; the second key is resolved only from the root-signed founding descriptor, authorize payload and unit-local candidate overlay. For the second Event proof.verification_method, the verifier parses the DID URL, requires the registered adapter to project its bare DID component to principal_id, and requires its fragment to equal device_id (the complete ak:device UUID string); constructing a DID URL by appending to did_core_id is forbidden, and did:key is not accepted for this slot. The verifier MUST NOT consult or mutate the durable device directory until every check succeeds. These Events are replayable only inside this complete unit and its accepted receipt closure, never as standalone shared-history Events. No partial acceptance is permitted.
* events ·
…recursion truncated at depth 8; see source schema for full shape
* initial_session · object · $ref ./service-operation-dtos.schema.json#/$defs/InitialSessionGrantIntent
Initial Standard SessionGrant intent embedded in identity_creation registration. It reuses the DPoP holder key established by account handoff; Account Authority recomputes RFC 7638 thumbprint of session_public_key and requires equality with the handoff/control-proof dpop_jkt. It is not a separate authorization or credential.
* device_id ·
…recursion truncated at depth 8; see source schema for full shape
* session_public_key ·
…recursion truncated at depth 8; see source schema for full shape
* audience_id ·
…recursion truncated at depth 8; see source schema for full shape
policy_evidence · object · $ref #/$defs/account_registration_policy_evidence
verification_code ·
string · $ref #/$defs/non_empty_stringorganization ·
string · $ref #/$defs/non_empty_stringinvitation_token ·
string · $ref #/$defs/non_empty_stringanyOf · anyOf[7] · object · $ref #/$defs/account_register_outcome
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* state ·
string (enum) · $ref #/$defs/account_stateAccount lifecycle projection; mirrors zh/identity/account-lifecycle.md §3.
enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"* devices · array<$ref #/$defs/device_summary> · $ref #/$defs/device_summaries
items · object · $ref #/$defs/device_summary
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
* device_id ·
…recursion truncated at depth 8; see source schema for full shape
display_name ·
…recursion truncated at depth 8; see source schema for full shape
* status ·
…recursion truncated at depth 8; see source schema for full shape
* verification_state ·
…recursion truncated at depth 8; see source schema for full shape
verification_source ·
…recursion truncated at depth 8; see source schema for full shape
authorized_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
authorized_at ·
…recursion truncated at depth 8; see source schema for full shape
last_seen_at ·
…recursion truncated at depth 8; see source schema for full shape
revoked_at ·
…recursion truncated at depth 8; see source schema for full shape
revocation_states ·
…recursion truncated at depth 8; see source schema for full shape
primary_handle_claim · object · $ref ./handle-claim.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* schema ·
const "ak.schema.handle_claim.v1"enum:
"ak.schema.handle_claim.v1"* claim ·
$ref #/$defs/handle_claim_core · $ref #/$defs/handle_claim_core* status ·
string (enum)enum:
"pending" "verified" "revoked"* as_of ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verifier_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verified_at ·
$ref #/$defs/nullable_timestamp · $ref #/$defs/nullable_timestamp* revocation · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* status_proof · allOf[2]
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
primary_handle_claim_ref ·
string · $ref #/$defs/handle_claim_refOpaque reference to a signed ak.schema.handle_claim.v1 claim, such as an event ref, issuer-local receipt ref, or content-addressed artifact ref.
handle_claim_digests · array<$ref #/$defs/digest> · $ref #/$defs/handle_claim_digests
items ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$profile · allOf[2] · $ref #/$defs/account_materialized_profile
Materialized Actor Profile returned on the account surface. id is the actor_profile ID derived by retyping the accepted ak.profile.create Event ID; realm_id is the exact Principal Control Realm that carries the profile Event lineage.
allOf · allOf[0] · object · $ref ./actor-profile.schema.json
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
id ·
…recursion truncated at depth 8; see source schema for full shape
* schema ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* actor_kind ·
…recursion truncated at depth 8; see source schema for full shape
* display_name ·
…recursion truncated at depth 8; see source schema for full shape
handle ·
…recursion truncated at depth 8; see source schema for full shape
agent_slug ·
…recursion truncated at depth 8; see source schema for full shape
avatar_blob_ref ·
…recursion truncated at depth 8; see source schema for full shape
accountable_principal_ids ·
…recursion truncated at depth 8; see source schema for full shape
resolution ·
…recursion truncated at depth 8; see source schema for full shape
profile_fields ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
updated_by ·
…recursion truncated at depth 8; see source schema for full shape
updated_at ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
?registration_audit · object · $ref #/$defs/account_registration_audit
* outcome ·
string (enum) · $ref #/$defs/account_registration_audit_outcomeenum:
"accepted" "registration_closed" "verification_code_required" "verification_code_invalid" "organization_not_allowed" "invitation_required" "invitation_invalid" "rate_limited" "duplicate_conflict"* policy_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* evidence · object · $ref #/$defs/account_registration_evidence_summary
verification_code_present ·
…recursion truncated at depth 8; see source schema for full shape
invitation_token_present ·
…recursion truncated at depth 8; see source schema for full shape
organization ·
…recursion truncated at depth 8; see source schema for full shape
retry_after_ms ·
integer* binding_receipt · object · $ref #/$defs/account_binding_receipt
allOf · allOf[0] ·
?* binding_state ·
const "bound"enum:
"bound"* binding_kind ·
string (enum)Discriminates the already-published DID proof branch from account-first identity creation.
enum:
"published_did" "identity_creation"* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_subject ·
string · $ref #/$defs/account_subjectpattern:
^sha256:[0-9a-f]{64}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* did_version_id · allOf[2]
Adapter-defined version identifier pinned when the account binding was accepted.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* control_key_digest ·
string · $ref #/$defs/sha256_digestDigest of the verified current control key that authorized this binding.
pattern:
^sha256:[0-9a-f]{64}$identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idPresent only when binding_kind=identity_creation. The published_did branch creates no identity-creation lease.
pattern:
^[A-Za-z0-9_-]{22,128}$lease_fence ·
integerPresent only when binding_kind=identity_creation.
* operation_status ·
string (enum)enum:
"accepted" "duplicate"* registration_anchor_digest ·
string · $ref #/$defs/sha256_digestSHA-256 of RFC 8785 JCS of the complete frozen typed principal_registration_anchor, including the exact method-native material of the selected branch. For binding_kind=identity_creation it is the submitted anchor; for published_did the Account Authority freezes the anchor it reconstructed from the verified method history at did_version_id. The verifier MUST recompute it from that typed object; serializing a raw JSON transport with different optional-member treatment is not equivalent.
pattern:
^sha256:[0-9a-f]{64}$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* payload_digest ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
domain ·
…recursion truncated at depth 8; see source schema for full shape
audience ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
session_grant_outcome · object · $ref ./service-operation-dtos.schema.json#/$defs/SessionGrantOutcome
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
device_id ·
stringpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* session_grant ·
stringShort-lived bearer/session grant bound to the requested principal, device and audience.
* expires_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* session_grant_id ·
string · $ref ./common-ids.schema.json#/$defs/session_grant_idStable id of the issued or rotated session grant. Returned for every grant so the client can reference, refresh, introspect or revoke this exact grant without re-parsing the opaque session_grant.
pattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$* session_public_key ·
string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcsJWK of the holder/session key the grant is bound to (the device holder key). The client needs this to perform RFC 9421 PoP and to derive the DPoP cnf.jkt for /_arkret/self/* requests (api-conventions.md §3.2 / §3.3); returning it avoids a mandatory introspect round-trip before the first self-path request.
* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* granted_scope · array<string>
items ·
…recursion truncated at depth 8; see source schema for full shape
previous_session_grant_id ·
string · $ref ./common-ids.schema.json#/$defs/session_grant_idPresent only on refresh. The predecessor grant atomically superseded by this successor.
pattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$pcr_genesis_commits · array
Optional authorized disclosure of the two PCR genesis RealmCommit objects in registered unit order.
[0] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* authority_ref ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
…recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
[1] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* authority_ref ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
…recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[8] · object · $ref #/$defs/account_update_profile_request_body
Carries exactly one holder-signed profile create-or-update Event and no unsigned profile patch.
* profile_event · allOf[3] · $ref #/$defs/account_profile_event_submission
Holder-signed ordinary Actor Profile Event. (event.actor_id, event.station_id) MUST equal the authenticated session's exact account authority pair, and event.realm_id MUST select that pair's local unique PCR lineage. Accepted-profile presence is evaluated only within that lineage. With no accepted profile there the exact Event MUST be ak.profile.create and its materialized actor_profile ID is derived by retyping event.event_id; the create payload MUST NOT carry id. With an accepted profile there the exact Event MUST be ak.profile.update and payload.target_ref MUST equal that accepted create-derived ID. On create payload.object.principal_id MUST equal event.actor_id; on update the accepted target profile's materialized principal_id MUST equal it. Holder direct proof is required without executed_by, authorization_ref or Applet provenance. Event preconditions MUST be empty; update concurrency uses only the optional signed payload.expected_state_digest. The service submits the exact bytes through authority Event submission and MUST NOT author, rebuild, co-sign, choose an ID or add a concurrency guard. Success exists only after the current PCR governance Station atomically accepts the Event, materializes the profile result and signs its RealmCommit; exact retry returns the stored outcome and the same Commit.
allOf · allOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event ·
…recursion truncated at depth 8; see source schema for full shape
approval_signatures ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* event ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[9] · object · $ref #/$defs/account_update_profile_outcome
Stored outcome after the profile Event is authority-committed and its effect is materialized. profile.id is the create-derived ActorProfile ID, profile.realm_id is event.realm_id, and an update projects updated_by/updated_at from event.actor_id/event.created_at. commit is the exact RealmCommit covering the submitted Event. Exact Event replay returns the byte-identical stored outcome and emits no second account-aggregate delta.
* profile · allOf[2] · $ref #/$defs/account_materialized_profile
Materialized Actor Profile returned on the account surface. id is the actor_profile ID derived by retyping the accepted ak.profile.create Event ID; realm_id is the exact Principal Control Realm that carries the profile Event lineage.
allOf · allOf[0] · object · $ref ./actor-profile.schema.json
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
id ·
…recursion truncated at depth 8; see source schema for full shape
* schema ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* actor_kind ·
…recursion truncated at depth 8; see source schema for full shape
* display_name ·
…recursion truncated at depth 8; see source schema for full shape
handle ·
…recursion truncated at depth 8; see source schema for full shape
agent_slug ·
…recursion truncated at depth 8; see source schema for full shape
avatar_blob_ref ·
…recursion truncated at depth 8; see source schema for full shape
accountable_principal_ids ·
…recursion truncated at depth 8; see source schema for full shape
resolution ·
…recursion truncated at depth 8; see source schema for full shape
profile_fields ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
updated_by ·
…recursion truncated at depth 8; see source schema for full shape
updated_at ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
?* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[10] · object · $ref #/$defs/account_status_record
Immutable Account Authority issuer-ledger record. account_status_record_id is the suite-tagged full digest of RFC 8785 JCS over every field except account_status_record_id and proof. The proof uses context ak.account_status_record_proof.v1 over that same closed unsigned core. principal_control_realm_id is a verified account-binding coordinate only and is never a finality scope.
allOf · allOf[0] ·
?* schema ·
const "ak.schema.account_status_record.v1"enum:
"ak.schema.account_status_record.v1"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* binding_version ·
integerMonotonic Account Authority-local account-to-principal binding generation.
* status_seq ·
integerprevious_account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* status ·
string (enum)enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$reason ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/audit_reason_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$anyOf · anyOf[11] · object · $ref #/$defs/account_status_receipt
Receiver-signed receipt proving durable monotonic replication of one exact AccountStatusRecord. It grants no authority. proof uses context ak.account_status_replication_receipt_proof.v1 and payload_digest over RFC 8785 JCS of every field except proof.
* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* record_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* status_seq ·
integer* receiver_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$anyOf · anyOf[12] · object · $ref #/$defs/account_status_resolve_request_body
Service-authenticated bounded issuer-ledger range request used for freshness checks and predecessor-gap recovery. Unauthorized or unrelated callers receive the operation's non-enumerating authority outcome.
* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* from_status_seq ·
integer* limit ·
integeranyOf · anyOf[13] · object · $ref #/$defs/account_status_resolve_outcome
Contiguous Account Authority issuer-ledger range. Records are ordered by status_seq, begin exactly at from_status_seq when present, and retain the Account Authority's original bytes and proofs.
* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* records · array<$ref #/$defs/account_status_record>
items · object · $ref #/$defs/account_status_record
Immutable Account Authority issuer-ledger record. account_status_record_id is the suite-tagged full digest of RFC 8785 JCS over every field except account_status_record_id and proof. The proof uses context ak.account_status_record_proof.v1 over that same closed unsigned core. principal_control_realm_id is a verified account-binding coordinate only and is never a finality scope.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* schema ·
…recursion truncated at depth 8; see source schema for full shape
* account_status_record_id ·
…recursion truncated at depth 8; see source schema for full shape
* account_authority_id ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
* principal_control_realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* binding_version ·
…recursion truncated at depth 8; see source schema for full shape
* status_seq ·
…recursion truncated at depth 8; see source schema for full shape
previous_account_status_record_id ·
…recursion truncated at depth 8; see source schema for full shape
* status ·
…recursion truncated at depth 8; see source schema for full shape
reason_code ·
…recursion truncated at depth 8; see source schema for full shape
reason ·
…recursion truncated at depth 8; see source schema for full shape
* issued_at ·
…recursion truncated at depth 8; see source schema for full shape
expires_at ·
…recursion truncated at depth 8; see source schema for full shape
* proof ·
…recursion truncated at depth 8; see source schema for full shape
* has_more ·
booleannext_status_seq ·
integeranyOf · anyOf[14] · object · $ref #/$defs/account_status_publication_request_body
* publication · oneOf[2] · $ref #/$defs/account_status_publication
Constrained carrier for one exact AccountStatusRecord. Initial publication carries record only; downstream fanout carries the byte-identical record plus prior receiver receipts. No receiver rebuilds or re-signs the record.
oneOf · oneOf[0] · object
* record ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* record ·
…recursion truncated at depth 8; see source schema for full shape
* account_status_receipts ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[15] · object · $ref #/$defs/account_status_publication_outcome
Durable replica operation state. accepted/duplicate are terminal for this receiver and dependency_missing performs zero writes while identifying the exact next sequence required for gap recovery.
* status ·
string (enum)enum:
"accepted" "duplicate" "dependency_missing"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* status_seq ·
integer* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$current_account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$current_status_seq ·
integerrequired_status_seq ·
integerbarrier_cursor · object · $ref ./cursor.schema.json
Single opaque cursor type. Used as both stream continuation token (incremental sync, list pagination — 'after', 'before', 'prev_cursor', 'next_cursor') and barrier token (read-your-writes wait — 'X-Arkret-Wait-For'). Wire form is always ak:cursor:<base64url(canonical_json)>. Clients MUST treat the wire form as opaque; only the issuing server reads the inner structure.
Integrity contract (normative, see client-sync.md §12 and encoding.md §8 / §8.3.1): v1 core uses the stateful opaque-handle form only — body is {v, purpose, issued_at, expires_at, h} where 'h' is an unguessable server-side handle that the issuing server resolves to the bound (account_id, device_id, filter_digest, purpose, positions, target?, expiry) tuple. account_id is the complete exact AccountId and already contains the Station coordinate; an additional principal_id or service_id identity sidecar MUST NOT be used. Server-side handle lookup IS the integrity check; there is no inline transcript binding to verify on the client side. Servers MUST reject unknown / expired / cross-binding handles with cursor_integrity_invalid.
* v ·
const "1"enum:
"1"* purpose ·
string (enum)Cursor purpose. 'stream' = continuation cursor for incremental sync / list pagination. Used as 'after' on /account/subscribe and as response 'prev_cursor' (older direction) / 'next_cursor' (newer direction) on the list-pagination surfaces. It is NOT used by ak.self.committed_event.read.scan.v1 or ak.peer.committed_event.read.scan.v1: positional stream scan paginates by stream_position, and those surfaces MUST reject an ak:cursor: value (api-conventions.md section 7.2). prev_cursor / next_cursor carry absolute directional meaning regardless of how the request was issued — see api-conventions.md §7.0. 'barrier' = read-your-writes / wait-for-event cursor (use in X-Arkret-Wait-For header to block until local checkpoint covers target.event_id). The handle binding (resolved server-side) carries positions for 'stream' or target for 'barrier'; the wire body does not.
enum:
"stream" "barrier"* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* h ·
stringServer-side opaque handle. The issuing server MUST bind this handle to (account_id, device_id, filter_digest, purpose, positions, target?, expiry) and MUST be able to revoke it. account_id is the complete exact AccountId and already contains the Station coordinate; an additional principal_id or service_id identity sidecar MUST NOT be used. The handle MUST be unguessable (≥ 128 bits entropy after base64url decoding); minLength=22 enforces that floor mechanically (base64url packs 6 bits per character so 128/6 ≈ 21.33 → at least 22 chars of the [A-Za-z0-9_-] alphabet). Servers MUST reject any unknown / expired / cross-binding handle with `cursor_integrity_invalid`. Handle lookup IS the integrity check — there is no MAC or signature to verify inline. This is the moral equivalent of Matrix `next_batch` / MSC4186 `pos` and satisfies the integrity contract without crypto. Servers SHOULD keep the handle → binding map durable across process restarts (see client-sync.md §12.1): a memory-only table is still integrity-correct (unknown handles fail closed) but turns every restart into a fleet-wide forced full resync. For production-grade deployment profiles (small_team / organization / high_security_organization / sovereign_deployment / sovereign_enclave / isolated_sovereign_network) this durability plus TTL GC is a MUST per client-sync.md §12.1; only personal_node keeps it at SHOULD.
pattern:
^[A-Za-z0-9_-]+$(^_[A-Za-z0-9_]*$) ·
?Server-private auxiliary fields (e.g. `_compress` / `_kid` flags). Names MUST start with underscore. In v1 core there is no `_mac` / `_sig` integrity field — handle lookup IS the integrity check — so the underscore namespace is private to the issuing server. `_mac` and `_sig` themselves are explicitly excluded by the top-level `not` clause: a cursor body carrying either MUST be rejected (encoding.md §8.3).
* propagation_state ·
string (enum)enum:
"not_required" "scheduled" "complete" "incomplete"pending_destination_count ·
integerreceipt · object · $ref #/$defs/account_status_receipt
Receiver-signed receipt proving durable monotonic replication of one exact AccountStatusRecord. It grants no authority. proof uses context ak.account_status_replication_receipt_proof.v1 and payload_digest over RFC 8785 JCS of every field except proof.
* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* record_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* status_seq ·
integer* receiver_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* payload_digest ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
domain ·
…recursion truncated at depth 8; see source schema for full shape
audience ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[16] · object · $ref #/$defs/session_revoke_request_body
target_session_grant_id ·
string · $ref #/$defs/session_grant_idpattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$target_device_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$all_sessions ·
const trueenum:
trueproof · object · $ref #/$defs/account_lifecycle_proof
* proof_kind ·
string (enum)enum:
"did_bound_signature" "paired_device_proof" "passkey_assertion" "oidc_code_exchange" "agent_key_proof"* challenge ·
string* request_canonical_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$verification_method ·
string · $ref #/$defs/did_urlpattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature ·
string · $ref #/$defs/non_empty_stringanyOf · anyOf[17] · object · $ref #/$defs/session_revoke_outcome
* revoked_count ·
integerrevoked_session_grant_ids · array<$ref #/$defs/session_grant_id>
items ·
string · $ref #/$defs/session_grant_idpattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$anyOf · anyOf[18] · object · $ref #/$defs/account_request_erasure_request_body
Record the authenticated account holder's explicit request to erase the account (ak.gate.account.command.request_erasure.v1; zh/identity/account-lifecycle.md section 8.1). The Account Authority accepts it directly on the gate surface; acceptance only records the intent and continues the Account Authority's existing erasure_pending issuance flow within the same service — it is neither the signed AccountStatusRecord nor a completion receipt. The Account Authority MUST treat this as a high-risk action and require fresh high-risk action authentication (recent login, WebAuthn, recovery key or a deployment equivalent), judged locally by the Account Authority; re-authentication strength, risk checks and cooldown are deployment governance.
* request_id ·
string · $ref #/$defs/request_idIdempotency identity of the erasure request. Replaying it returns the recorded acceptance outcome and MUST NOT record a second intent; the same request_id with different canonical bytes is duplicate_conflict with zero writes. A different request_id while a live intent whose erasure_pending AccountStatusRecord is not yet signed exists is failed_precondition with reason_code erasure_request_already_pending.
pattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$anyOf · anyOf[19] · object · $ref #/$defs/account_request_erasure_outcome
Acceptance confirmation of a self-initiated account erasure request. At most one live intent record exists per account while the erasure_pending AccountStatusRecord is unsigned. This outcome proves only that the intent is durably recorded; it MUST NOT be read as record issuance or physical erasure completion. Completion is observed through the existing account-status read surface, and physical completion through the erasure receipt rail (zh/identity/account-lifecycle.md section 8).
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* recorded_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$withdrawal_window_ends_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$allOf · allOf[1] · object
context ·
const "ak.realm_commit_signature.v1"enum:
"ak.realm_commit_signature.v1"[1] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · anyOf[20] · $ref #
Closed request and response DTOs for account self-service operations and Account Authority issuer-ledger account-status publication and resolution.
anyOf · anyOf[0] · object · $ref #/$defs/account_view
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$primary_handle_claim · object · $ref ./handle-claim.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* schema ·
const "ak.schema.handle_claim.v1"enum:
"ak.schema.handle_claim.v1"* claim ·
$ref #/$defs/handle_claim_core · $ref #/$defs/handle_claim_core* status ·
string (enum)enum:
"pending" "verified" "revoked"* as_of ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verifier_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verified_at ·
$ref #/$defs/nullable_timestamp · $ref #/$defs/nullable_timestamp* revocation · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* status_proof · allOf[2]
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
primary_handle_claim_ref ·
string · $ref #/$defs/handle_claim_refOpaque reference to a signed ak.schema.handle_claim.v1 claim, such as an event ref, issuer-local receipt ref, or content-addressed artifact ref.
handle_claim_digests · array<$ref #/$defs/digest> · $ref #/$defs/handle_claim_digests
items ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* state ·
string (enum) · $ref #/$defs/account_stateAccount lifecycle projection; mirrors zh/identity/account-lifecycle.md §3.
enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"* devices · array<$ref #/$defs/device_summary> · $ref #/$defs/device_summaries
items · object · $ref #/$defs/device_summary
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
* device_id ·
…recursion truncated at depth 8; see source schema for full shape
display_name ·
…recursion truncated at depth 8; see source schema for full shape
* status ·
…recursion truncated at depth 8; see source schema for full shape
* verification_state ·
…recursion truncated at depth 8; see source schema for full shape
verification_source ·
…recursion truncated at depth 8; see source schema for full shape
authorized_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
authorized_at ·
…recursion truncated at depth 8; see source schema for full shape
last_seen_at ·
…recursion truncated at depth 8; see source schema for full shape
revoked_at ·
…recursion truncated at depth 8; see source schema for full shape
revocation_states ·
…recursion truncated at depth 8; see source schema for full shape
profile · allOf[2] · $ref #/$defs/account_materialized_profile
Materialized Actor Profile returned on the account surface. id is the actor_profile ID derived by retyping the accepted ak.profile.create Event ID; realm_id is the exact Principal Control Realm that carries the profile Event lineage.
allOf · allOf[0] · object · $ref ./actor-profile.schema.json
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
id ·
…recursion truncated at depth 8; see source schema for full shape
* schema ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* actor_kind ·
…recursion truncated at depth 8; see source schema for full shape
* display_name ·
…recursion truncated at depth 8; see source schema for full shape
handle ·
…recursion truncated at depth 8; see source schema for full shape
agent_slug ·
…recursion truncated at depth 8; see source schema for full shape
avatar_blob_ref ·
…recursion truncated at depth 8; see source schema for full shape
accountable_principal_ids ·
…recursion truncated at depth 8; see source schema for full shape
resolution ·
…recursion truncated at depth 8; see source schema for full shape
profile_fields ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
updated_by ·
…recursion truncated at depth 8; see source schema for full shape
updated_at ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
?is_server_admin ·
booleanTrue when the authenticated principal is a deployment server administrator (the server's configured admin principal set). Operator-only product surfaces (e.g. organization creation) gate their UI on this. Reducer/config-derived, not a stored account field; absent or false means non-admin.
anyOf · anyOf[1] · object · $ref #/$defs/account_handoff_request_body
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* proof · object · $ref #/$defs/account_handoff_authentication_proof
OIDC authorization-code exchange proof used only to create a DPoP-bound account handoff. The signature is made by the same Ed25519 holder key as the request DPoP proof over utf8('ak.account_handoff_authentication_proof.v1\n') || RFC8785_JCS(this object with signature omitted).
* proof_kind ·
const "oidc_code_exchange"enum:
"oidc_code_exchange"* challenge ·
stringAccount Authority-generated challenge persisted with the OIDC authorization transaction and consumed by this exchange.
* request_canonical_digest ·
string · $ref #/$defs/sha256_digestsha256:<lowercase-hex> of SHA-256 over RFC 8785 JCS bytes of the complete account_handoff_request_body with proof.request_canonical_digest and proof.signature omitted.
pattern:
^sha256:[0-9a-f]{64}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* issuer_uri ·
string (uri) · format=uri* client_id · allOf[2]
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* redirect_uri ·
string (uri) · format=uri* state ·
string* nonce ·
string* authorization_code ·
string · $ref #/$defs/non_empty_string* code_verifier ·
string* signature ·
string64-byte Ed25519 signature encoded base64url without padding.
pattern:
^[A-Za-z0-9_-]{86}$anyOf · anyOf[2] · object · $ref #/$defs/account_handoff_outcome
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_handle ·
string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref ./handle-claim.schema.json#/$defs/handle_claim_core/properties/handleCanonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern:
^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$* account_subject ·
string · $ref #/$defs/account_subjectStable subject for the authenticated service account. The client freezes this value from the DPoP-bound handoff and MUST require the identity-binding challenge to echo it byte-for-byte before signing.
pattern:
^sha256:[0-9a-f]{64}$preferred_locale ·
string (enum)Optional private UI-language preference of the authenticated service account. It is returned only in this DPoP-bound handoff response so the client can continue the just-completed authentication flow in the selected language; it MUST NOT be copied into a public actor profile.
enum:
"en" "zh"* account_handoff_grant ·
stringOpaque, short-lived credential bound to the request DPoP key. It is not ak.session.grant and has no refresh-token semantics.
* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* allowed_operations ·
const ["ak.gate.account.command.issue_identity_binding_challenge.v1","ak.gate.account.command.issue_did_binding_challenge.v1","ak.gate.account.command.abandon_identity_creation.v1","ak.gate.account.command.register.v1","ak.gate.account.command.finalize_device_pairing.v1","ak.gate.account.command.issue_session_grant.v1","ak.gate.account.command.issue_recovery_completion_grant.v1"]Closed set of operations this handoff may be presented at. The abandonment command is a member because a never-accepted PCR leaves the holder without a principal, so no principal-bound ak.session.grant can carry them. The device-pairing finalize command is a member for the mirror reason: a fresh device of an already bound account has no accepted-device signer yet, so this handoff is the only sender-constrained credential that can supply the exact AccountId its target proof must sign. Membership here does not widen the handoff into a session credential.
enum:
["ak.gate.account.command.issue_identity_binding_challenge.v1","ak.gate.account.command.issue_did_binding_challenge.v1","ak.gate.account.command.abandon_identity_creation.v1","ak.gate.account.command.register.v1","ak.gate.account.command.finalize_device_pairing.v1","ak.gate.account.command.issue_session_grant.v1","ak.gate.account.command.issue_recovery_completion_grant.v1"]* binding · oneOf[3] · $ref #/$defs/account_handoff_binding
oneOf · oneOf[0] · object
* state ·
…recursion truncated at depth 8; see source schema for full shape
* identity_creation_lease ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* state ·
…recursion truncated at depth 8; see source schema for full shape
* retry_after_ms ·
…recursion truncated at depth 8; see source schema for full shape
* expires_at ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* state ·
…recursion truncated at depth 8; see source schema for full shape
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* did ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[3] · object · $ref #/$defs/account_onboarding_state
* handoff_request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_subject ·
string · $ref #/$defs/account_subjectpattern:
^sha256:[0-9a-f]{64}$* observed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* binding · oneOf[3] · $ref #/$defs/account_handoff_binding
oneOf · oneOf[0] · object
* state ·
…recursion truncated at depth 8; see source schema for full shape
* identity_creation_lease ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* state ·
…recursion truncated at depth 8; see source schema for full shape
* retry_after_ms ·
…recursion truncated at depth 8; see source schema for full shape
* expires_at ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* state ·
…recursion truncated at depth 8; see source schema for full shape
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* did ·
…recursion truncated at depth 8; see source schema for full shape
* goal · object · $ref #/$defs/account_onboarding_goal
* goal ·
const "complete_identity"enum:
"complete_identity"anyOf · anyOf[4] · object · $ref #/$defs/identity_binding_challenge_request_body
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* lease_fence ·
integer* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* principal_registration_anchor · oneOf[1] · $ref ./principal-registration-anchor.schema.json
Closed WebVH registration anchor for a v1 human principal. It is the single primary method-native material that human registration and PCR genesis both consume. v1 human registration supports exactly the active did:webvh adapter and anchor_kind=webvh_registration; every other DID method, including did:key and did:web, fails closed with unsupported_did_method before method-specific parsing. The anchor carries originals, never receipts: a verifier reconstructs did, method_history_head, version_id, the exact normalized DID document and the root verification method/key from the branch material alone, offline, without a current resolver, a database row or an Account Authority attestation. registration_did_evidence and identity_creation_control_proof keep their own registration anti-replay and control-intent roles and never substitute for this object. Adding another branch requires a separately registered publication-proof or independent-witness trust model, threat model and conformance vectors. Complete canonical anchor bytes MUST NOT exceed 1 MiB.
oneOf · oneOf[0] ·
$ref #/$defs/webvh_registration_anchor · $ref #/$defs/webvh_registration_anchor* pcr_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* realm_create_payload_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* founding_authorize_payload_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* initial_session_request_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$anyOf · anyOf[5] · object · $ref #/$defs/identity_binding_challenge_outcome
Only fresh challenge material and domain separation. The authority durably retains the full request, account/handoff subject, lease/fence, DID operation and independently derived pins, PCR/genesis/session digests, audience/origin/trust-domain, and rechecks all of them atomically at registration. The client reconstructs the proof from its frozen submission and authenticated onboarding context.
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* challenge_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* challenge ·
string* purpose ·
const "account_binding_and_pcr_genesis"enum:
"account_binding_and_pcr_genesis"* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$anyOf · anyOf[6] · object · $ref #/$defs/account_register_request_body
Canonical account binding request. Exactly one branch is required: proof binds an already-published did, while identity_creation carries the account-first DID operation and PCR genesis unit. In either branch every repeated principal_id and did in the selected proof/creation objects and genesis initial_resolution MUST equal the outer values byte-for-byte, and the Account Authority MUST independently require project(did)=principal_id before any write.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref #/$defs/display_nameNFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$device_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$proof · object · $ref #/$defs/account_registration_control_proof
Closed control proof for binding an already-published did to principal_id through account register. OIDC, passkey, or agent authentication alone is insufficient to establish DID control. The Account Authority resolves did at high freshness, requires project(did)=principal_id, and selects the current active update key of the entry pinned by did_version_id from verified method history rather than from request-supplied key material. The signature covers every field except signature as canonical JSON with domain separator ak.account_registration_control_proof.v1 and MUST replay the durable challenge issued by ak.gate.account.command.issue_did_binding_challenge.v1.
* proof_kind ·
const "did_bound_signature"enum:
"did_bound_signature"* challenge_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* challenge ·
string* purpose ·
const "account_binding_for_published_did"enum:
"account_binding_for_published_did"* request_canonical_digest ·
string · $ref #/$defs/sha256_digestSHA-256 over RFC 8785 JCS of the complete account_register_request_body with proof.request_canonical_digest and proof.signature omitted.
pattern:
^sha256:[0-9a-f]{64}$* account_subject ·
string · $ref #/$defs/non_empty_stringService account subject this identity is being bound to. Signed so the proof cannot be replayed to bind the same identity to a different account.
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* did_version_id · allOf[2]
Adapter-defined versionId of the entry whose current active update key signed this proof.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* control_key_digest ·
string · $ref #/$defs/sha256_digestSHA-256 over the canonical multikey bytes of the verified current active update key.
pattern:
^sha256:[0-9a-f]{64}$* dpop_jkt ·
string · $ref #/$defs/dpop_jktRFC 7638 SHA-256 JWK thumbprint of the holder key, encoded base64url without padding.
pattern:
^[A-Za-z0-9_-]{43}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* origin ·
string (uri) · format=uri · $ref ./common-ids.schema.json#/$defs/web_originCanonical HTTP(S) Web Origin: lowercase scheme/host plus an optional valid non-default effective port. Userinfo, path (including a trailing slash), query, fragment, explicit :80 on HTTP, and explicit :443 on HTTPS are forbidden.
pattern:
^(?:http://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!80$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?|https://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!443$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?)$* trust_domain ·
string · $ref ./common-ids.schema.json#/$defs/trust_domainpattern:
^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verification_method ·
string · $ref #/$defs/did_urlCurrent active update-key DID URL under did. The verifier parses its bare DID component with the registered adapter and requires the projected did_core_id to equal principal_id; it never appends a fragment to principal_id.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$witness_evidence ·
string · $ref #/$defs/non_empty_stringMethod-native witness / freshness evidence digest for the external DID, required by deployments that do not host the DID themselves.
* signature ·
string · $ref #/$defs/non_empty_stringidentity_creation · object · $ref #/$defs/identity_creation_registration
allOf · allOf[0] · allOf[1] · $ref #/$defs/registration_anchor_control_proof_pairing
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* lease_fence ·
integer* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* principal_registration_anchor · oneOf[1] · $ref ./principal-registration-anchor.schema.json
Closed WebVH registration anchor for a v1 human principal. It is the single primary method-native material that human registration and PCR genesis both consume. v1 human registration supports exactly the active did:webvh adapter and anchor_kind=webvh_registration; every other DID method, including did:key and did:web, fails closed with unsupported_did_method before method-specific parsing. The anchor carries originals, never receipts: a verifier reconstructs did, method_history_head, version_id, the exact normalized DID document and the root verification method/key from the branch material alone, offline, without a current resolver, a database row or an Account Authority attestation. registration_did_evidence and identity_creation_control_proof keep their own registration anti-replay and control-intent roles and never substitute for this object. Adding another branch requires a separately registered publication-proof or independent-witness trust model, threat model and conformance vectors. Complete canonical anchor bytes MUST NOT exceed 1 MiB.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* registration_did_evidence_draft · object · $ref ./registration-did-evidence.schema.json#/$defs/registration_did_evidence_draft
Client-authored historical DID evidence before Account Authority acceptance. control_proof signs canonical_json({context:'ak.registration_did_evidence_control_proof.v1',principal_id,did,adapter_version,method_history_head,version_id,control_key_digest,method_evidence_digest,verification_method,created_at}); method_evidence_digest is sha256 over RFC 8785 JCS of method_evidence. accepted_at is deliberately absent: the Account Authority adds it only after the exact did_operation has been accepted by the registry.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* did ·
…recursion truncated at depth 8; see source schema for full shape
* adapter_version ·
…recursion truncated at depth 8; see source schema for full shape
* method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* version_id ·
…recursion truncated at depth 8; see source schema for full shape
* control_key_digest ·
…recursion truncated at depth 8; see source schema for full shape
* method_evidence ·
…recursion truncated at depth 8; see source schema for full shape
* control_proof ·
…recursion truncated at depth 8; see source schema for full shape
* control_proof · object · $ref #/$defs/identity_creation_control_proof
Fresh proof signed by the WebVH registration root control key. The verifier derives that key from the accepted did:webvh entry's parameters.updateKeys[0] in principal_registration_anchor and MUST NOT treat a request-supplied key or a DID Document verificationMethod as authority. proof_kind is fixed to did_webvh_inception_update_key and MUST agree with anchor_kind=webvh_registration. The Ed25519 signature covers every field except signature as canonical JSON with domain separator ak.identity_creation_control_proof.v1; signature_algorithm is part of those signed bytes.
* proof_kind ·
…recursion truncated at depth 8; see source schema for full shape
* challenge_id ·
…recursion truncated at depth 8; see source schema for full shape
* challenge ·
…recursion truncated at depth 8; see source schema for full shape
* purpose ·
…recursion truncated at depth 8; see source schema for full shape
* account_subject ·
…recursion truncated at depth 8; see source schema for full shape
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* did ·
…recursion truncated at depth 8; see source schema for full shape
* registration_anchor_digest ·
…recursion truncated at depth 8; see source schema for full shape
* did_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* control_key_digest ·
…recursion truncated at depth 8; see source schema for full shape
* pcr_realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_create_payload_digest ·
…recursion truncated at depth 8; see source schema for full shape
* founding_authorize_payload_digest ·
…recursion truncated at depth 8; see source schema for full shape
* initial_session_request_digest ·
…recursion truncated at depth 8; see source schema for full shape
* genesis_unit_kinds ·
…recursion truncated at depth 8; see source schema for full shape
* identity_creation_lease_id ·
…recursion truncated at depth 8; see source schema for full shape
* lease_fence ·
…recursion truncated at depth 8; see source schema for full shape
* dpop_jkt ·
…recursion truncated at depth 8; see source schema for full shape
* audience_id ·
…recursion truncated at depth 8; see source schema for full shape
* origin ·
…recursion truncated at depth 8; see source schema for full shape
* trust_domain ·
…recursion truncated at depth 8; see source schema for full shape
* issued_at ·
…recursion truncated at depth 8; see source schema for full shape
* expires_at ·
…recursion truncated at depth 8; see source schema for full shape
* verification_key_multibase ·
…recursion truncated at depth 8; see source schema for full shape
* signature_algorithm ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
* pcr_genesis_unit · object · $ref ./principal-operations.schema.json#/$defs/pcr_genesis_unit
Exact ordered, atomic PCR genesis unit. The first Event is identity-root signed ak.realm.create; the second is founding-device signed ak.device.authorize. Neither signer has an accepted Arkret signer projection before this unit, so neither producer proof is resolved through the ordinary device directory. The first key is resolved only from principal_registration_anchor, registration_did_evidence and identity_creation_control_proof; the second key is resolved only from the root-signed founding descriptor, authorize payload and unit-local candidate overlay. For the second Event proof.verification_method, the verifier parses the DID URL, requires the registered adapter to project its bare DID component to principal_id, and requires its fragment to equal device_id (the complete ak:device UUID string); constructing a DID URL by appending to did_core_id is forbidden, and did:key is not accepted for this slot. The verifier MUST NOT consult or mutate the durable device directory until every check succeeds. These Events are replayable only inside this complete unit and its accepted receipt closure, never as standalone shared-history Events. No partial acceptance is permitted.
* events ·
…recursion truncated at depth 8; see source schema for full shape
* initial_session · object · $ref ./service-operation-dtos.schema.json#/$defs/InitialSessionGrantIntent
Initial Standard SessionGrant intent embedded in identity_creation registration. It reuses the DPoP holder key established by account handoff; Account Authority recomputes RFC 7638 thumbprint of session_public_key and requires equality with the handoff/control-proof dpop_jkt. It is not a separate authorization or credential.
* device_id ·
…recursion truncated at depth 8; see source schema for full shape
* session_public_key ·
…recursion truncated at depth 8; see source schema for full shape
* audience_id ·
…recursion truncated at depth 8; see source schema for full shape
policy_evidence · object · $ref #/$defs/account_registration_policy_evidence
verification_code ·
string · $ref #/$defs/non_empty_stringorganization ·
string · $ref #/$defs/non_empty_stringinvitation_token ·
string · $ref #/$defs/non_empty_stringanyOf · anyOf[7] · object · $ref #/$defs/account_register_outcome
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* state ·
string (enum) · $ref #/$defs/account_stateAccount lifecycle projection; mirrors zh/identity/account-lifecycle.md §3.
enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"* devices · array<$ref #/$defs/device_summary> · $ref #/$defs/device_summaries
items · object · $ref #/$defs/device_summary
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
* device_id ·
…recursion truncated at depth 8; see source schema for full shape
display_name ·
…recursion truncated at depth 8; see source schema for full shape
* status ·
…recursion truncated at depth 8; see source schema for full shape
* verification_state ·
…recursion truncated at depth 8; see source schema for full shape
verification_source ·
…recursion truncated at depth 8; see source schema for full shape
authorized_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
authorized_at ·
…recursion truncated at depth 8; see source schema for full shape
last_seen_at ·
…recursion truncated at depth 8; see source schema for full shape
revoked_at ·
…recursion truncated at depth 8; see source schema for full shape
revocation_states ·
…recursion truncated at depth 8; see source schema for full shape
primary_handle_claim · object · $ref ./handle-claim.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* schema ·
const "ak.schema.handle_claim.v1"enum:
"ak.schema.handle_claim.v1"* claim ·
$ref #/$defs/handle_claim_core · $ref #/$defs/handle_claim_core* status ·
string (enum)enum:
"pending" "verified" "revoked"* as_of ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verifier_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verified_at ·
$ref #/$defs/nullable_timestamp · $ref #/$defs/nullable_timestamp* revocation · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* status_proof · allOf[2]
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
primary_handle_claim_ref ·
string · $ref #/$defs/handle_claim_refOpaque reference to a signed ak.schema.handle_claim.v1 claim, such as an event ref, issuer-local receipt ref, or content-addressed artifact ref.
handle_claim_digests · array<$ref #/$defs/digest> · $ref #/$defs/handle_claim_digests
items ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$profile · allOf[2] · $ref #/$defs/account_materialized_profile
Materialized Actor Profile returned on the account surface. id is the actor_profile ID derived by retyping the accepted ak.profile.create Event ID; realm_id is the exact Principal Control Realm that carries the profile Event lineage.
allOf · allOf[0] · object · $ref ./actor-profile.schema.json
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
id ·
…recursion truncated at depth 8; see source schema for full shape
* schema ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* actor_kind ·
…recursion truncated at depth 8; see source schema for full shape
* display_name ·
…recursion truncated at depth 8; see source schema for full shape
handle ·
…recursion truncated at depth 8; see source schema for full shape
agent_slug ·
…recursion truncated at depth 8; see source schema for full shape
avatar_blob_ref ·
…recursion truncated at depth 8; see source schema for full shape
accountable_principal_ids ·
…recursion truncated at depth 8; see source schema for full shape
resolution ·
…recursion truncated at depth 8; see source schema for full shape
profile_fields ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
updated_by ·
…recursion truncated at depth 8; see source schema for full shape
updated_at ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
?registration_audit · object · $ref #/$defs/account_registration_audit
* outcome ·
string (enum) · $ref #/$defs/account_registration_audit_outcomeenum:
"accepted" "registration_closed" "verification_code_required" "verification_code_invalid" "organization_not_allowed" "invitation_required" "invitation_invalid" "rate_limited" "duplicate_conflict"* policy_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* evidence · object · $ref #/$defs/account_registration_evidence_summary
verification_code_present ·
…recursion truncated at depth 8; see source schema for full shape
invitation_token_present ·
…recursion truncated at depth 8; see source schema for full shape
organization ·
…recursion truncated at depth 8; see source schema for full shape
retry_after_ms ·
integer* binding_receipt · object · $ref #/$defs/account_binding_receipt
allOf · allOf[0] ·
?* binding_state ·
const "bound"enum:
"bound"* binding_kind ·
string (enum)Discriminates the already-published DID proof branch from account-first identity creation.
enum:
"published_did" "identity_creation"* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_subject ·
string · $ref #/$defs/account_subjectpattern:
^sha256:[0-9a-f]{64}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* did_version_id · allOf[2]
Adapter-defined version identifier pinned when the account binding was accepted.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* control_key_digest ·
string · $ref #/$defs/sha256_digestDigest of the verified current control key that authorized this binding.
pattern:
^sha256:[0-9a-f]{64}$identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idPresent only when binding_kind=identity_creation. The published_did branch creates no identity-creation lease.
pattern:
^[A-Za-z0-9_-]{22,128}$lease_fence ·
integerPresent only when binding_kind=identity_creation.
* operation_status ·
string (enum)enum:
"accepted" "duplicate"* registration_anchor_digest ·
string · $ref #/$defs/sha256_digestSHA-256 of RFC 8785 JCS of the complete frozen typed principal_registration_anchor, including the exact method-native material of the selected branch. For binding_kind=identity_creation it is the submitted anchor; for published_did the Account Authority freezes the anchor it reconstructed from the verified method history at did_version_id. The verifier MUST recompute it from that typed object; serializing a raw JSON transport with different optional-member treatment is not equivalent.
pattern:
^sha256:[0-9a-f]{64}$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* payload_digest ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
domain ·
…recursion truncated at depth 8; see source schema for full shape
audience ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
session_grant_outcome · object · $ref ./service-operation-dtos.schema.json#/$defs/SessionGrantOutcome
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
device_id ·
stringpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* session_grant ·
stringShort-lived bearer/session grant bound to the requested principal, device and audience.
* expires_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* session_grant_id ·
string · $ref ./common-ids.schema.json#/$defs/session_grant_idStable id of the issued or rotated session grant. Returned for every grant so the client can reference, refresh, introspect or revoke this exact grant without re-parsing the opaque session_grant.
pattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$* session_public_key ·
string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcsJWK of the holder/session key the grant is bound to (the device holder key). The client needs this to perform RFC 9421 PoP and to derive the DPoP cnf.jkt for /_arkret/self/* requests (api-conventions.md §3.2 / §3.3); returning it avoids a mandatory introspect round-trip before the first self-path request.
* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* granted_scope · array<string>
items ·
…recursion truncated at depth 8; see source schema for full shape
previous_session_grant_id ·
string · $ref ./common-ids.schema.json#/$defs/session_grant_idPresent only on refresh. The predecessor grant atomically superseded by this successor.
pattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$pcr_genesis_commits · array
Optional authorized disclosure of the two PCR genesis RealmCommit objects in registered unit order.
[0] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* authority_ref ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
…recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
[1] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* authority_ref ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
…recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[8] · object · $ref #/$defs/account_update_profile_request_body
Carries exactly one holder-signed profile create-or-update Event and no unsigned profile patch.
* profile_event · allOf[3] · $ref #/$defs/account_profile_event_submission
Holder-signed ordinary Actor Profile Event. (event.actor_id, event.station_id) MUST equal the authenticated session's exact account authority pair, and event.realm_id MUST select that pair's local unique PCR lineage. Accepted-profile presence is evaluated only within that lineage. With no accepted profile there the exact Event MUST be ak.profile.create and its materialized actor_profile ID is derived by retyping event.event_id; the create payload MUST NOT carry id. With an accepted profile there the exact Event MUST be ak.profile.update and payload.target_ref MUST equal that accepted create-derived ID. On create payload.object.principal_id MUST equal event.actor_id; on update the accepted target profile's materialized principal_id MUST equal it. Holder direct proof is required without executed_by, authorization_ref or Applet provenance. Event preconditions MUST be empty; update concurrency uses only the optional signed payload.expected_state_digest. The service submits the exact bytes through authority Event submission and MUST NOT author, rebuild, co-sign, choose an ID or add a concurrency guard. Success exists only after the current PCR governance Station atomically accepts the Event, materializes the profile result and signs its RealmCommit; exact retry returns the stored outcome and the same Commit.
allOf · allOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event ·
…recursion truncated at depth 8; see source schema for full shape
approval_signatures ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* event ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[9] · object · $ref #/$defs/account_update_profile_outcome
Stored outcome after the profile Event is authority-committed and its effect is materialized. profile.id is the create-derived ActorProfile ID, profile.realm_id is event.realm_id, and an update projects updated_by/updated_at from event.actor_id/event.created_at. commit is the exact RealmCommit covering the submitted Event. Exact Event replay returns the byte-identical stored outcome and emits no second account-aggregate delta.
* profile · allOf[2] · $ref #/$defs/account_materialized_profile
Materialized Actor Profile returned on the account surface. id is the actor_profile ID derived by retyping the accepted ak.profile.create Event ID; realm_id is the exact Principal Control Realm that carries the profile Event lineage.
allOf · allOf[0] · object · $ref ./actor-profile.schema.json
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
id ·
…recursion truncated at depth 8; see source schema for full shape
* schema ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* actor_kind ·
…recursion truncated at depth 8; see source schema for full shape
* display_name ·
…recursion truncated at depth 8; see source schema for full shape
handle ·
…recursion truncated at depth 8; see source schema for full shape
agent_slug ·
…recursion truncated at depth 8; see source schema for full shape
avatar_blob_ref ·
…recursion truncated at depth 8; see source schema for full shape
accountable_principal_ids ·
…recursion truncated at depth 8; see source schema for full shape
resolution ·
…recursion truncated at depth 8; see source schema for full shape
profile_fields ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
updated_by ·
…recursion truncated at depth 8; see source schema for full shape
updated_at ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
?* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[10] · object · $ref #/$defs/account_status_record
Immutable Account Authority issuer-ledger record. account_status_record_id is the suite-tagged full digest of RFC 8785 JCS over every field except account_status_record_id and proof. The proof uses context ak.account_status_record_proof.v1 over that same closed unsigned core. principal_control_realm_id is a verified account-binding coordinate only and is never a finality scope.
allOf · allOf[0] ·
?* schema ·
const "ak.schema.account_status_record.v1"enum:
"ak.schema.account_status_record.v1"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* binding_version ·
integerMonotonic Account Authority-local account-to-principal binding generation.
* status_seq ·
integerprevious_account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* status ·
string (enum)enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$reason ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/audit_reason_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$anyOf · anyOf[11] · object · $ref #/$defs/account_status_receipt
Receiver-signed receipt proving durable monotonic replication of one exact AccountStatusRecord. It grants no authority. proof uses context ak.account_status_replication_receipt_proof.v1 and payload_digest over RFC 8785 JCS of every field except proof.
* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* record_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* status_seq ·
integer* receiver_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$anyOf · anyOf[12] · object · $ref #/$defs/account_status_resolve_request_body
Service-authenticated bounded issuer-ledger range request used for freshness checks and predecessor-gap recovery. Unauthorized or unrelated callers receive the operation's non-enumerating authority outcome.
* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* from_status_seq ·
integer* limit ·
integeranyOf · anyOf[13] · object · $ref #/$defs/account_status_resolve_outcome
Contiguous Account Authority issuer-ledger range. Records are ordered by status_seq, begin exactly at from_status_seq when present, and retain the Account Authority's original bytes and proofs.
* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* records · array<$ref #/$defs/account_status_record>
items · object · $ref #/$defs/account_status_record
Immutable Account Authority issuer-ledger record. account_status_record_id is the suite-tagged full digest of RFC 8785 JCS over every field except account_status_record_id and proof. The proof uses context ak.account_status_record_proof.v1 over that same closed unsigned core. principal_control_realm_id is a verified account-binding coordinate only and is never a finality scope.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* schema ·
…recursion truncated at depth 8; see source schema for full shape
* account_status_record_id ·
…recursion truncated at depth 8; see source schema for full shape
* account_authority_id ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
* principal_control_realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* binding_version ·
…recursion truncated at depth 8; see source schema for full shape
* status_seq ·
…recursion truncated at depth 8; see source schema for full shape
previous_account_status_record_id ·
…recursion truncated at depth 8; see source schema for full shape
* status ·
…recursion truncated at depth 8; see source schema for full shape
reason_code ·
…recursion truncated at depth 8; see source schema for full shape
reason ·
…recursion truncated at depth 8; see source schema for full shape
* issued_at ·
…recursion truncated at depth 8; see source schema for full shape
expires_at ·
…recursion truncated at depth 8; see source schema for full shape
* proof ·
…recursion truncated at depth 8; see source schema for full shape
* has_more ·
booleannext_status_seq ·
integeranyOf · anyOf[14] · object · $ref #/$defs/account_status_publication_request_body
* publication · oneOf[2] · $ref #/$defs/account_status_publication
Constrained carrier for one exact AccountStatusRecord. Initial publication carries record only; downstream fanout carries the byte-identical record plus prior receiver receipts. No receiver rebuilds or re-signs the record.
oneOf · oneOf[0] · object
* record ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* record ·
…recursion truncated at depth 8; see source schema for full shape
* account_status_receipts ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[15] · object · $ref #/$defs/account_status_publication_outcome
Durable replica operation state. accepted/duplicate are terminal for this receiver and dependency_missing performs zero writes while identifying the exact next sequence required for gap recovery.
* status ·
string (enum)enum:
"accepted" "duplicate" "dependency_missing"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* status_seq ·
integer* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$current_account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$current_status_seq ·
integerrequired_status_seq ·
integerbarrier_cursor · object · $ref ./cursor.schema.json
Single opaque cursor type. Used as both stream continuation token (incremental sync, list pagination — 'after', 'before', 'prev_cursor', 'next_cursor') and barrier token (read-your-writes wait — 'X-Arkret-Wait-For'). Wire form is always ak:cursor:<base64url(canonical_json)>. Clients MUST treat the wire form as opaque; only the issuing server reads the inner structure.
Integrity contract (normative, see client-sync.md §12 and encoding.md §8 / §8.3.1): v1 core uses the stateful opaque-handle form only — body is {v, purpose, issued_at, expires_at, h} where 'h' is an unguessable server-side handle that the issuing server resolves to the bound (account_id, device_id, filter_digest, purpose, positions, target?, expiry) tuple. account_id is the complete exact AccountId and already contains the Station coordinate; an additional principal_id or service_id identity sidecar MUST NOT be used. Server-side handle lookup IS the integrity check; there is no inline transcript binding to verify on the client side. Servers MUST reject unknown / expired / cross-binding handles with cursor_integrity_invalid.
* v ·
const "1"enum:
"1"* purpose ·
string (enum)Cursor purpose. 'stream' = continuation cursor for incremental sync / list pagination. Used as 'after' on /account/subscribe and as response 'prev_cursor' (older direction) / 'next_cursor' (newer direction) on the list-pagination surfaces. It is NOT used by ak.self.committed_event.read.scan.v1 or ak.peer.committed_event.read.scan.v1: positional stream scan paginates by stream_position, and those surfaces MUST reject an ak:cursor: value (api-conventions.md section 7.2). prev_cursor / next_cursor carry absolute directional meaning regardless of how the request was issued — see api-conventions.md §7.0. 'barrier' = read-your-writes / wait-for-event cursor (use in X-Arkret-Wait-For header to block until local checkpoint covers target.event_id). The handle binding (resolved server-side) carries positions for 'stream' or target for 'barrier'; the wire body does not.
enum:
"stream" "barrier"* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* h ·
stringServer-side opaque handle. The issuing server MUST bind this handle to (account_id, device_id, filter_digest, purpose, positions, target?, expiry) and MUST be able to revoke it. account_id is the complete exact AccountId and already contains the Station coordinate; an additional principal_id or service_id identity sidecar MUST NOT be used. The handle MUST be unguessable (≥ 128 bits entropy after base64url decoding); minLength=22 enforces that floor mechanically (base64url packs 6 bits per character so 128/6 ≈ 21.33 → at least 22 chars of the [A-Za-z0-9_-] alphabet). Servers MUST reject any unknown / expired / cross-binding handle with `cursor_integrity_invalid`. Handle lookup IS the integrity check — there is no MAC or signature to verify inline. This is the moral equivalent of Matrix `next_batch` / MSC4186 `pos` and satisfies the integrity contract without crypto. Servers SHOULD keep the handle → binding map durable across process restarts (see client-sync.md §12.1): a memory-only table is still integrity-correct (unknown handles fail closed) but turns every restart into a fleet-wide forced full resync. For production-grade deployment profiles (small_team / organization / high_security_organization / sovereign_deployment / sovereign_enclave / isolated_sovereign_network) this durability plus TTL GC is a MUST per client-sync.md §12.1; only personal_node keeps it at SHOULD.
pattern:
^[A-Za-z0-9_-]+$(^_[A-Za-z0-9_]*$) ·
?Server-private auxiliary fields (e.g. `_compress` / `_kid` flags). Names MUST start with underscore. In v1 core there is no `_mac` / `_sig` integrity field — handle lookup IS the integrity check — so the underscore namespace is private to the issuing server. `_mac` and `_sig` themselves are explicitly excluded by the top-level `not` clause: a cursor body carrying either MUST be rejected (encoding.md §8.3).
* propagation_state ·
string (enum)enum:
"not_required" "scheduled" "complete" "incomplete"pending_destination_count ·
integerreceipt · object · $ref #/$defs/account_status_receipt
Receiver-signed receipt proving durable monotonic replication of one exact AccountStatusRecord. It grants no authority. proof uses context ak.account_status_replication_receipt_proof.v1 and payload_digest over RFC 8785 JCS of every field except proof.
* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* record_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* status_seq ·
integer* receiver_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* payload_digest ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
domain ·
…recursion truncated at depth 8; see source schema for full shape
audience ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[16] · object · $ref #/$defs/session_revoke_request_body
target_session_grant_id ·
string · $ref #/$defs/session_grant_idpattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$target_device_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$all_sessions ·
const trueenum:
trueproof · object · $ref #/$defs/account_lifecycle_proof
* proof_kind ·
string (enum)enum:
"did_bound_signature" "paired_device_proof" "passkey_assertion" "oidc_code_exchange" "agent_key_proof"* challenge ·
string* request_canonical_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$verification_method ·
string · $ref #/$defs/did_urlpattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature ·
string · $ref #/$defs/non_empty_stringanyOf · anyOf[17] · object · $ref #/$defs/session_revoke_outcome
* revoked_count ·
integerrevoked_session_grant_ids · array<$ref #/$defs/session_grant_id>
items ·
string · $ref #/$defs/session_grant_idpattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$anyOf · anyOf[18] · object · $ref #/$defs/account_request_erasure_request_body
Record the authenticated account holder's explicit request to erase the account (ak.gate.account.command.request_erasure.v1; zh/identity/account-lifecycle.md section 8.1). The Account Authority accepts it directly on the gate surface; acceptance only records the intent and continues the Account Authority's existing erasure_pending issuance flow within the same service — it is neither the signed AccountStatusRecord nor a completion receipt. The Account Authority MUST treat this as a high-risk action and require fresh high-risk action authentication (recent login, WebAuthn, recovery key or a deployment equivalent), judged locally by the Account Authority; re-authentication strength, risk checks and cooldown are deployment governance.
* request_id ·
string · $ref #/$defs/request_idIdempotency identity of the erasure request. Replaying it returns the recorded acceptance outcome and MUST NOT record a second intent; the same request_id with different canonical bytes is duplicate_conflict with zero writes. A different request_id while a live intent whose erasure_pending AccountStatusRecord is not yet signed exists is failed_precondition with reason_code erasure_request_already_pending.
pattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$anyOf · anyOf[19] · object · $ref #/$defs/account_request_erasure_outcome
Acceptance confirmation of a self-initiated account erasure request. At most one live intent record exists per account while the erasure_pending AccountStatusRecord is unsigned. This outcome proves only that the intent is durably recorded; it MUST NOT be read as record issuance or physical erasure completion. Completion is observed through the existing account-status read surface, and physical completion through the erasure receipt rail (zh/identity/account-lifecycle.md section 8).
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* recorded_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$withdrawal_window_ends_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$allOf · allOf[1] · object
context ·
const "ak.realm_commit_signature.v1"enum:
"ak.realm_commit_signature.v1"anyOf · anyOf[8] · object · $ref #/$defs/account_update_profile_request_body
Carries exactly one holder-signed profile create-or-update Event and no unsigned profile patch.
* profile_event · allOf[3] · $ref #/$defs/account_profile_event_submission
Holder-signed ordinary Actor Profile Event. (event.actor_id, event.station_id) MUST equal the authenticated session's exact account authority pair, and event.realm_id MUST select that pair's local unique PCR lineage. Accepted-profile presence is evaluated only within that lineage. With no accepted profile there the exact Event MUST be ak.profile.create and its materialized actor_profile ID is derived by retyping event.event_id; the create payload MUST NOT carry id. With an accepted profile there the exact Event MUST be ak.profile.update and payload.target_ref MUST equal that accepted create-derived ID. On create payload.object.principal_id MUST equal event.actor_id; on update the accepted target profile's materialized principal_id MUST equal it. Holder direct proof is required without executed_by, authorization_ref or Applet provenance. Event preconditions MUST be empty; update concurrency uses only the optional signed payload.expected_state_digest. The service submits the exact bytes through authority Event submission and MUST NOT author, rebuild, co-sign, choose an ID or add a concurrency guard. Success exists only after the current PCR governance Station atomically accepts the Event, materializes the profile result and signs its RealmCommit; exact retry returns the stored outcome and the same Commit.
allOf · allOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input ·
$ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input* proof ·
$ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proofallOf · allOf[1] · object
* event · object
preconditions ·
?This account self-service surface forbids Event preconditions. ak.profile.update concurrency is expressed only by the optional signed payload.expected_state_digest.
allOf · allOf[2] · oneOf[2]
oneOf · oneOf[0] · object
event · object
kind ·
const "ak.profile.create"enum:
"ak.profile.create"payload · object
* object ·
?oneOf · oneOf[1] · object
event · object
kind ·
const "ak.profile.update"enum:
"ak.profile.update"payload · object
* patch · allOf[1] · $ref #/$defs/profile_patch
allOf · allOf[0] ·
object · $ref ./patch.schema.jsonCanonical field-patch format embedded in event payloads (typically at payload.patch) for non-create updates. Its only protocol identifier is ak.schema.patch.v1. Grammar, parser responsibilities, redactable content-slot protection and reducer-managed-field protection are defined normatively in zh/models/event-and-patch.md §4; the machine-readable path set an $op="unset" MUST NOT remove is registry/redactable-field-registry.json, which this schema deliberately does not restate.
anyOf · anyOf[9] · object · $ref #/$defs/account_update_profile_outcome
Stored outcome after the profile Event is authority-committed and its effect is materialized. profile.id is the create-derived ActorProfile ID, profile.realm_id is event.realm_id, and an update projects updated_by/updated_at from event.actor_id/event.created_at. commit is the exact RealmCommit covering the submitted Event. Exact Event replay returns the byte-identical stored outcome and emits no second account-aggregate delta.
* profile · allOf[2] · $ref #/$defs/account_materialized_profile
Materialized Actor Profile returned on the account surface. id is the actor_profile ID derived by retyping the accepted ak.profile.create Event ID; realm_id is the exact Principal Control Realm that carries the profile Event lineage.
allOf · allOf[0] · object · $ref ./actor-profile.schema.json
allOf · allOf[0] ·
?id ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:actor_profile:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.actor_profile.v1"enum:
"ak.schema.actor_profile.v1"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* actor_kind ·
string (enum)Closed Actor classification. agent is reserved exclusively for a controller-provisioned Agent; Applet-created or Applet-hosted automation uses bot; Ghost Actor is provenance rather than an actor_kind and uses integration for an external account/integration mirror or bot for an external bot mirror. MUST NOT include device: a device is an endpoint rather than an Actor principal. actor_kind alone grants no authority; authorization still requires the normative DID, provisioning/registration, Grant and Constraint evidence. See zh/models/actor.md.
enum:
"user" "organization" "team" "agent" "bot" "service" "integration"* display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_128NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$handle ·
string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref string-profiles.schema.json#/$defs/canonical_handleCanonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern:
^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$agent_slug ·
string (arkret-agent-slug) · format=arkret-agent-slug · $ref string-profiles.schema.json#/$defs/agent_slugCanonical controller-scoped Agent Agent selector slug. Maximum 64 Unicode code points in prepared form.
pattern:
^[^\s:@/#?\\]+$avatar_blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$accountable_principal_ids · array<$ref #/$defs/did_core_id>
items ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$resolution · object · $ref ./identity-resolution.schema.json#/$defs/resolution_projection
Read-only current principal did projection derived from the PCR identity resolution typed current result. It is not writable through Actor Profile create/update patches and is not an authorization root.
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$profile_fields · object
bio ·
stringstatus_message ·
stringapplet_interaction ·
$ref #/$defs/applet_interaction · $ref #/$defs/applet_interaction* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$updated_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$allOf · allOf[1] ·
?* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · anyOf[20] · $ref #
Closed request and response DTOs for account self-service operations and Account Authority issuer-ledger account-status publication and resolution.
anyOf · anyOf[0] · object · $ref #/$defs/account_view
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$primary_handle_claim · object · $ref ./handle-claim.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* schema ·
const "ak.schema.handle_claim.v1"enum:
"ak.schema.handle_claim.v1"* claim ·
$ref #/$defs/handle_claim_core · $ref #/$defs/handle_claim_core* status ·
string (enum)enum:
"pending" "verified" "revoked"* as_of ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verifier_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verified_at ·
$ref #/$defs/nullable_timestamp · $ref #/$defs/nullable_timestamp* revocation · oneOf[2]
oneOf · oneOf[0] ·
$ref #/$defs/handle_claim_revocation · $ref #/$defs/handle_claim_revocationoneOf · oneOf[1] ·
null* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* status_proof · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* payload_digest ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
domain ·
…recursion truncated at depth 8; see source schema for full shape
audience ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* domain ·
…recursion truncated at depth 8; see source schema for full shape
* proof_purpose ·
…recursion truncated at depth 8; see source schema for full shape
primary_handle_claim_ref ·
string · $ref #/$defs/handle_claim_refOpaque reference to a signed ak.schema.handle_claim.v1 claim, such as an event ref, issuer-local receipt ref, or content-addressed artifact ref.
handle_claim_digests · array<$ref #/$defs/digest> · $ref #/$defs/handle_claim_digests
items ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* state ·
string (enum) · $ref #/$defs/account_stateAccount lifecycle projection; mirrors zh/identity/account-lifecycle.md §3.
enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"* devices · array<$ref #/$defs/device_summary> · $ref #/$defs/device_summaries
items · object · $ref #/$defs/device_summary
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?* device_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref #/$defs/display_nameNFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$* status ·
string (enum)Lifecycle projection only, matching device-lifecycle.md section 14.1. revocation_pending is authority-derived from a durable accepted ak.device.revoke security transaction; trust/evidence quality is reported separately in verification_state.
enum:
"active" "revocation_pending" "revoked" "expired" "generation_fenced"* verification_state ·
string (enum)Trust verification of the device authorization evidence, separate from lifecycle status. A consumer MUST NOT interpret lifecycle status=active as usable authority unless verification_state=verified.
enum:
"verified" "unresolved" "stale"verification_source ·
string (enum)Closed provenance of the verification checkpoint behind verification_state, per device-lifecycle.md section 10.1. genesis is the PCR genesis first device, pairing_code an accepted-device pairing or re-verification ceremony, and recovery an accepted recovery unit replacement device. Login factors, SSO sessions, ordinary session grants and bare server projections MUST NOT mint a checkpoint. Required when verification_state is verified, retained when a previously verified checkpoint went stale, and absent when verification_state is unresolved.
enum:
"genesis" "pairing_code" "recovery"authorized_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$authorized_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$last_seen_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$revoked_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$revocation_states · array<$ref ./device-revocation-state.schema.json#/$defs/device_revocation_gate_record>
All gate-relevant durable revoke records for the exact device/generation, sorted by acceptance_seq and Event id. At most 128 distinct unresolved transactions may be admitted; exact replay consumes no slot, a terminal rejected result removes one pending slot, and an already revoked generation accepts no new transaction. Committing one record makes lifecycle status revoked but MUST NOT hide other surviving pending records.
items ·
…recursion truncated at depth 8; see source schema for full shape
profile · allOf[2] · $ref #/$defs/account_materialized_profile
Materialized Actor Profile returned on the account surface. id is the actor_profile ID derived by retyping the accepted ak.profile.create Event ID; realm_id is the exact Principal Control Realm that carries the profile Event lineage.
allOf · allOf[0] · object · $ref ./actor-profile.schema.json
allOf · allOf[0] ·
?id ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:actor_profile:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.actor_profile.v1"enum:
"ak.schema.actor_profile.v1"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* actor_kind ·
string (enum)Closed Actor classification. agent is reserved exclusively for a controller-provisioned Agent; Applet-created or Applet-hosted automation uses bot; Ghost Actor is provenance rather than an actor_kind and uses integration for an external account/integration mirror or bot for an external bot mirror. MUST NOT include device: a device is an endpoint rather than an Actor principal. actor_kind alone grants no authority; authorization still requires the normative DID, provisioning/registration, Grant and Constraint evidence. See zh/models/actor.md.
enum:
"user" "organization" "team" "agent" "bot" "service" "integration"* display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_128NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$handle ·
string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref string-profiles.schema.json#/$defs/canonical_handleCanonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern:
^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$agent_slug ·
string (arkret-agent-slug) · format=arkret-agent-slug · $ref string-profiles.schema.json#/$defs/agent_slugCanonical controller-scoped Agent Agent selector slug. Maximum 64 Unicode code points in prepared form.
pattern:
^[^\s:@/#?\\]+$avatar_blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$accountable_principal_ids · array<$ref #/$defs/did_core_id>
items ·
…recursion truncated at depth 8; see source schema for full shape
resolution · object · $ref ./identity-resolution.schema.json#/$defs/resolution_projection
Read-only current principal did projection derived from the PCR identity resolution typed current result. It is not writable through Actor Profile create/update patches and is not an authorization root.
* did ·
…recursion truncated at depth 8; see source schema for full shape
* method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* version_id ·
…recursion truncated at depth 8; see source schema for full shape
* resolution_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* updated_at ·
…recursion truncated at depth 8; see source schema for full shape
profile_fields · object
bio ·
…recursion truncated at depth 8; see source schema for full shape
status_message ·
…recursion truncated at depth 8; see source schema for full shape
applet_interaction ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
updated_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$allOf · allOf[1] ·
?is_server_admin ·
booleanTrue when the authenticated principal is a deployment server administrator (the server's configured admin principal set). Operator-only product surfaces (e.g. organization creation) gate their UI on this. Reducer/config-derived, not a stored account field; absent or false means non-admin.
anyOf · anyOf[1] · object · $ref #/$defs/account_handoff_request_body
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* proof · object · $ref #/$defs/account_handoff_authentication_proof
OIDC authorization-code exchange proof used only to create a DPoP-bound account handoff. The signature is made by the same Ed25519 holder key as the request DPoP proof over utf8('ak.account_handoff_authentication_proof.v1\n') || RFC8785_JCS(this object with signature omitted).
* proof_kind ·
const "oidc_code_exchange"enum:
"oidc_code_exchange"* challenge ·
stringAccount Authority-generated challenge persisted with the OIDC authorization transaction and consumed by this exchange.
* request_canonical_digest ·
string · $ref #/$defs/sha256_digestsha256:<lowercase-hex> of SHA-256 over RFC 8785 JCS bytes of the complete account_handoff_request_body with proof.request_canonical_digest and proof.signature omitted.
pattern:
^sha256:[0-9a-f]{64}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* issuer_uri ·
string (uri) · format=uri* client_id · allOf[2]
allOf · allOf[0] ·
string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)* redirect_uri ·
string (uri) · format=uri* state ·
string* nonce ·
string* authorization_code ·
string · $ref #/$defs/non_empty_string* code_verifier ·
string* signature ·
string64-byte Ed25519 signature encoded base64url without padding.
pattern:
^[A-Za-z0-9_-]{86}$anyOf · anyOf[2] · object · $ref #/$defs/account_handoff_outcome
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_handle ·
string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref ./handle-claim.schema.json#/$defs/handle_claim_core/properties/handleCanonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern:
^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$* account_subject ·
string · $ref #/$defs/account_subjectStable subject for the authenticated service account. The client freezes this value from the DPoP-bound handoff and MUST require the identity-binding challenge to echo it byte-for-byte before signing.
pattern:
^sha256:[0-9a-f]{64}$preferred_locale ·
string (enum)Optional private UI-language preference of the authenticated service account. It is returned only in this DPoP-bound handoff response so the client can continue the just-completed authentication flow in the selected language; it MUST NOT be copied into a public actor profile.
enum:
"en" "zh"* account_handoff_grant ·
stringOpaque, short-lived credential bound to the request DPoP key. It is not ak.session.grant and has no refresh-token semantics.
* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* allowed_operations ·
const ["ak.gate.account.command.issue_identity_binding_challenge.v1","ak.gate.account.command.issue_did_binding_challenge.v1","ak.gate.account.command.abandon_identity_creation.v1","ak.gate.account.command.register.v1","ak.gate.account.command.finalize_device_pairing.v1","ak.gate.account.command.issue_session_grant.v1","ak.gate.account.command.issue_recovery_completion_grant.v1"]Closed set of operations this handoff may be presented at. The abandonment command is a member because a never-accepted PCR leaves the holder without a principal, so no principal-bound ak.session.grant can carry them. The device-pairing finalize command is a member for the mirror reason: a fresh device of an already bound account has no accepted-device signer yet, so this handoff is the only sender-constrained credential that can supply the exact AccountId its target proof must sign. Membership here does not widen the handoff into a session credential.
enum:
["ak.gate.account.command.issue_identity_binding_challenge.v1","ak.gate.account.command.issue_did_binding_challenge.v1","ak.gate.account.command.abandon_identity_creation.v1","ak.gate.account.command.register.v1","ak.gate.account.command.finalize_device_pairing.v1","ak.gate.account.command.issue_session_grant.v1","ak.gate.account.command.issue_recovery_completion_grant.v1"]* binding · oneOf[3] · $ref #/$defs/account_handoff_binding
oneOf · oneOf[0] · object
* state ·
const "identity_creation_active"enum:
"identity_creation_active"* identity_creation_lease · object · $ref #/$defs/identity_creation_lease
* identity_creation_lease_id ·
…recursion truncated at depth 8; see source schema for full shape
* fence ·
…recursion truncated at depth 8; see source schema for full shape
* state ·
…recursion truncated at depth 8; see source schema for full shape
* expires_at ·
…recursion truncated at depth 8; see source schema for full shape
reserved_identity ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* state ·
const "identity_creation_busy"enum:
"identity_creation_busy"* retry_after_ms ·
integer* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[2] · object
* state ·
const "bound"enum:
"bound"* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$anyOf · anyOf[3] · object · $ref #/$defs/account_onboarding_state
* handoff_request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_subject ·
string · $ref #/$defs/account_subjectpattern:
^sha256:[0-9a-f]{64}$* observed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* binding · oneOf[3] · $ref #/$defs/account_handoff_binding
oneOf · oneOf[0] · object
* state ·
const "identity_creation_active"enum:
"identity_creation_active"* identity_creation_lease · object · $ref #/$defs/identity_creation_lease
* identity_creation_lease_id ·
…recursion truncated at depth 8; see source schema for full shape
* fence ·
…recursion truncated at depth 8; see source schema for full shape
* state ·
…recursion truncated at depth 8; see source schema for full shape
* expires_at ·
…recursion truncated at depth 8; see source schema for full shape
reserved_identity ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* state ·
const "identity_creation_busy"enum:
"identity_creation_busy"* retry_after_ms ·
integer* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[2] · object
* state ·
const "bound"enum:
"bound"* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* goal · object · $ref #/$defs/account_onboarding_goal
* goal ·
const "complete_identity"enum:
"complete_identity"anyOf · anyOf[4] · object · $ref #/$defs/identity_binding_challenge_request_body
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* lease_fence ·
integer* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* principal_registration_anchor · oneOf[1] · $ref ./principal-registration-anchor.schema.json
Closed WebVH registration anchor for a v1 human principal. It is the single primary method-native material that human registration and PCR genesis both consume. v1 human registration supports exactly the active did:webvh adapter and anchor_kind=webvh_registration; every other DID method, including did:key and did:web, fails closed with unsupported_did_method before method-specific parsing. The anchor carries originals, never receipts: a verifier reconstructs did, method_history_head, version_id, the exact normalized DID document and the root verification method/key from the branch material alone, offline, without a current resolver, a database row or an Account Authority attestation. registration_did_evidence and identity_creation_control_proof keep their own registration anti-replay and control-intent roles and never substitute for this object. Adding another branch requires a separately registered publication-proof or independent-witness trust model, threat model and conformance vectors. Complete canonical anchor bytes MUST NOT exceed 1 MiB.
oneOf · oneOf[0] ·
$ref #/$defs/webvh_registration_anchor · $ref #/$defs/webvh_registration_anchor* pcr_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* realm_create_payload_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* founding_authorize_payload_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* initial_session_request_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$anyOf · anyOf[5] · object · $ref #/$defs/identity_binding_challenge_outcome
Only fresh challenge material and domain separation. The authority durably retains the full request, account/handoff subject, lease/fence, DID operation and independently derived pins, PCR/genesis/session digests, audience/origin/trust-domain, and rechecks all of them atomically at registration. The client reconstructs the proof from its frozen submission and authenticated onboarding context.
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* challenge_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* challenge ·
string* purpose ·
const "account_binding_and_pcr_genesis"enum:
"account_binding_and_pcr_genesis"* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$anyOf · anyOf[6] · object · $ref #/$defs/account_register_request_body
Canonical account binding request. Exactly one branch is required: proof binds an already-published did, while identity_creation carries the account-first DID operation and PCR genesis unit. In either branch every repeated principal_id and did in the selected proof/creation objects and genesis initial_resolution MUST equal the outer values byte-for-byte, and the Account Authority MUST independently require project(did)=principal_id before any write.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref #/$defs/display_nameNFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$device_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$proof · object · $ref #/$defs/account_registration_control_proof
Closed control proof for binding an already-published did to principal_id through account register. OIDC, passkey, or agent authentication alone is insufficient to establish DID control. The Account Authority resolves did at high freshness, requires project(did)=principal_id, and selects the current active update key of the entry pinned by did_version_id from verified method history rather than from request-supplied key material. The signature covers every field except signature as canonical JSON with domain separator ak.account_registration_control_proof.v1 and MUST replay the durable challenge issued by ak.gate.account.command.issue_did_binding_challenge.v1.
* proof_kind ·
const "did_bound_signature"enum:
"did_bound_signature"* challenge_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* challenge ·
string* purpose ·
const "account_binding_for_published_did"enum:
"account_binding_for_published_did"* request_canonical_digest ·
string · $ref #/$defs/sha256_digestSHA-256 over RFC 8785 JCS of the complete account_register_request_body with proof.request_canonical_digest and proof.signature omitted.
pattern:
^sha256:[0-9a-f]{64}$* account_subject ·
string · $ref #/$defs/non_empty_stringService account subject this identity is being bound to. Signed so the proof cannot be replayed to bind the same identity to a different account.
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* did_version_id · allOf[2]
Adapter-defined versionId of the entry whose current active update key signed this proof.
allOf · allOf[0] ·
string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)* control_key_digest ·
string · $ref #/$defs/sha256_digestSHA-256 over the canonical multikey bytes of the verified current active update key.
pattern:
^sha256:[0-9a-f]{64}$* dpop_jkt ·
string · $ref #/$defs/dpop_jktRFC 7638 SHA-256 JWK thumbprint of the holder key, encoded base64url without padding.
pattern:
^[A-Za-z0-9_-]{43}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* origin ·
string (uri) · format=uri · $ref ./common-ids.schema.json#/$defs/web_originCanonical HTTP(S) Web Origin: lowercase scheme/host plus an optional valid non-default effective port. Userinfo, path (including a trailing slash), query, fragment, explicit :80 on HTTP, and explicit :443 on HTTPS are forbidden.
pattern:
^(?:http://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!80$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?|https://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!443$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?)$* trust_domain ·
string · $ref ./common-ids.schema.json#/$defs/trust_domainpattern:
^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verification_method ·
string · $ref #/$defs/did_urlCurrent active update-key DID URL under did. The verifier parses its bare DID component with the registered adapter and requires the projected did_core_id to equal principal_id; it never appends a fragment to principal_id.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$witness_evidence ·
string · $ref #/$defs/non_empty_stringMethod-native witness / freshness evidence digest for the external DID, required by deployments that do not host the DID themselves.
* signature ·
string · $ref #/$defs/non_empty_stringidentity_creation · object · $ref #/$defs/identity_creation_registration
allOf · allOf[0] · allOf[1] · $ref #/$defs/registration_anchor_control_proof_pairing
allOf · allOf[0] ·
?* identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* lease_fence ·
integer* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* principal_registration_anchor · oneOf[1] · $ref ./principal-registration-anchor.schema.json
Closed WebVH registration anchor for a v1 human principal. It is the single primary method-native material that human registration and PCR genesis both consume. v1 human registration supports exactly the active did:webvh adapter and anchor_kind=webvh_registration; every other DID method, including did:key and did:web, fails closed with unsupported_did_method before method-specific parsing. The anchor carries originals, never receipts: a verifier reconstructs did, method_history_head, version_id, the exact normalized DID document and the root verification method/key from the branch material alone, offline, without a current resolver, a database row or an Account Authority attestation. registration_did_evidence and identity_creation_control_proof keep their own registration anti-replay and control-intent roles and never substitute for this object. Adding another branch requires a separately registered publication-proof or independent-witness trust model, threat model and conformance vectors. Complete canonical anchor bytes MUST NOT exceed 1 MiB.
oneOf · oneOf[0] ·
$ref #/$defs/webvh_registration_anchor · $ref #/$defs/webvh_registration_anchor* registration_did_evidence_draft · object · $ref ./registration-did-evidence.schema.json#/$defs/registration_did_evidence_draft
Client-authored historical DID evidence before Account Authority acceptance. control_proof signs canonical_json({context:'ak.registration_did_evidence_control_proof.v1',principal_id,did,adapter_version,method_history_head,version_id,control_key_digest,method_evidence_digest,verification_method,created_at}); method_evidence_digest is sha256 over RFC 8785 JCS of method_evidence. accepted_at is deliberately absent: the Account Authority adds it only after the exact did_operation has been accepted by the registry.
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref ./common-ids.schema.json#/$defs/webvh_didCanonical bare did:webvh identifier used at method-native registration, document and evidence boundaries. Role admission is enforced separately.
pattern:
^did:webvh:[^\s:/?#]+:[^\s/?#]+$* adapter_version ·
const "did:webvh:1.0"enum:
"did:webvh:1.0"* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* control_key_digest ·
stringpattern:
^sha256:[0-9a-f]{64}$* method_evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* method ·
…recursion truncated at depth 8; see source schema for full shape
* document_digest ·
…recursion truncated at depth 8; see source schema for full shape
* method_proofs ·
…recursion truncated at depth 8; see source schema for full shape
* control_proof · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
* control_proof · object · $ref #/$defs/identity_creation_control_proof
Fresh proof signed by the WebVH registration root control key. The verifier derives that key from the accepted did:webvh entry's parameters.updateKeys[0] in principal_registration_anchor and MUST NOT treat a request-supplied key or a DID Document verificationMethod as authority. proof_kind is fixed to did_webvh_inception_update_key and MUST agree with anchor_kind=webvh_registration. The Ed25519 signature covers every field except signature as canonical JSON with domain separator ak.identity_creation_control_proof.v1; signature_algorithm is part of those signed bytes.
* proof_kind ·
string (enum)Closed registration root-key derivation discriminator. v1 permits only did_webvh_inception_update_key paired with anchor_kind=webvh_registration.
enum:
"did_webvh_inception_update_key"* challenge_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* challenge ·
string* purpose ·
const "account_binding_and_pcr_genesis"enum:
"account_binding_and_pcr_genesis"* account_subject ·
string · $ref #/$defs/account_subjectpattern:
^sha256:[0-9a-f]{64}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* registration_anchor_digest ·
string · $ref #/$defs/sha256_digestSHA-256 over RFC 8785 JCS of the complete principal_registration_anchor. The verifier recomputes it from the submitted anchor.
pattern:
^sha256:[0-9a-f]{64}$* did_version_id ·
stringpattern:
^(?!ak:)* control_key_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* pcr_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* realm_create_payload_digest ·
string · $ref #/$defs/sha256_digestCanonical digest of the ak.realm.create payload only. Event ids and envelope digests are forbidden from this transcript.
pattern:
^sha256:[0-9a-f]{64}$* founding_authorize_payload_digest ·
string · $ref #/$defs/sha256_digestCanonical digest of the founding ak.device.authorize payload only. Event ids and envelope digests are forbidden from this transcript.
pattern:
^sha256:[0-9a-f]{64}$* initial_session_request_digest ·
string · $ref #/$defs/sha256_digestSHA-256 digest of RFC 8785 JCS InitialSessionGrantRequest. The embedded session_public_key MUST thumbprint to dpop_jkt; this binds the first Standard grant intent without turning it into a separate root-signed object.
pattern:
^sha256:[0-9a-f]{64}$* genesis_unit_kinds · array · $ref #/$defs/pcr_genesis_unit_kinds
Closed ordered declaration copied into the identity-root creation transcript.
[0] ·
…recursion truncated at depth 8; see source schema for full shape
[1] ·
…recursion truncated at depth 8; see source schema for full shape
* identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idpattern:
^[A-Za-z0-9_-]{22,128}$* lease_fence ·
integer* dpop_jkt ·
string · $ref #/$defs/dpop_jktRFC 7638 SHA-256 JWK thumbprint of the holder key, encoded base64url without padding.
pattern:
^[A-Za-z0-9_-]{43}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* origin ·
string (uri) · format=uri · $ref ./common-ids.schema.json#/$defs/web_originCanonical HTTP(S) Web Origin: lowercase scheme/host plus an optional valid non-default effective port. Userinfo, path (including a trailing slash), query, fragment, explicit :80 on HTTP, and explicit :443 on HTTPS are forbidden.
pattern:
^(?:http://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!80$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?|https://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!443$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?)$* trust_domain ·
string · $ref ./common-ids.schema.json#/$defs/trust_domainpattern:
^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verification_key_multibase ·
stringpattern:
^z[1-9A-HJ-NP-Za-km-z]+$* signature_algorithm ·
const "Ed25519"enum:
"Ed25519"* signature ·
string64-byte Ed25519 identity-root signature encoded base64url without padding.
pattern:
^[A-Za-z0-9_-]{86}$* pcr_genesis_unit · object · $ref ./principal-operations.schema.json#/$defs/pcr_genesis_unit
Exact ordered, atomic PCR genesis unit. The first Event is identity-root signed ak.realm.create; the second is founding-device signed ak.device.authorize. Neither signer has an accepted Arkret signer projection before this unit, so neither producer proof is resolved through the ordinary device directory. The first key is resolved only from principal_registration_anchor, registration_did_evidence and identity_creation_control_proof; the second key is resolved only from the root-signed founding descriptor, authorize payload and unit-local candidate overlay. For the second Event proof.verification_method, the verifier parses the DID URL, requires the registered adapter to project its bare DID component to principal_id, and requires its fragment to equal device_id (the complete ak:device UUID string); constructing a DID URL by appending to did_core_id is forbidden, and did:key is not accepted for this slot. The verifier MUST NOT consult or mutate the durable device directory until every check succeeds. These Events are replayable only inside this complete unit and its accepted receipt closure, never as standalone shared-history Events. No partial acceptance is permitted.
* events · array
[0] ·
…recursion truncated at depth 8; see source schema for full shape
[1] ·
…recursion truncated at depth 8; see source schema for full shape
* initial_session · object · $ref ./service-operation-dtos.schema.json#/$defs/InitialSessionGrantIntent
Initial Standard SessionGrant intent embedded in identity_creation registration. It reuses the DPoP holder key established by account handoff; Account Authority recomputes RFC 7638 thumbprint of session_public_key and requires equality with the handoff/control-proof dpop_jkt. It is not a separate authorization or credential.
* device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* session_public_key ·
string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcsExact RFC 8785 JCS public JWK for the existing handoff DPoP holder key. Private members are forbidden.
* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$policy_evidence · object · $ref #/$defs/account_registration_policy_evidence
verification_code ·
string · $ref #/$defs/non_empty_stringorganization ·
string · $ref #/$defs/non_empty_stringinvitation_token ·
string · $ref #/$defs/non_empty_stringanyOf · anyOf[7] · object · $ref #/$defs/account_register_outcome
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* state ·
string (enum) · $ref #/$defs/account_stateAccount lifecycle projection; mirrors zh/identity/account-lifecycle.md §3.
enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"* devices · array<$ref #/$defs/device_summary> · $ref #/$defs/device_summaries
items · object · $ref #/$defs/device_summary
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?* device_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref #/$defs/display_nameNFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$* status ·
string (enum)Lifecycle projection only, matching device-lifecycle.md section 14.1. revocation_pending is authority-derived from a durable accepted ak.device.revoke security transaction; trust/evidence quality is reported separately in verification_state.
enum:
"active" "revocation_pending" "revoked" "expired" "generation_fenced"* verification_state ·
string (enum)Trust verification of the device authorization evidence, separate from lifecycle status. A consumer MUST NOT interpret lifecycle status=active as usable authority unless verification_state=verified.
enum:
"verified" "unresolved" "stale"verification_source ·
string (enum)Closed provenance of the verification checkpoint behind verification_state, per device-lifecycle.md section 10.1. genesis is the PCR genesis first device, pairing_code an accepted-device pairing or re-verification ceremony, and recovery an accepted recovery unit replacement device. Login factors, SSO sessions, ordinary session grants and bare server projections MUST NOT mint a checkpoint. Required when verification_state is verified, retained when a previously verified checkpoint went stale, and absent when verification_state is unresolved.
enum:
"genesis" "pairing_code" "recovery"authorized_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$authorized_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$last_seen_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$revoked_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$revocation_states · array<$ref ./device-revocation-state.schema.json#/$defs/device_revocation_gate_record>
All gate-relevant durable revoke records for the exact device/generation, sorted by acceptance_seq and Event id. At most 128 distinct unresolved transactions may be admitted; exact replay consumes no slot, a terminal rejected result removes one pending slot, and an already revoked generation accepts no new transaction. Committing one record makes lifecycle status revoked but MUST NOT hide other surviving pending records.
items ·
…recursion truncated at depth 8; see source schema for full shape
primary_handle_claim · object · $ref ./handle-claim.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* schema ·
const "ak.schema.handle_claim.v1"enum:
"ak.schema.handle_claim.v1"* claim ·
$ref #/$defs/handle_claim_core · $ref #/$defs/handle_claim_core* status ·
string (enum)enum:
"pending" "verified" "revoked"* as_of ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verifier_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verified_at ·
$ref #/$defs/nullable_timestamp · $ref #/$defs/nullable_timestamp* revocation · oneOf[2]
oneOf · oneOf[0] ·
$ref #/$defs/handle_claim_revocation · $ref #/$defs/handle_claim_revocationoneOf · oneOf[1] ·
null* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* status_proof · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* payload_digest ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
domain ·
…recursion truncated at depth 8; see source schema for full shape
audience ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* domain ·
…recursion truncated at depth 8; see source schema for full shape
* proof_purpose ·
…recursion truncated at depth 8; see source schema for full shape
primary_handle_claim_ref ·
string · $ref #/$defs/handle_claim_refOpaque reference to a signed ak.schema.handle_claim.v1 claim, such as an event ref, issuer-local receipt ref, or content-addressed artifact ref.
handle_claim_digests · array<$ref #/$defs/digest> · $ref #/$defs/handle_claim_digests
items ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$profile · allOf[2] · $ref #/$defs/account_materialized_profile
Materialized Actor Profile returned on the account surface. id is the actor_profile ID derived by retyping the accepted ak.profile.create Event ID; realm_id is the exact Principal Control Realm that carries the profile Event lineage.
allOf · allOf[0] · object · $ref ./actor-profile.schema.json
allOf · allOf[0] ·
?id ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:actor_profile:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.actor_profile.v1"enum:
"ak.schema.actor_profile.v1"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* actor_kind ·
string (enum)Closed Actor classification. agent is reserved exclusively for a controller-provisioned Agent; Applet-created or Applet-hosted automation uses bot; Ghost Actor is provenance rather than an actor_kind and uses integration for an external account/integration mirror or bot for an external bot mirror. MUST NOT include device: a device is an endpoint rather than an Actor principal. actor_kind alone grants no authority; authorization still requires the normative DID, provisioning/registration, Grant and Constraint evidence. See zh/models/actor.md.
enum:
"user" "organization" "team" "agent" "bot" "service" "integration"* display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_128NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$handle ·
string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref string-profiles.schema.json#/$defs/canonical_handleCanonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern:
^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$agent_slug ·
string (arkret-agent-slug) · format=arkret-agent-slug · $ref string-profiles.schema.json#/$defs/agent_slugCanonical controller-scoped Agent Agent selector slug. Maximum 64 Unicode code points in prepared form.
pattern:
^[^\s:@/#?\\]+$avatar_blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$accountable_principal_ids · array<$ref #/$defs/did_core_id>
items ·
…recursion truncated at depth 8; see source schema for full shape
resolution · object · $ref ./identity-resolution.schema.json#/$defs/resolution_projection
Read-only current principal did projection derived from the PCR identity resolution typed current result. It is not writable through Actor Profile create/update patches and is not an authorization root.
* did ·
…recursion truncated at depth 8; see source schema for full shape
* method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* version_id ·
…recursion truncated at depth 8; see source schema for full shape
* resolution_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* updated_at ·
…recursion truncated at depth 8; see source schema for full shape
profile_fields · object
bio ·
…recursion truncated at depth 8; see source schema for full shape
status_message ·
…recursion truncated at depth 8; see source schema for full shape
applet_interaction ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
updated_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$allOf · allOf[1] ·
?registration_audit · object · $ref #/$defs/account_registration_audit
* outcome ·
string (enum) · $ref #/$defs/account_registration_audit_outcomeenum:
"accepted" "registration_closed" "verification_code_required" "verification_code_invalid" "organization_not_allowed" "invitation_required" "invitation_invalid" "rate_limited" "duplicate_conflict"* policy_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* evidence · object · $ref #/$defs/account_registration_evidence_summary
verification_code_present ·
booleanexample:
falseinvitation_token_present ·
booleanexample:
falseorganization ·
string · $ref #/$defs/non_empty_stringretry_after_ms ·
integer* binding_receipt · object · $ref #/$defs/account_binding_receipt
allOf · allOf[0] ·
?* binding_state ·
const "bound"enum:
"bound"* binding_kind ·
string (enum)Discriminates the already-published DID proof branch from account-first identity creation.
enum:
"published_did" "identity_creation"* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_subject ·
string · $ref #/$defs/account_subjectpattern:
^sha256:[0-9a-f]{64}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref #/$defs/didCanonical bare DID for a v1 human principal anchor. The method set is derived from role_requirements.human_principal_anchor and contains exactly did:webvh. Every other method, including did:key and did:web, MUST fail closed with unsupported_did_method here rather than inside a method parser or history replay. Capability checks for relocation, DID-root recovery and ongoing governance are separate.
pattern:
^did:webvh:[^\s#?]+$* did_version_id · allOf[2]
Adapter-defined version identifier pinned when the account binding was accepted.
allOf · allOf[0] ·
string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)* control_key_digest ·
string · $ref #/$defs/sha256_digestDigest of the verified current control key that authorized this binding.
pattern:
^sha256:[0-9a-f]{64}$identity_creation_lease_id ·
string · $ref #/$defs/opaque_registration_idPresent only when binding_kind=identity_creation. The published_did branch creates no identity-creation lease.
pattern:
^[A-Za-z0-9_-]{22,128}$lease_fence ·
integerPresent only when binding_kind=identity_creation.
* operation_status ·
string (enum)enum:
"accepted" "duplicate"* registration_anchor_digest ·
string · $ref #/$defs/sha256_digestSHA-256 of RFC 8785 JCS of the complete frozen typed principal_registration_anchor, including the exact method-native material of the selected branch. For binding_kind=identity_creation it is the submitted anchor; for published_did the Account Authority freezes the anchor it reconstructed from the verified method history at did_version_id. The verifier MUST recompute it from that typed object; serializing a raw JSON transport with different optional-member treatment is not equivalent.
pattern:
^sha256:[0-9a-f]{64}$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$session_grant_outcome · object · $ref ./service-operation-dtos.schema.json#/$defs/SessionGrantOutcome
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$device_id ·
stringpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* session_grant ·
stringShort-lived bearer/session grant bound to the requested principal, device and audience.
* expires_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* session_grant_id ·
string · $ref ./common-ids.schema.json#/$defs/session_grant_idStable id of the issued or rotated session grant. Returned for every grant so the client can reference, refresh, introspect or revoke this exact grant without re-parsing the opaque session_grant.
pattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$* session_public_key ·
string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcsJWK of the holder/session key the grant is bound to (the device holder key). The client needs this to perform RFC 9421 PoP and to derive the DPoP cnf.jkt for /_arkret/self/* requests (api-conventions.md §3.2 / §3.3); returning it avoids a mandatory introspect round-trip before the first self-path request.
* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* granted_scope · array<string>
items ·
stringprevious_session_grant_id ·
string · $ref ./common-ids.schema.json#/$defs/session_grant_idPresent only on refresh. The predecessor grant atomically superseded by this successor.
pattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$pcr_genesis_commits · array
Optional authorized disclosure of the two PCR genesis RealmCommit objects in registered unit order.
[0] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
[1] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[8] · object · $ref #/$defs/account_update_profile_request_body
Carries exactly one holder-signed profile create-or-update Event and no unsigned profile patch.
* profile_event · allOf[3] · $ref #/$defs/account_profile_event_submission
Holder-signed ordinary Actor Profile Event. (event.actor_id, event.station_id) MUST equal the authenticated session's exact account authority pair, and event.realm_id MUST select that pair's local unique PCR lineage. Accepted-profile presence is evaluated only within that lineage. With no accepted profile there the exact Event MUST be ak.profile.create and its materialized actor_profile ID is derived by retyping event.event_id; the create payload MUST NOT carry id. With an accepted profile there the exact Event MUST be ak.profile.update and payload.target_ref MUST equal that accepted create-derived ID. On create payload.object.principal_id MUST equal event.actor_id; on update the accepted target profile's materialized principal_id MUST equal it. Holder direct proof is required without executed_by, authorization_ref or Applet provenance. Event preconditions MUST be empty; update concurrency uses only the optional signed payload.expected_state_digest. The service submits the exact bytes through authority Event submission and MUST NOT author, rebuild, co-sign, choose an ID or add a concurrency guard. Success exists only after the current PCR governance Station atomically accepts the Event, materializes the profile result and signs its RealmCommit; exact retry returns the stored outcome and the same Commit.
allOf · allOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* event · object
preconditions ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] · oneOf[2]
oneOf · oneOf[0] · object
event ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
event ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[9] · object · $ref #/$defs/account_update_profile_outcome
Stored outcome after the profile Event is authority-committed and its effect is materialized. profile.id is the create-derived ActorProfile ID, profile.realm_id is event.realm_id, and an update projects updated_by/updated_at from event.actor_id/event.created_at. commit is the exact RealmCommit covering the submitted Event. Exact Event replay returns the byte-identical stored outcome and emits no second account-aggregate delta.
* profile · allOf[2] · $ref #/$defs/account_materialized_profile
Materialized Actor Profile returned on the account surface. id is the actor_profile ID derived by retyping the accepted ak.profile.create Event ID; realm_id is the exact Principal Control Realm that carries the profile Event lineage.
allOf · allOf[0] · object · $ref ./actor-profile.schema.json
allOf · allOf[0] ·
?id ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:actor_profile:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.actor_profile.v1"enum:
"ak.schema.actor_profile.v1"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* actor_kind ·
string (enum)Closed Actor classification. agent is reserved exclusively for a controller-provisioned Agent; Applet-created or Applet-hosted automation uses bot; Ghost Actor is provenance rather than an actor_kind and uses integration for an external account/integration mirror or bot for an external bot mirror. MUST NOT include device: a device is an endpoint rather than an Actor principal. actor_kind alone grants no authority; authorization still requires the normative DID, provisioning/registration, Grant and Constraint evidence. See zh/models/actor.md.
enum:
"user" "organization" "team" "agent" "bot" "service" "integration"* display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_128NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$handle ·
string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref string-profiles.schema.json#/$defs/canonical_handleCanonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern:
^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$agent_slug ·
string (arkret-agent-slug) · format=arkret-agent-slug · $ref string-profiles.schema.json#/$defs/agent_slugCanonical controller-scoped Agent Agent selector slug. Maximum 64 Unicode code points in prepared form.
pattern:
^[^\s:@/#?\\]+$avatar_blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$accountable_principal_ids · array<$ref #/$defs/did_core_id>
items ·
…recursion truncated at depth 8; see source schema for full shape
resolution · object · $ref ./identity-resolution.schema.json#/$defs/resolution_projection
Read-only current principal did projection derived from the PCR identity resolution typed current result. It is not writable through Actor Profile create/update patches and is not an authorization root.
* did ·
…recursion truncated at depth 8; see source schema for full shape
* method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* version_id ·
…recursion truncated at depth 8; see source schema for full shape
* resolution_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* updated_at ·
…recursion truncated at depth 8; see source schema for full shape
profile_fields · object
bio ·
…recursion truncated at depth 8; see source schema for full shape
status_message ·
…recursion truncated at depth 8; see source schema for full shape
applet_interaction ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
updated_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$allOf · allOf[1] ·
?* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · anyOf[20] · $ref #
Closed request and response DTOs for account self-service operations and Account Authority issuer-ledger account-status publication and resolution.
anyOf · anyOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[10] · object · $ref #/$defs/account_status_record
Immutable Account Authority issuer-ledger record. account_status_record_id is the suite-tagged full digest of RFC 8785 JCS over every field except account_status_record_id and proof. The proof uses context ak.account_status_record_proof.v1 over that same closed unsigned core. principal_control_realm_id is a verified account-binding coordinate only and is never a finality scope.
allOf · allOf[0] ·
?* schema ·
const "ak.schema.account_status_record.v1"enum:
"ak.schema.account_status_record.v1"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* binding_version ·
integerMonotonic Account Authority-local account-to-principal binding generation.
* status_seq ·
integerprevious_account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* status ·
string (enum)enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$reason ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/audit_reason_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$anyOf · anyOf[11] · object · $ref #/$defs/account_status_receipt
Receiver-signed receipt proving durable monotonic replication of one exact AccountStatusRecord. It grants no authority. proof uses context ak.account_status_replication_receipt_proof.v1 and payload_digest over RFC 8785 JCS of every field except proof.
* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* record_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* status_seq ·
integer* receiver_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$anyOf · anyOf[12] · object · $ref #/$defs/account_status_resolve_request_body
Service-authenticated bounded issuer-ledger range request used for freshness checks and predecessor-gap recovery. Unauthorized or unrelated callers receive the operation's non-enumerating authority outcome.
* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* from_status_seq ·
integer* limit ·
integeranyOf · anyOf[13] · object · $ref #/$defs/account_status_resolve_outcome
Contiguous Account Authority issuer-ledger range. Records are ordered by status_seq, begin exactly at from_status_seq when present, and retain the Account Authority's original bytes and proofs.
* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* records · array<$ref #/$defs/account_status_record>
items · object · $ref #/$defs/account_status_record
Immutable Account Authority issuer-ledger record. account_status_record_id is the suite-tagged full digest of RFC 8785 JCS over every field except account_status_record_id and proof. The proof uses context ak.account_status_record_proof.v1 over that same closed unsigned core. principal_control_realm_id is a verified account-binding coordinate only and is never a finality scope.
allOf · allOf[0] ·
?* schema ·
const "ak.schema.account_status_record.v1"enum:
"ak.schema.account_status_record.v1"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* binding_version ·
integerMonotonic Account Authority-local account-to-principal binding generation.
* status_seq ·
integerprevious_account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* status ·
string (enum)enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$reason ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/audit_reason_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* payload_digest ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
domain ·
…recursion truncated at depth 8; see source schema for full shape
audience ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
* has_more ·
booleannext_status_seq ·
integeranyOf · anyOf[14] · object · $ref #/$defs/account_status_publication_request_body
* publication · oneOf[2] · $ref #/$defs/account_status_publication
Constrained carrier for one exact AccountStatusRecord. Initial publication carries record only; downstream fanout carries the byte-identical record plus prior receiver receipts. No receiver rebuilds or re-signs the record.
oneOf · oneOf[0] · object
* record · object · $ref #/$defs/account_status_record
Immutable Account Authority issuer-ledger record. account_status_record_id is the suite-tagged full digest of RFC 8785 JCS over every field except account_status_record_id and proof. The proof uses context ak.account_status_record_proof.v1 over that same closed unsigned core. principal_control_realm_id is a verified account-binding coordinate only and is never a finality scope.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* schema ·
…recursion truncated at depth 8; see source schema for full shape
* account_status_record_id ·
…recursion truncated at depth 8; see source schema for full shape
* account_authority_id ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
* principal_control_realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* binding_version ·
…recursion truncated at depth 8; see source schema for full shape
* status_seq ·
…recursion truncated at depth 8; see source schema for full shape
previous_account_status_record_id ·
…recursion truncated at depth 8; see source schema for full shape
* status ·
…recursion truncated at depth 8; see source schema for full shape
reason_code ·
…recursion truncated at depth 8; see source schema for full shape
reason ·
…recursion truncated at depth 8; see source schema for full shape
* issued_at ·
…recursion truncated at depth 8; see source schema for full shape
expires_at ·
…recursion truncated at depth 8; see source schema for full shape
* proof ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* record · object · $ref #/$defs/account_status_record
Immutable Account Authority issuer-ledger record. account_status_record_id is the suite-tagged full digest of RFC 8785 JCS over every field except account_status_record_id and proof. The proof uses context ak.account_status_record_proof.v1 over that same closed unsigned core. principal_control_realm_id is a verified account-binding coordinate only and is never a finality scope.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* schema ·
…recursion truncated at depth 8; see source schema for full shape
* account_status_record_id ·
…recursion truncated at depth 8; see source schema for full shape
* account_authority_id ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
* principal_control_realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* binding_version ·
…recursion truncated at depth 8; see source schema for full shape
* status_seq ·
…recursion truncated at depth 8; see source schema for full shape
previous_account_status_record_id ·
…recursion truncated at depth 8; see source schema for full shape
* status ·
…recursion truncated at depth 8; see source schema for full shape
reason_code ·
…recursion truncated at depth 8; see source schema for full shape
reason ·
…recursion truncated at depth 8; see source schema for full shape
* issued_at ·
…recursion truncated at depth 8; see source schema for full shape
expires_at ·
…recursion truncated at depth 8; see source schema for full shape
* proof ·
…recursion truncated at depth 8; see source schema for full shape
* account_status_receipts · array<$ref #/$defs/account_status_receipt>
items ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[15] · object · $ref #/$defs/account_status_publication_outcome
Durable replica operation state. accepted/duplicate are terminal for this receiver and dependency_missing performs zero writes while identifying the exact next sequence required for gap recovery.
* status ·
string (enum)enum:
"accepted" "duplicate" "dependency_missing"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* status_seq ·
integer* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$current_account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$current_status_seq ·
integerrequired_status_seq ·
integerbarrier_cursor · object · $ref ./cursor.schema.json
Single opaque cursor type. Used as both stream continuation token (incremental sync, list pagination — 'after', 'before', 'prev_cursor', 'next_cursor') and barrier token (read-your-writes wait — 'X-Arkret-Wait-For'). Wire form is always ak:cursor:<base64url(canonical_json)>. Clients MUST treat the wire form as opaque; only the issuing server reads the inner structure.
Integrity contract (normative, see client-sync.md §12 and encoding.md §8 / §8.3.1): v1 core uses the stateful opaque-handle form only — body is {v, purpose, issued_at, expires_at, h} where 'h' is an unguessable server-side handle that the issuing server resolves to the bound (account_id, device_id, filter_digest, purpose, positions, target?, expiry) tuple. account_id is the complete exact AccountId and already contains the Station coordinate; an additional principal_id or service_id identity sidecar MUST NOT be used. Server-side handle lookup IS the integrity check; there is no inline transcript binding to verify on the client side. Servers MUST reject unknown / expired / cross-binding handles with cursor_integrity_invalid.
* v ·
const "1"enum:
"1"* purpose ·
string (enum)Cursor purpose. 'stream' = continuation cursor for incremental sync / list pagination. Used as 'after' on /account/subscribe and as response 'prev_cursor' (older direction) / 'next_cursor' (newer direction) on the list-pagination surfaces. It is NOT used by ak.self.committed_event.read.scan.v1 or ak.peer.committed_event.read.scan.v1: positional stream scan paginates by stream_position, and those surfaces MUST reject an ak:cursor: value (api-conventions.md section 7.2). prev_cursor / next_cursor carry absolute directional meaning regardless of how the request was issued — see api-conventions.md §7.0. 'barrier' = read-your-writes / wait-for-event cursor (use in X-Arkret-Wait-For header to block until local checkpoint covers target.event_id). The handle binding (resolved server-side) carries positions for 'stream' or target for 'barrier'; the wire body does not.
enum:
"stream" "barrier"* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* h ·
stringServer-side opaque handle. The issuing server MUST bind this handle to (account_id, device_id, filter_digest, purpose, positions, target?, expiry) and MUST be able to revoke it. account_id is the complete exact AccountId and already contains the Station coordinate; an additional principal_id or service_id identity sidecar MUST NOT be used. The handle MUST be unguessable (≥ 128 bits entropy after base64url decoding); minLength=22 enforces that floor mechanically (base64url packs 6 bits per character so 128/6 ≈ 21.33 → at least 22 chars of the [A-Za-z0-9_-] alphabet). Servers MUST reject any unknown / expired / cross-binding handle with `cursor_integrity_invalid`. Handle lookup IS the integrity check — there is no MAC or signature to verify inline. This is the moral equivalent of Matrix `next_batch` / MSC4186 `pos` and satisfies the integrity contract without crypto. Servers SHOULD keep the handle → binding map durable across process restarts (see client-sync.md §12.1): a memory-only table is still integrity-correct (unknown handles fail closed) but turns every restart into a fleet-wide forced full resync. For production-grade deployment profiles (small_team / organization / high_security_organization / sovereign_deployment / sovereign_enclave / isolated_sovereign_network) this durability plus TTL GC is a MUST per client-sync.md §12.1; only personal_node keeps it at SHOULD.
pattern:
^[A-Za-z0-9_-]+$(^_[A-Za-z0-9_]*$) ·
?Server-private auxiliary fields (e.g. `_compress` / `_kid` flags). Names MUST start with underscore. In v1 core there is no `_mac` / `_sig` integrity field — handle lookup IS the integrity check — so the underscore namespace is private to the issuing server. `_mac` and `_sig` themselves are explicitly excluded by the top-level `not` clause: a cursor body carrying either MUST be rejected (encoding.md §8.3).
* propagation_state ·
string (enum)enum:
"not_required" "scheduled" "complete" "incomplete"pending_destination_count ·
integerreceipt · object · $ref #/$defs/account_status_receipt
Receiver-signed receipt proving durable monotonic replication of one exact AccountStatusRecord. It grants no authority. proof uses context ak.account_status_replication_receipt_proof.v1 and payload_digest over RFC 8785 JCS of every field except proof.
* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* record_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* status_seq ·
integer* receiver_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$anyOf · anyOf[16] · object · $ref #/$defs/session_revoke_request_body
target_session_grant_id ·
string · $ref #/$defs/session_grant_idpattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$target_device_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$all_sessions ·
const trueenum:
trueproof · object · $ref #/$defs/account_lifecycle_proof
* proof_kind ·
string (enum)enum:
"did_bound_signature" "paired_device_proof" "passkey_assertion" "oidc_code_exchange" "agent_key_proof"* challenge ·
string* request_canonical_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$verification_method ·
string · $ref #/$defs/did_urlpattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature ·
string · $ref #/$defs/non_empty_stringanyOf · anyOf[17] · object · $ref #/$defs/session_revoke_outcome
* revoked_count ·
integerrevoked_session_grant_ids · array<$ref #/$defs/session_grant_id>
items ·
string · $ref #/$defs/session_grant_idpattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$anyOf · anyOf[18] · object · $ref #/$defs/account_request_erasure_request_body
Record the authenticated account holder's explicit request to erase the account (ak.gate.account.command.request_erasure.v1; zh/identity/account-lifecycle.md section 8.1). The Account Authority accepts it directly on the gate surface; acceptance only records the intent and continues the Account Authority's existing erasure_pending issuance flow within the same service — it is neither the signed AccountStatusRecord nor a completion receipt. The Account Authority MUST treat this as a high-risk action and require fresh high-risk action authentication (recent login, WebAuthn, recovery key or a deployment equivalent), judged locally by the Account Authority; re-authentication strength, risk checks and cooldown are deployment governance.
* request_id ·
string · $ref #/$defs/request_idIdempotency identity of the erasure request. Replaying it returns the recorded acceptance outcome and MUST NOT record a second intent; the same request_id with different canonical bytes is duplicate_conflict with zero writes. A different request_id while a live intent whose erasure_pending AccountStatusRecord is not yet signed exists is failed_precondition with reason_code erasure_request_already_pending.
pattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$anyOf · anyOf[19] · object · $ref #/$defs/account_request_erasure_outcome
Acceptance confirmation of a self-initiated account erasure request. At most one live intent record exists per account while the erasure_pending AccountStatusRecord is unsigned. This outcome proves only that the intent is durably recorded; it MUST NOT be read as record issuance or physical erasure completion. Completion is observed through the existing account-status read surface, and physical completion through the erasure receipt rail (zh/identity/account-lifecycle.md section 8).
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* recorded_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$withdrawal_window_ends_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$allOf · allOf[1] · object
context ·
const "ak.realm_commit_signature.v1"enum:
"ak.realm_commit_signature.v1"anyOf · anyOf[10] · object · $ref #/$defs/account_status_record
Immutable Account Authority issuer-ledger record. account_status_record_id is the suite-tagged full digest of RFC 8785 JCS over every field except account_status_record_id and proof. The proof uses context ak.account_status_record_proof.v1 over that same closed unsigned core. principal_control_realm_id is a verified account-binding coordinate only and is never a finality scope.
allOf · allOf[0] ·
?* schema ·
const "ak.schema.account_status_record.v1"enum:
"ak.schema.account_status_record.v1"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* binding_version ·
integerMonotonic Account Authority-local account-to-principal binding generation.
* status_seq ·
integerprevious_account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* status ·
string (enum)enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$reason ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/audit_reason_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
stringproof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$anyOf · anyOf[11] · object · $ref #/$defs/account_status_receipt
Receiver-signed receipt proving durable monotonic replication of one exact AccountStatusRecord. It grants no authority. proof uses context ak.account_status_replication_receipt_proof.v1 and payload_digest over RFC 8785 JCS of every field except proof.
* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* record_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* status_seq ·
integer* receiver_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
stringproof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$anyOf · anyOf[12] · object · $ref #/$defs/account_status_resolve_request_body
Service-authenticated bounded issuer-ledger range request used for freshness checks and predecessor-gap recovery. Unauthorized or unrelated callers receive the operation's non-enumerating authority outcome.
* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* from_status_seq ·
integer* limit ·
integeranyOf · anyOf[13] · object · $ref #/$defs/account_status_resolve_outcome
Contiguous Account Authority issuer-ledger range. Records are ordered by status_seq, begin exactly at from_status_seq when present, and retain the Account Authority's original bytes and proofs.
* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* records · array<$ref #/$defs/account_status_record>
items · object · $ref #/$defs/account_status_record
Immutable Account Authority issuer-ledger record. account_status_record_id is the suite-tagged full digest of RFC 8785 JCS over every field except account_status_record_id and proof. The proof uses context ak.account_status_record_proof.v1 over that same closed unsigned core. principal_control_realm_id is a verified account-binding coordinate only and is never a finality scope.
allOf · allOf[0] ·
?* schema ·
const "ak.schema.account_status_record.v1"enum:
"ak.schema.account_status_record.v1"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* binding_version ·
integerMonotonic Account Authority-local account-to-principal binding generation.
* status_seq ·
integerprevious_account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* status ·
string (enum)enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$reason ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/audit_reason_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
stringproof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* has_more ·
booleannext_status_seq ·
integeranyOf · anyOf[14] · object · $ref #/$defs/account_status_publication_request_body
* publication · oneOf[2] · $ref #/$defs/account_status_publication
Constrained carrier for one exact AccountStatusRecord. Initial publication carries record only; downstream fanout carries the byte-identical record plus prior receiver receipts. No receiver rebuilds or re-signs the record.
oneOf · oneOf[0] · object
* record · object · $ref #/$defs/account_status_record
Immutable Account Authority issuer-ledger record. account_status_record_id is the suite-tagged full digest of RFC 8785 JCS over every field except account_status_record_id and proof. The proof uses context ak.account_status_record_proof.v1 over that same closed unsigned core. principal_control_realm_id is a verified account-binding coordinate only and is never a finality scope.
allOf · allOf[0] ·
?* schema ·
const "ak.schema.account_status_record.v1"enum:
"ak.schema.account_status_record.v1"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* binding_version ·
integerMonotonic Account Authority-local account-to-principal binding generation.
* status_seq ·
integerprevious_account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* status ·
string (enum)enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$reason ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/audit_reason_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
stringproof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[1] · object
* record · object · $ref #/$defs/account_status_record
Immutable Account Authority issuer-ledger record. account_status_record_id is the suite-tagged full digest of RFC 8785 JCS over every field except account_status_record_id and proof. The proof uses context ak.account_status_record_proof.v1 over that same closed unsigned core. principal_control_realm_id is a verified account-binding coordinate only and is never a finality scope.
allOf · allOf[0] ·
?* schema ·
const "ak.schema.account_status_record.v1"enum:
"ak.schema.account_status_record.v1"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* binding_version ·
integerMonotonic Account Authority-local account-to-principal binding generation.
* status_seq ·
integerprevious_account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* status ·
string (enum)enum:
"active" "soft_logged_out" "locked" "suspended" "deactivated" "erasure_pending"reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$reason ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/audit_reason_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
stringproof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* account_status_receipts · array<$ref #/$defs/account_status_receipt>
items · object · $ref #/$defs/account_status_receipt
Receiver-signed receipt proving durable monotonic replication of one exact AccountStatusRecord. It grants no authority. proof uses context ak.account_status_replication_receipt_proof.v1 and payload_digest over RFC 8785 JCS of every field except proof.
* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* record_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* status_seq ·
integer* receiver_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$anyOf · anyOf[15] · object · $ref #/$defs/account_status_publication_outcome
Durable replica operation state. accepted/duplicate are terminal for this receiver and dependency_missing performs zero writes while identifying the exact next sequence required for gap recovery.
* status ·
string (enum)enum:
"accepted" "duplicate" "dependency_missing"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* status_seq ·
integer* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$current_account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$current_status_seq ·
integerrequired_status_seq ·
integerbarrier_cursor · object · $ref ./cursor.schema.json
Single opaque cursor type. Used as both stream continuation token (incremental sync, list pagination — 'after', 'before', 'prev_cursor', 'next_cursor') and barrier token (read-your-writes wait — 'X-Arkret-Wait-For'). Wire form is always ak:cursor:<base64url(canonical_json)>. Clients MUST treat the wire form as opaque; only the issuing server reads the inner structure.
Integrity contract (normative, see client-sync.md §12 and encoding.md §8 / §8.3.1): v1 core uses the stateful opaque-handle form only — body is {v, purpose, issued_at, expires_at, h} where 'h' is an unguessable server-side handle that the issuing server resolves to the bound (account_id, device_id, filter_digest, purpose, positions, target?, expiry) tuple. account_id is the complete exact AccountId and already contains the Station coordinate; an additional principal_id or service_id identity sidecar MUST NOT be used. Server-side handle lookup IS the integrity check; there is no inline transcript binding to verify on the client side. Servers MUST reject unknown / expired / cross-binding handles with cursor_integrity_invalid.
* v ·
const "1"enum:
"1"* purpose ·
string (enum)Cursor purpose. 'stream' = continuation cursor for incremental sync / list pagination. Used as 'after' on /account/subscribe and as response 'prev_cursor' (older direction) / 'next_cursor' (newer direction) on the list-pagination surfaces. It is NOT used by ak.self.committed_event.read.scan.v1 or ak.peer.committed_event.read.scan.v1: positional stream scan paginates by stream_position, and those surfaces MUST reject an ak:cursor: value (api-conventions.md section 7.2). prev_cursor / next_cursor carry absolute directional meaning regardless of how the request was issued — see api-conventions.md §7.0. 'barrier' = read-your-writes / wait-for-event cursor (use in X-Arkret-Wait-For header to block until local checkpoint covers target.event_id). The handle binding (resolved server-side) carries positions for 'stream' or target for 'barrier'; the wire body does not.
enum:
"stream" "barrier"* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* h ·
stringServer-side opaque handle. The issuing server MUST bind this handle to (account_id, device_id, filter_digest, purpose, positions, target?, expiry) and MUST be able to revoke it. account_id is the complete exact AccountId and already contains the Station coordinate; an additional principal_id or service_id identity sidecar MUST NOT be used. The handle MUST be unguessable (≥ 128 bits entropy after base64url decoding); minLength=22 enforces that floor mechanically (base64url packs 6 bits per character so 128/6 ≈ 21.33 → at least 22 chars of the [A-Za-z0-9_-] alphabet). Servers MUST reject any unknown / expired / cross-binding handle with `cursor_integrity_invalid`. Handle lookup IS the integrity check — there is no MAC or signature to verify inline. This is the moral equivalent of Matrix `next_batch` / MSC4186 `pos` and satisfies the integrity contract without crypto. Servers SHOULD keep the handle → binding map durable across process restarts (see client-sync.md §12.1): a memory-only table is still integrity-correct (unknown handles fail closed) but turns every restart into a fleet-wide forced full resync. For production-grade deployment profiles (small_team / organization / high_security_organization / sovereign_deployment / sovereign_enclave / isolated_sovereign_network) this durability plus TTL GC is a MUST per client-sync.md §12.1; only personal_node keeps it at SHOULD.
pattern:
^[A-Za-z0-9_-]+$(^_[A-Za-z0-9_]*$) ·
?Server-private auxiliary fields (e.g. `_compress` / `_kid` flags). Names MUST start with underscore. In v1 core there is no `_mac` / `_sig` integrity field — handle lookup IS the integrity check — so the underscore namespace is private to the issuing server. `_mac` and `_sig` themselves are explicitly excluded by the top-level `not` clause: a cursor body carrying either MUST be rejected (encoding.md §8.3).
* propagation_state ·
string (enum)enum:
"not_required" "scheduled" "complete" "incomplete"pending_destination_count ·
integerreceipt · object · $ref #/$defs/account_status_receipt
Receiver-signed receipt proving durable monotonic replication of one exact AccountStatusRecord. It grants no authority. proof uses context ak.account_status_replication_receipt_proof.v1 and payload_digest over RFC 8785 JCS of every field except proof.
* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* record_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* account_authority_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* status_seq ·
integer* receiver_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
stringproof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$anyOf · anyOf[16] · object · $ref #/$defs/session_revoke_request_body
target_session_grant_id ·
string · $ref #/$defs/session_grant_idpattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$target_device_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$all_sessions ·
const trueenum:
trueproof · object · $ref #/$defs/account_lifecycle_proof
* proof_kind ·
string (enum)enum:
"did_bound_signature" "paired_device_proof" "passkey_assertion" "oidc_code_exchange" "agent_key_proof"* challenge ·
string* request_canonical_digest ·
string · $ref #/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$verification_method ·
string · $ref #/$defs/did_urlpattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature ·
string · $ref #/$defs/non_empty_stringanyOf · anyOf[17] · object · $ref #/$defs/session_revoke_outcome
* revoked_count ·
integerrevoked_session_grant_ids · array<$ref #/$defs/session_grant_id>
items ·
string · $ref #/$defs/session_grant_idpattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$anyOf · anyOf[18] · object · $ref #/$defs/account_request_erasure_request_body
Record the authenticated account holder's explicit request to erase the account (ak.gate.account.command.request_erasure.v1; zh/identity/account-lifecycle.md section 8.1). The Account Authority accepts it directly on the gate surface; acceptance only records the intent and continues the Account Authority's existing erasure_pending issuance flow within the same service — it is neither the signed AccountStatusRecord nor a completion receipt. The Account Authority MUST treat this as a high-risk action and require fresh high-risk action authentication (recent login, WebAuthn, recovery key or a deployment equivalent), judged locally by the Account Authority; re-authentication strength, risk checks and cooldown are deployment governance.
* request_id ·
string · $ref #/$defs/request_idIdempotency identity of the erasure request. Replaying it returns the recorded acceptance outcome and MUST NOT record a second intent; the same request_id with different canonical bytes is duplicate_conflict with zero writes. A different request_id while a live intent whose erasure_pending AccountStatusRecord is not yet signed exists is failed_precondition with reason_code erasure_request_already_pending.
pattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$anyOf · anyOf[19] · object · $ref #/$defs/account_request_erasure_outcome
Acceptance confirmation of a self-initiated account erasure request. At most one live intent record exists per account while the erasure_pending AccountStatusRecord is unsigned. This outcome proves only that the intent is durably recorded; it MUST NOT be read as record issuance or physical erasure completion. Completion is observed through the existing account-status read surface, and physical completion through the erasure receipt rail (zh/identity/account-lifecycle.md section 8).
* request_id ·
string · $ref #/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* recorded_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$withdrawal_window_ends_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/account-operations.schema.json