跳转到内容

ak.schema.account_subscribe_frame.v1

← Schemas

Arkret Account Subscribe Frame
ak.schema.account_subscribe_frame.v1 · file: schemas/account-subscribe-frame.schema.json

Single NDJSON frame on the ak.self.account.stream.subscribe.v1 streaming channel (GET /_arkret/self/account/subscribe, Content-Type: application/x-ndjson). Each newline-delimited line is one frame object. Discriminated by the `kind` field: `delta` carries account-aggregate data (per-Realm stream heads, to_device, account_data, agent_draft_pending_intents, device_lists, notifications, unread counts); the other kinds are control frames that mirror ak.self.committed_event.stream.subscribe.v1 (`catchup_complete`, `checkpoint`, `heartbeat`, `dropped`, `resync_required`, `unauthorized`). Agent draft pending intents use their own holder-private baseline/delta channel and never reuse account_data.events, account_data.station_cas, notifications, or to_device. Encrypted broadcast signals use the optional Signal Extension rail and never appear in this durable/account aggregate stream. `dropped` and `resync_required` MAY carry `reconnect_after_ms` as a server-directed minimum delay before opening another account subscribe stream for the same principal/device/filter scope.

* $ · object
Single NDJSON frame on the ak.self.account.stream.subscribe.v1 streaming channel (GET /_arkret/self/account/subscribe, Content-Type: application/x-ndjson). Each newline-delimited line is one frame object. Discriminated by the `kind` field: `delta` carries account-aggregate data (per-Realm stream heads, to_device, account_data, agent_draft_pending_intents, device_lists, notifications, unread counts); the other kinds are control frames that mirror ak.self.committed_event.stream.subscribe.v1 (`catchup_complete`, `checkpoint`, `heartbeat`, `dropped`, `resync_required`, `unauthorized`). Agent draft pending intents use their own holder-private baseline/delta channel and never reuse account_data.events, account_data.station_cas, notifications, or to_device. Encrypted broadcast signals use the optional Signal Extension rail and never appear in this durable/account aggregate stream. `dropped` and `resync_required` MAY carry `reconnect_after_ms` as a server-directed minimum delay before opening another account subscribe stream for the same principal/device/filter scope.
oneOf · oneOf[0] · object
Account aggregate data frame.
* kind · const "delta"
enum: "delta"
oneOf · oneOf[1] · object
This bounded catchup round completed. Per-channel and Realm baseline completion is declared separately.
* kind · const "catchup_complete"
enum: "catchup_complete"
oneOf · oneOf[2] · object
Cursor-only checkpoint advancement; no data fields are allowed.
* kind · const "checkpoint"
enum: "checkpoint"
oneOf · oneOf[3] · object
Account stream gap signal; cursor is the account catch-up start. No data fields are allowed. `reconnect_after_ms` MAY be present to enforce a server-directed reconnect holdoff.
* kind · const "dropped"
enum: "dropped"
oneOf · oneOf[4] · object
Keepalive frame; cursor and data fields are forbidden.
* kind · const "heartbeat"
enum: "heartbeat"
oneOf · oneOf[5] · object
Hard reset signal; cursor and data fields are forbidden. `reconnect_after_ms` MAY be present to enforce a server-directed reconnect holdoff.
* kind · const "resync_required"
enum: "resync_required"
oneOf · oneOf[6] · object
Authorization-loss signal; cursor and data fields are forbidden.
* kind · const "unauthorized"
enum: "unauthorized"
* kind · string (enum)
enum: "delta" "catchup_complete" "checkpoint" "heartbeat" "dropped" "resync_required" "unauthorized"
cursor · string · $ref #/$defs/cursor_value
Stream cursor (purpose='stream'). On `delta` / `catchup_complete` / `checkpoint` frames it points to the position covered by this frame; pass back as `after=` on the next subscribe call to resume. REQUIRED on `dropped` frames as the account-aggregate catch-up start for `GET /account/subscribe?after=<cursor>&catchup=true`. MUST be present on `delta` / `catchup_complete` / `checkpoint` / `dropped`; absent on `heartbeat` / `resync_required` / `unauthorized`. This one stays opaque even though each individual stream now has a total order: the account aggregate spans N independent streams so there is no scalar position to state in the clear, a cleartext position vector would let the caller infer private streams it cannot see from the gaps (zh/sync/client-sync.md §4), and the server-side handle also binds filter_digest and device so a changed filter cannot silently skip events. Single-stream reads do NOT use a cursor — see zh/sync/api-conventions.md §7.2.
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
realms · object
Per-Realm map on `delta` frames. Keys are `ak:realm:*`; values are that Realm's aggregate entry: per-stream window boundaries (streams[]), delivered commit rows (committed_events[]), projection state and account data. Membership state (`join` / `knock` / `leave` / `ban`) is carried by the events inside the Realm entry; pending Invite lifecycle remains a caller-private inbox projection and is not membership.
(^ak:realm:[A-Za-z0-9_-]{44}$) · object · $ref #/$defs/realm_sync_entry
allOf · allOf[0] · ?
allOf · allOf[1] · ?
streams · array<$ref #/$defs/realm_stream_window>
Per-stream window boundaries for the streams of this Realm bucket that the caller is authorized to see and whose Commit chain is already established. A container with no Commit yet MUST NOT appear here: head_commit_ref and next_position have no value to carry before position 0 exists, and the server MUST NOT fabricate a window with an empty head. Such a container becomes visible through stream enumeration (ak.self.realm.read.streams.v1) or a later frame once its first Commit lands. Entries MUST be sorted by unsigned bytes of RFC 8785 JCS(stream_ref) and stream_ref MUST be unique. Delivery rows live in committed_events[]; this array carries only the window scalars, which are per stream because Realm / each Circle / each Sidecar are independent commit streams. The caller MUST NOT infer anything about streams absent from this array other than what streams_limited states: an authorized-but-absent stream and a stream the caller cannot see are indistinguishable here by construction.
items · object · $ref #/$defs/realm_stream_window
Per-stream delivery window for one visible authority stream of this Realm bucket. Realm, each Circle and each Sidecar are independent commit streams, so every window boundary marker is per stream: a bucket-level 'there is more history' boolean has no referent once the bucket spans N streams, and a bucket-level one would make one stream's window a function of activity on streams the caller cannot see (zh/sync/client-sync.md §4).
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* head_commit_ref · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* next_position · integer
Next stream_position this stream expects, i.e. head stream_position + 1. Positions are never compared across streams.
* limited · boolean
Gap marker for THIS stream: history this caller is permitted to read exists below this stream's window start. It is read against the caller's permitted range, never against the physical stream: history below the caller's readable floor MUST NOT set it, and it MUST NOT be cleared because the remaining history happens to be unreadable. Within one frozen baseline window every segment repeats the same value; it must not change because the current segment could not fit the remaining items. Backfill goes through ak.self.committed_event.read.scan.v1 with before_position — there is no second pagination mechanism on the subscribe surface.
* window_limit · integer
Cumulative item ceiling of the frozen window for THIS stream after merging the request targets (account_filter.window_limit), not the count emitted in one frame. Constant within a window; byte budgets only decide segmentation and must never lower it. Per stream, so one stream being limited never depends on how much budget the other streams consumed. 0 is a boundary-and-context-only window: the server delivers no ordinary event rows for this stream, limited and complete still describe the caller's permitted range (complete true means the zero-row window was delivered in full, never that the stream was scanned to its start), and the client MUST NOT read a zero-row window as an empty or exhausted stream.
* complete · boolean
The server has delivered every segment of this stream's frozen window. Independent of realm_detail_baseline.complete, account baseline completed_channels and catchup_complete. Completion proves delivery only: not per-event authentication, decryption, display dependencies, full history or any read/write permission, and never that the stream was read down to position 0 — the window is bounded by window_limit and by the caller's permitted range.
preview_only · boolean
Per-stream display fallback: when a window starts after position 0 and this frame lacks a window_start_basis sufficient to verify THIS stream start, preview_only MUST be true regardless of limited. A position-0 start has no basis and is not preview for that reason. Realm-level state_at_window_start cannot substitute for this basis. A preview window MUST NOT feed reducer input or MLS install. Repeat identically in every segment of a frozen window.
window_start_basis · object
Verifiable material only for THIS stream window starting after position 0. It names the exact committed prefix the state is valid after (all Commits of THIS stream through anchor_position) and an authority-signed realm-state-snapshot slice whose head on THIS stream is that Commit; the server must retain the exact snapshot throughout the actual lifetime of the Account stream cursor carrying the window (issued_at through expires_at, at most 7 days), while current disclosure authorization still applies. The client fetches and verifies the basis before persisting the Account frame. Without sufficient basis, this stream is preview_only regardless of limited. A position-0 window has no basis and starts verification at genesis. No cross-stream order or typed-current client reconstruction is implied.
* anchor_position · integer
stream_position of anchor_commit_ref on THIS stream; the basis state is valid after every Commit of THIS stream through this position. A window that starts at the caller readable floor Commit (floor > 0) has no Commit of the caller readable range before it and therefore carries no basis: that stream is preview_only. Positions are never compared across streams.
* anchor_commit_ref · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* snapshot_ref · string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_id
Content-addressed identity of an authority-signed typed Realm snapshot.
pattern: ^ak:realm_snapshot:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Station tenure the anchor and snapshot slice are bound to. A client MUST resolve this historical generation and its Station through a fresh verified genesis-to-current authority bundle; an unknown generation or Station is invalid. The snapshot_ref names the exact signed object from this tenure, not a substitute current head.
accepted_dependency_refs · array<$ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref>
Exact accepted cross-stream authorization dependencies the anchor's prefix relied on, each a closed four-coordinate committed_event_ref. They are explicit references, not an ordering: listing them introduces no cross-stream total order and no comparison of positions across streams. Omitted or empty means the prefix depended on no accepted reference outside this stream.
items · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · integer
e2ee_epoch · oneOf[2]
Projection-only MLS epoch of THIS stream at its window start. Each Circle and each Sidecar owns an independent MLS group and epoch, so this cannot be a Realm-level scalar. null when the stream has no MLS group. Not part of any state hash, checkpoint or causal graph.
oneOf · oneOf[0] · null
oneOf · oneOf[1] · object
* epoch · integer
* key_ref · string
streams_limited · boolean
True when the caller is authorized to see more streams in this Realm than the 64-entry streams[] ceiling admits. Truncation is deterministic and depends only on the caller's own visible stream set: the Realm stream (stream_ref.kind='realm') MUST be retained whenever the caller can see it, and the remaining slots are filled in ascending unsigned-byte order of JCS(stream_ref). The server MUST NOT silently drop streams — a client that reads this as false may treat streams[] as the complete visible set, while true means it MUST fetch the remainder through the per-stream surfaces (ak.self.committed_event.read.scan.v1 and Realm detail) and MUST NOT conclude that an absent stream does not exist. Omitted means false.
window_snapshot_cursor · string · $ref #/$defs/cursor_value
Identifies and binds the frozen window generation of this Realm bucket. Repeated identically in every segment of that window. It is an identity, not a position: never used as the account `after` parameter, never parsed, never compared as an ordered token. Distinct from realm_detail_baseline.snapshot_cursor, which freezes a different generation.
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
state_at_window_start · object · $ref #/$defs/state_at_window_start
Derived projection-only state at the window start, Realm-level display context only. NOT part of state hash, checkpoint, or causal graph, and never a security basis: it is a display preview and MUST NOT be presented as, or accepted in place of, an authority-signed snapshot. The verifiable rebuild material is per stream in realm_sync_entry.streams[].window_start_basis, and the presence of this object MUST NOT clear any stream's preview_only. The MLS epoch is NOT here either: each Circle and each Sidecar has its own group and epoch, so e2ee_epoch lives on realm_sync_entry.streams[] instead.
* actor_profiles · array<object>
Window-start profile rows keyed semantically by the complete ActorId. Entries MUST be sorted by unsigned UTF-8 bytes of RFC 8785 JCS(actor_id), and duplicate ActorIds MUST be rejected even if display fields differ. A principal DID alone is not a key: accounts on distinct Stations remain distinct rows with their own display projections.
items · object
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
display_name · string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_256
NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern: ^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$
avatar_blob_ref · string
* realm_metadata · object
title · string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_256
NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern: ^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$
summary · string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/short_text
NFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern: ^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$
join_rule · string
collaboration_role · string (enum)
Projection-only strong Realm role, emitted only after the server validates the registered Realm profile and discriminator.
enum: "direct_conversation"
current · object · $ref ./account-current-result.schema.json#/$defs/current
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Station tenure these entries and stream heads were read under.
* stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* entries · array<$ref #/$defs/entry>
items · $ref #/$defs/entry · $ref #/$defs/entry
account_data · object · $ref #/$defs/event_container
* events · array<$ref ./event-envelope.schema.json#/$defs/shared_event_envelope>
items · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · object · $ref #
Single NDJSON frame on the ak.self.account.stream.subscribe.v1 streaming channel (GET /_arkret/self/account/subscribe, Content-Type: application/x-ndjson). Each newline-delimited line is one frame object. Discriminated by the `kind` field: `delta` carries account-aggregate data (per-Realm stream heads, to_device, account_data, agent_draft_pending_intents, device_lists, notifications, unread counts); the other kinds are control frames that mirror ak.self.committed_event.stream.subscribe.v1 (`catchup_complete`, `checkpoint`, `heartbeat`, `dropped`, `resync_required`, `unauthorized`). Agent draft pending intents use their own holder-private baseline/delta channel and never reuse account_data.events, account_data.station_cas, notifications, or to_device. Encrypted broadcast signals use the optional Signal Extension rail and never appear in this durable/account aggregate stream. `dropped` and `resync_required` MAY carry `reconnect_after_ms` as a server-directed minimum delay before opening another account subscribe stream for the same principal/device/filter scope.
oneOf · oneOf[0] · object
Account aggregate data frame.
* kind · const "delta"
enum: "delta"
oneOf · oneOf[1] · object
This bounded catchup round completed. Per-channel and Realm baseline completion is declared separately.
* kind · const "catchup_complete"
enum: "catchup_complete"
oneOf · oneOf[2] · object
Cursor-only checkpoint advancement; no data fields are allowed.
* kind · const "checkpoint"
enum: "checkpoint"
oneOf · oneOf[3] · object
Account stream gap signal; cursor is the account catch-up start. No data fields are allowed. `reconnect_after_ms` MAY be present to enforce a server-directed reconnect holdoff.
* kind · const "dropped"
enum: "dropped"
oneOf · oneOf[4] · object
Keepalive frame; cursor and data fields are forbidden.
* kind · const "heartbeat"
enum: "heartbeat"
oneOf · oneOf[5] · object
Hard reset signal; cursor and data fields are forbidden. `reconnect_after_ms` MAY be present to enforce a server-directed reconnect holdoff.
* kind · const "resync_required"
enum: "resync_required"
oneOf · oneOf[6] · object
Authorization-loss signal; cursor and data fields are forbidden.
* kind · const "unauthorized"
enum: "unauthorized"
* kind · string (enum)
enum: "delta" "catchup_complete" "checkpoint" "heartbeat" "dropped" "resync_required" "unauthorized"
cursor · string · $ref #/$defs/cursor_value
Stream cursor (purpose='stream'). On `delta` / `catchup_complete` / `checkpoint` frames it points to the position covered by this frame; pass back as `after=` on the next subscribe call to resume. REQUIRED on `dropped` frames as the account-aggregate catch-up start for `GET /account/subscribe?after=<cursor>&catchup=true`. MUST be present on `delta` / `catchup_complete` / `checkpoint` / `dropped`; absent on `heartbeat` / `resync_required` / `unauthorized`. This one stays opaque even though each individual stream now has a total order: the account aggregate spans N independent streams so there is no scalar position to state in the clear, a cleartext position vector would let the caller infer private streams it cannot see from the gaps (zh/sync/client-sync.md §4), and the server-side handle also binds filter_digest and device so a changed filter cannot silently skip events. Single-stream reads do NOT use a cursor — see zh/sync/api-conventions.md §7.2.
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
realms · object
Per-Realm map on `delta` frames. Keys are `ak:realm:*`; values are that Realm's aggregate entry: per-stream window boundaries (streams[]), delivered commit rows (committed_events[]), projection state and account data. Membership state (`join` / `knock` / `leave` / `ban`) is carried by the events inside the Realm entry; pending Invite lifecycle remains a caller-private inbox projection and is not membership.
(^ak:realm:[A-Za-z0-9_-]{44}$) · object · $ref #/$defs/realm_sync_entry
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
streams · …
recursion truncated at depth 8; see source schema for full shape
streams_limited · …
recursion truncated at depth 8; see source schema for full shape
window_snapshot_cursor · …
recursion truncated at depth 8; see source schema for full shape
state_at_window_start · …
recursion truncated at depth 8; see source schema for full shape
current · …
recursion truncated at depth 8; see source schema for full shape
account_data · …
recursion truncated at depth 8; see source schema for full shape
summary · …
recursion truncated at depth 8; see source schema for full shape
member_roster · …
recursion truncated at depth 8; see source schema for full shape
unread_notifications · …
recursion truncated at depth 8; see source schema for full shape
event_states · …
recursion truncated at depth 8; see source schema for full shape
baseline · …
recursion truncated at depth 8; see source schema for full shape
unavailable · …
recursion truncated at depth 8; see source schema for full shape
committed_events · …
recursion truncated at depth 8; see source schema for full shape
to_device · object · $ref #/$defs/recipient_delivery_container
To-device message batch on `delta` frames.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
* deliveries · array<$ref #/$defs/recipient_delivery>
items · …
recursion truncated at depth 8; see source schema for full shape
ack_token · string
Server-issued opaque acknowledgement token, REQUIRED whenever deliveries[] is non-empty. Bound server-side to the authenticated recipient endpoint and queue high-water position of this batch, covering both delivery kinds and all earlier queue items. NOT a cursor. The client passes it verbatim to ak.self.device_messages.command.ack.v1 only after durably processing every covered delivery (client-sync.md §10.1).
lost · boolean
SHOULD be true only when durable evidence proves a historical gap or failure since this recipient endpoint's last acknowledged position. Normal expiry and capacity MUST NOT delete unacknowledged deliveries of either kind; clients MUST NOT silently assume completeness when lost is true.
limited · boolean
True when this account subscribe recipient-delivery batch is truncated by the stream frame budget. When true, `next_cursor` is REQUIRED and the client MUST continue the same queue with ak.self.device_messages.read.list.v1?after=<next_cursor>.
next_cursor · string · $ref #/$defs/cursor_value
Read-only to-device queue continuation cursor for ak.self.device_messages.read.list.v1?after=... . It is not an acknowledgement and MUST NOT delete queued messages; queue deletion happens only through `ack_token` passed to ak.self.device_messages.command.ack.v1.
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
device_lists · object · $ref #/$defs/device_list_changes
Principal DID sets whose authoritative device list changed or left the caller's visibility scope on `delta` frames.
* changed_ids · array<$ref ./common-ids.schema.json#/$defs/actor_id>
items · …
recursion truncated at depth 8; see source schema for full shape
* left_ids · array<$ref ./common-ids.schema.json#/$defs/actor_id>
items · …
recursion truncated at depth 8; see source schema for full shape
account_data · object · $ref #/$defs/account_data_container
Account-scoped private data on `delta` frames, split by authority: holder-authored durable Events remain in events[], while registry-declared station_cas registers use the closed station_cas branch.
* events · array<$ref ./event-envelope.schema.json>
Holder-authored ak.account_data.set Events only. Station-CAS rows MUST NOT be synthesized as Events.
items · …
recursion truncated at depth 8; see source schema for full shape
station_cas · object · $ref #/$defs/station_cas_account_data_container
Bounded holder-readable Station-CAS upserts/removals. Initial completeness is carried only by baseline.channels/completed_channels; never clear absent keys on an intermediate page.
* upserts · …
recursion truncated at depth 8; see source schema for full shape
* removals · …
recursion truncated at depth 8; see source schema for full shape
agent_draft_pending_intents · oneOf[2] · $ref #/$defs/agent_draft_pending_intent_container
Independent pending-intent projection page. A frame carries at most 100 ordered changes in one items array; each upsert value's canonical JSON is at most 1 MiB and the complete canonical frame remains at most 8 MiB. The account cursor covers the independent pending-intent projection position.
oneOf · oneOf[0] · object · $ref #/$defs/agent_draft_pending_intent_delta_container
* mode · …
recursion truncated at depth 8; see source schema for full shape
* projection_position · …
recursion truncated at depth 8; see source schema for full shape
* items · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/agent_draft_pending_intent_baseline_container
* mode · …
recursion truncated at depth 8; see source schema for full shape
* snapshot_cut_position · …
recursion truncated at depth 8; see source schema for full shape
* page_offset · …
recursion truncated at depth 8; see source schema for full shape
* next_page_offset · …
recursion truncated at depth 8; see source schema for full shape
* items · …
recursion truncated at depth 8; see source schema for full shape
notifications · object · $ref #/$defs/notification_container
Account-private notification projection deltas on `delta` frames. They are not Realm Events: the channel is authorized by the authenticated account context and is never filtered by the detail Realm window. Ordinary source-Event rows are additionally re-evaluated against the recipient's current read authorization on every frame, frozen baseline pages included.
* items · array<$ref #/$defs/notification_delta>
items · …
recursion truncated at depth 8; see source schema for full shape
partial · boolean
This frame contains at least one limited stream window (some streams[].limited is true). Missing older history is loaded on user demand through ak.self.committed_event.read.scan.v1 with before_position; partial does not describe account baseline completion.
priority · string
Optional server-side priority hint for the frame (UX scheduling).
reconnect_after_ms · integer
Optional server-directed minimum delay, in milliseconds, before opening another `ak.self.account.stream.subscribe.v1` stream for the same principal/device/filter scope. MAY appear only on `dropped` and `resync_required` frames. This is a stream reconnect hint, not a generic error retry field; it does not apply to unrelated API calls. Clients MUST wait at least this delay before reconnecting, and servers MUST reject earlier reconnect attempts with `429 rate_limited` plus `Retry-After`.
realm_list · object · $ref #/$defs/realm_list_page
Only next_cursor presence indicates another page. A nonterminal page MUST contain at least one item; no duplicated terminal flag is carried.
allOf · allOf[0] · ?
* snapshot_cursor · string · $ref #/$defs/cursor_value
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
* snapshot_revision · integer
* items · array<$ref #/$defs/realm_list_row>
items · …
recursion truncated at depth 8; see source schema for full shape
next_cursor · string · $ref #/$defs/cursor_value
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
realm_list_changes · object · $ref #/$defs/realm_list_changes
* upserts · array<$ref #/$defs/realm_list_row>
items · …
recursion truncated at depth 8; see source schema for full shape
* removals · array<$ref #/$defs/realm_list_removal>
items · …
recursion truncated at depth 8; see source schema for full shape
baseline · object · $ref #/$defs/account_baseline_segment
* snapshot_cursor · string · $ref #/$defs/cursor_value
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
* channels · array<string (enum)>
Global baseline channels carried by this segment. agent_draft_pending_intents is independent from account_data_events, station_cas, notifications and to_device.
items · …
recursion truncated at depth 8; see source schema for full shape
* completed_channels · array<string (enum)>
Channels whose complete frozen snapshot has been delivered. A pending-intent channel is complete only on its terminal page with next_page_offset=null; absent items on an earlier page never remove local records.
items · …
recursion truncated at depth 8; see source schema for full shape
realm_invalidations · array<$ref #/$defs/realm_invalidation>
items · object · $ref #/$defs/realm_invalidation
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* revision · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind · string (enum)
enum: "ak.agent.action_approve" "ak.agent.interaction.set" "ak.agent.key.authorize" "ak.agent.key.revoke" "ak.agent.provision" "ak.agent.sidecar.exchange.control" "ak.applet.bridge_error" "ak.applet.discovery" "ak.applet.managed_actor.provision" "ak.applet.registration" "ak.audit.accessed" "ak.audit.erasure_receipt" "ak.call.create" "ak.call.recording.start" "ak.call.state" "ak.capability.grant" "ak.capability.relinquish" "ak.capability.revoke" "ak.circle.archive" "ak.circle.create" "ak.circle.history_access" "ak.circle.member.state" "ak.circle.restore" "ak.circle.tombstone" "ak.circle.update" "ak.consent.grant" "ak.consent.revoke" "ak.contact.accepted" "ak.contact.rejected" "ak.contact.requested" "ak.contact.scope.update" "ak.contact.tombstone" "ak.device.authorize" "ak.device.reanchor" "ak.device.revoke" "ak.direct_conversation.bound" "ak.identity.accountability_grant" "ak.identity.resolution.update" "ak.invite.accept" "ak.invite.cancel" "ak.invite.claim" "ak.invite.create" "ak.invite.revoke" "ak.invite.third_party" "ak.key_backup.active_series" "ak.member.identity.update" "ak.member.state" "ak.message.create" "ak.message.redact" "ak.message.revise" "ak.mimi.room_binding" "ak.mls.commit" "ak.mls.genesis" "ak.moderation.decision" "ak.moderation.decision.lift" "ak.moderation.franking_proof" "ak.morph.archive" "ak.morph.create" "ak.morph.restore" "ak.morph.stage.set" "ak.morph.update" "ak.organization.moderation_policy" "ak.pin.add" "ak.pin.remove" "ak.pin.reorder" "ak.policy.action" "ak.policy.set" "ak.profile.create" "ak.profile.realm_override" "ak.profile.update" "ak.reaction.add" "ak.reaction.remove" "ak.realm.alias" "ak.realm.archive" "ak.realm.asset_privacy_policy" "ak.realm.authority.reset" "ak.realm.create" "ak.realm.destroy" "ak.realm.discovery" "ak.realm.freeze" "ak.realm.governance_station.change" "ak.realm.history_access" "ak.realm.join_rule" "ak.realm.link" "ak.realm.media_service" "ak.realm.organization" "ak.realm.owner.transfer" "ak.realm.plaintext_visible_services" "ak.realm.policy_bundle" "ak.realm.preview_policy" "ak.realm.profile" "ak.realm.read_receipt_policy" "ak.realm.restore" "ak.realm.schema" "ak.realm.search_policy" "ak.realm.set_default_strand" "ak.realm.tombstone" "ak.realm.unfreeze" "ak.redaction" "ak.relation.create" "ak.relation.tombstone" "ak.relation.update" "ak.rsvp.set" "ak.schema.define" "ak.self.agent.deactivate" "ak.self.agent.pause" "ak.self.agent.resume" "ak.self.moderation.report" "ak.sidecar.context.attach" "ak.sidecar.create" "ak.space.archive" "ak.space.create" "ak.space.parent" "ak.space.restore" "ak.space.tombstone" "ak.space.update" "ak.strand.archive" "ak.strand.create" "ak.strand.move" "ak.strand.reorder" "ak.strand.restore" "ak.strand.stage.set" "ak.strand.tracks.update" "ak.strand.update" "ak.strand.watch.set" "ak.view.create" "ak.view.reconcile" "ak.view.update"
summary · object · $ref #/$defs/realm_summary
joined_member_count · integer
invited_member_count · integer
Count of caller-private pending Invite inbox entries associated with this Realm. This is not derived from ak.member.state, does not imply membership, and MUST NOT create roster rows.
hero_ids · array<$ref ./common-ids.schema.json#/$defs/actor_id>
items · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
member_roster · object · $ref #/$defs/member_roster
Lightweight roster page derived from effective ak.member.state, effective ak.member.identity.update references, and currently visible handle-claim evidence. Entries MUST NOT carry display fields or naked handle strings directly; handle strings may appear only inside signed ak.schema.handle_claim.v1 objects.
* entries · array<$ref #/$defs/member_roster_entry>
items · object · $ref #/$defs/member_roster_entry
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* membership · string (enum)
Effective membership rows visible in the roster. Invite lifecycle records are not membership and MUST NOT appear here.
enum: "join" "knock"
subject_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
identity_event_ids · array<string>
Effective ak.member.identity.update event ids for this actor after replacement refs are applied.
items · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
member_display_state_digest · string
Digest over the effective identity event references plus the current visible handle claim digest set for this roster entry.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
identity_events · array<$ref ./event-envelope.schema.json#/$defs/shared_event_envelope>
Optional inline effective ak.member.identity.update Event envelopes. When present these are the original events, not query-time re-encryption or projection rewrites. MUST be omitted unless subject_account_id is disclosed, because plaintext or decryptable identity events can disclose the same member subject.
items · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · object · $ref #
Single NDJSON frame on the ak.self.account.stream.subscribe.v1 streaming channel (GET /_arkret/self/account/subscribe, Content-Type: application/x-ndjson). Each newline-delimited line is one frame object. Discriminated by the `kind` field: `delta` carries account-aggregate data (per-Realm stream heads, to_device, account_data, agent_draft_pending_intents, device_lists, notifications, unread counts); the other kinds are control frames that mirror ak.self.committed_event.stream.subscribe.v1 (`catchup_complete`, `checkpoint`, `heartbeat`, `dropped`, `resync_required`, `unauthorized`). Agent draft pending intents use their own holder-private baseline/delta channel and never reuse account_data.events, account_data.station_cas, notifications, or to_device. Encrypted broadcast signals use the optional Signal Extension rail and never appear in this durable/account aggregate stream. `dropped` and `resync_required` MAY carry `reconnect_after_ms` as a server-directed minimum delay before opening another account subscribe stream for the same principal/device/filter scope.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
cursor · …
recursion truncated at depth 8; see source schema for full shape
realms · …
recursion truncated at depth 8; see source schema for full shape
to_device · …
recursion truncated at depth 8; see source schema for full shape
device_lists · …
recursion truncated at depth 8; see source schema for full shape
account_data · …
recursion truncated at depth 8; see source schema for full shape
agent_draft_pending_intents · …
recursion truncated at depth 8; see source schema for full shape
notifications · …
recursion truncated at depth 8; see source schema for full shape
partial · …
recursion truncated at depth 8; see source schema for full shape
priority · …
recursion truncated at depth 8; see source schema for full shape
reconnect_after_ms · …
recursion truncated at depth 8; see source schema for full shape
realm_list · …
recursion truncated at depth 8; see source schema for full shape
realm_list_changes · …
recursion truncated at depth 8; see source schema for full shape
baseline · …
recursion truncated at depth 8; see source schema for full shape
realm_invalidations · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
handle_claim_digests · array<string>
Digests of currently visible effective ak.schema.handle_claim.v1 objects for this member in the current Realm context. MUST be omitted unless subject_account_id is disclosed, because stable claim digests are linkable across contexts. Absence is not proof that the member has no handle.
items · string
pattern: ^(sha256|blake3):[0-9a-f]{64}$
handle_claims · array<$ref ./handle-claim.schema.json>
Optional inline signed handle claim status evidence. MUST be omitted unless subject_account_id is disclosed, and every included status view MUST have claim.subject_account_id byte-for-byte equal to the entry subject_account_id across both components. Services may omit this for privacy, size, or freshness. a claim whose principal_id matches but whose station_id differs MUST be discarded.
items · object · $ref ./handle-claim.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
* schema · const "ak.schema.handle_claim.v1"
enum: "ak.schema.handle_claim.v1"
* claim · $ref #/$defs/handle_claim_core · $ref #/$defs/handle_claim_core
* status · string (enum)
enum: "pending" "verified" "revoked"
* as_of · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* verifier_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* verified_at · $ref #/$defs/nullable_timestamp · $ref #/$defs/nullable_timestamp
* revocation · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* fresh_until · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* status_proof · allOf[2]
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
handle_claims_limited · boolean
True when handle_claims[] is truncated or replaced by digest-only hints. Clients MUST NOT interpret missing claims as no handle.
* limited · boolean
True when entries[] is truncated and MUST NOT be treated as the complete Realm roster.
next_cursor · string · $ref #/$defs/cursor_value
Optional pagination cursor for continuing member roster retrieval.
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
unread_notifications · object · $ref #/$defs/unread_notification_counts
notification_count · integer
highlight_count · integer
event_states · array<object>
Per-event protocol-state views (event_id + event_state) for reducer-input events carried by this entry. Ordinary current-value projection concurrency is resolved by the governance Station's {commit_id, stream_ref, stream_position} plus the domain revision — within one stream stream_position is a total order, and there is no cross-stream order to resolve. See zh/sync/service-surface.md §5.3.
items · object
* event_id · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* event_state · string (enum)
enum: "data_local" "data_observed" "control_pending" "control_committed" "failed_precondition" "failed_plane" "rejected_commit" "fork_quarantine"
event_state_reason_code · string
Optional registered reason code for failure detail beyond the enum.
baseline · object · $ref #/$defs/realm_detail_baseline
* snapshot_cursor · string · $ref #/$defs/cursor_value
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
* cut_revision · integer
* coverage · object · $ref ./account-current-result.schema.json#/$defs/coverage
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* complete_for_authorized_streams · boolean
* complete · boolean
unavailable · object
* error_code · string (enum)
enum: "revision_unavailable" "limit_exceeded" "temporarily_unavailable" "not_found" "witness_disagreement"
committed_events · array<$ref ./authority-commit-operations.schema.json#/$defs/stream_row>
Caller-visible committed Event views delivered by this Realm bucket. Each item carries its RealmCommit, so there is no cross-stream protocol order.
items · oneOf[2] · $ref ./authority-commit-operations.schema.json#/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · null
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · object · $ref #
Single NDJSON frame on the ak.self.account.stream.subscribe.v1 streaming channel (GET /_arkret/self/account/subscribe, Content-Type: application/x-ndjson). Each newline-delimited line is one frame object. Discriminated by the `kind` field: `delta` carries account-aggregate data (per-Realm stream heads, to_device, account_data, agent_draft_pending_intents, device_lists, notifications, unread counts); the other kinds are control frames that mirror ak.self.committed_event.stream.subscribe.v1 (`catchup_complete`, `checkpoint`, `heartbeat`, `dropped`, `resync_required`, `unauthorized`). Agent draft pending intents use their own holder-private baseline/delta channel and never reuse account_data.events, account_data.station_cas, notifications, or to_device. Encrypted broadcast signals use the optional Signal Extension rail and never appear in this durable/account aggregate stream. `dropped` and `resync_required` MAY carry `reconnect_after_ms` as a server-directed minimum delay before opening another account subscribe stream for the same principal/device/filter scope.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
cursor · …
recursion truncated at depth 8; see source schema for full shape
realms · …
recursion truncated at depth 8; see source schema for full shape
to_device · …
recursion truncated at depth 8; see source schema for full shape
device_lists · …
recursion truncated at depth 8; see source schema for full shape
account_data · …
recursion truncated at depth 8; see source schema for full shape
agent_draft_pending_intents · …
recursion truncated at depth 8; see source schema for full shape
notifications · …
recursion truncated at depth 8; see source schema for full shape
partial · …
recursion truncated at depth 8; see source schema for full shape
priority · …
recursion truncated at depth 8; see source schema for full shape
reconnect_after_ms · …
recursion truncated at depth 8; see source schema for full shape
realm_list · …
recursion truncated at depth 8; see source schema for full shape
realm_list_changes · …
recursion truncated at depth 8; see source schema for full shape
baseline · …
recursion truncated at depth 8; see source schema for full shape
realm_invalidations · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · …
recursion truncated at depth 8; see source schema for full shape
* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · object · $ref #
Single NDJSON frame on the ak.self.account.stream.subscribe.v1 streaming channel (GET /_arkret/self/account/subscribe, Content-Type: application/x-ndjson). Each newline-delimited line is one frame object. Discriminated by the `kind` field: `delta` carries account-aggregate data (per-Realm stream heads, to_device, account_data, agent_draft_pending_intents, device_lists, notifications, unread counts); the other kinds are control frames that mirror ak.self.committed_event.stream.subscribe.v1 (`catchup_complete`, `checkpoint`, `heartbeat`, `dropped`, `resync_required`, `unauthorized`). Agent draft pending intents use their own holder-private baseline/delta channel and never reuse account_data.events, account_data.station_cas, notifications, or to_device. Encrypted broadcast signals use the optional Signal Extension rail and never appear in this durable/account aggregate stream. `dropped` and `resync_required` MAY carry `reconnect_after_ms` as a server-directed minimum delay before opening another account subscribe stream for the same principal/device/filter scope.
oneOf · oneOf[0] · object
Account aggregate data frame.
* kind · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
This bounded catchup round completed. Per-channel and Realm baseline completion is declared separately.
* kind · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
Cursor-only checkpoint advancement; no data fields are allowed.
* kind · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object
Account stream gap signal; cursor is the account catch-up start. No data fields are allowed. `reconnect_after_ms` MAY be present to enforce a server-directed reconnect holdoff.
* kind · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · object
Keepalive frame; cursor and data fields are forbidden.
* kind · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object
Hard reset signal; cursor and data fields are forbidden. `reconnect_after_ms` MAY be present to enforce a server-directed reconnect holdoff.
* kind · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · object
Authorization-loss signal; cursor and data fields are forbidden.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* kind · string (enum)
enum: "delta" "catchup_complete" "checkpoint" "heartbeat" "dropped" "resync_required" "unauthorized"
cursor · string · $ref #/$defs/cursor_value
Stream cursor (purpose='stream'). On `delta` / `catchup_complete` / `checkpoint` frames it points to the position covered by this frame; pass back as `after=` on the next subscribe call to resume. REQUIRED on `dropped` frames as the account-aggregate catch-up start for `GET /account/subscribe?after=<cursor>&catchup=true`. MUST be present on `delta` / `catchup_complete` / `checkpoint` / `dropped`; absent on `heartbeat` / `resync_required` / `unauthorized`. This one stays opaque even though each individual stream now has a total order: the account aggregate spans N independent streams so there is no scalar position to state in the clear, a cleartext position vector would let the caller infer private streams it cannot see from the gaps (zh/sync/client-sync.md §4), and the server-side handle also binds filter_digest and device so a changed filter cannot silently skip events. Single-stream reads do NOT use a cursor — see zh/sync/api-conventions.md §7.2.
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
realms · object
Per-Realm map on `delta` frames. Keys are `ak:realm:*`; values are that Realm's aggregate entry: per-stream window boundaries (streams[]), delivered commit rows (committed_events[]), projection state and account data. Membership state (`join` / `knock` / `leave` / `ban`) is carried by the events inside the Realm entry; pending Invite lifecycle remains a caller-private inbox projection and is not membership.
(^ak:realm:[A-Za-z0-9_-]{44}$) · …
recursion truncated at depth 8; see source schema for full shape
to_device · object · $ref #/$defs/recipient_delivery_container
To-device message batch on `delta` frames.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* deliveries · …
recursion truncated at depth 8; see source schema for full shape
ack_token · …
recursion truncated at depth 8; see source schema for full shape
lost · …
recursion truncated at depth 8; see source schema for full shape
limited · …
recursion truncated at depth 8; see source schema for full shape
next_cursor · …
recursion truncated at depth 8; see source schema for full shape
device_lists · object · $ref #/$defs/device_list_changes
Principal DID sets whose authoritative device list changed or left the caller's visibility scope on `delta` frames.
* changed_ids · …
recursion truncated at depth 8; see source schema for full shape
* left_ids · …
recursion truncated at depth 8; see source schema for full shape
account_data · object · $ref #/$defs/account_data_container
Account-scoped private data on `delta` frames, split by authority: holder-authored durable Events remain in events[], while registry-declared station_cas registers use the closed station_cas branch.
* events · …
recursion truncated at depth 8; see source schema for full shape
station_cas · …
recursion truncated at depth 8; see source schema for full shape
agent_draft_pending_intents · oneOf[2] · $ref #/$defs/agent_draft_pending_intent_container
Independent pending-intent projection page. A frame carries at most 100 ordered changes in one items array; each upsert value's canonical JSON is at most 1 MiB and the complete canonical frame remains at most 8 MiB. The account cursor covers the independent pending-intent projection position.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
notifications · object · $ref #/$defs/notification_container
Account-private notification projection deltas on `delta` frames. They are not Realm Events: the channel is authorized by the authenticated account context and is never filtered by the detail Realm window. Ordinary source-Event rows are additionally re-evaluated against the recipient's current read authorization on every frame, frozen baseline pages included.
* items · …
recursion truncated at depth 8; see source schema for full shape
partial · boolean
This frame contains at least one limited stream window (some streams[].limited is true). Missing older history is loaded on user demand through ak.self.committed_event.read.scan.v1 with before_position; partial does not describe account baseline completion.
priority · string
Optional server-side priority hint for the frame (UX scheduling).
reconnect_after_ms · integer
Optional server-directed minimum delay, in milliseconds, before opening another `ak.self.account.stream.subscribe.v1` stream for the same principal/device/filter scope. MAY appear only on `dropped` and `resync_required` frames. This is a stream reconnect hint, not a generic error retry field; it does not apply to unrelated API calls. Clients MUST wait at least this delay before reconnecting, and servers MUST reject earlier reconnect attempts with `429 rate_limited` plus `Retry-After`.
realm_list · object · $ref #/$defs/realm_list_page
Only next_cursor presence indicates another page. A nonterminal page MUST contain at least one item; no duplicated terminal flag is carried.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* snapshot_cursor · …
recursion truncated at depth 8; see source schema for full shape
* snapshot_revision · …
recursion truncated at depth 8; see source schema for full shape
* items · …
recursion truncated at depth 8; see source schema for full shape
next_cursor · …
recursion truncated at depth 8; see source schema for full shape
realm_list_changes · object · $ref #/$defs/realm_list_changes
* upserts · …
recursion truncated at depth 8; see source schema for full shape
* removals · …
recursion truncated at depth 8; see source schema for full shape
baseline · object · $ref #/$defs/account_baseline_segment
* snapshot_cursor · …
recursion truncated at depth 8; see source schema for full shape
* channels · …
recursion truncated at depth 8; see source schema for full shape
* completed_channels · …
recursion truncated at depth 8; see source schema for full shape
realm_invalidations · array<$ref #/$defs/realm_invalidation>
items · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind · string (enum)
enum: "ak.agent.action_approve" "ak.agent.interaction.set" "ak.agent.key.authorize" "ak.agent.key.revoke" "ak.agent.provision" "ak.agent.sidecar.exchange.control" "ak.applet.bridge_error" "ak.applet.discovery" "ak.applet.managed_actor.provision" "ak.applet.registration" "ak.audit.accessed" "ak.audit.erasure_receipt" "ak.call.create" "ak.call.recording.start" "ak.call.state" "ak.capability.grant" "ak.capability.relinquish" "ak.capability.revoke" "ak.circle.archive" "ak.circle.create" "ak.circle.history_access" "ak.circle.member.state" "ak.circle.restore" "ak.circle.tombstone" "ak.circle.update" "ak.consent.grant" "ak.consent.revoke" "ak.contact.accepted" "ak.contact.rejected" "ak.contact.requested" "ak.contact.scope.update" "ak.contact.tombstone" "ak.device.authorize" "ak.device.reanchor" "ak.device.revoke" "ak.direct_conversation.bound" "ak.identity.accountability_grant" "ak.identity.resolution.update" "ak.invite.accept" "ak.invite.cancel" "ak.invite.claim" "ak.invite.create" "ak.invite.revoke" "ak.invite.third_party" "ak.key_backup.active_series" "ak.member.identity.update" "ak.member.state" "ak.message.create" "ak.message.redact" "ak.message.revise" "ak.mimi.room_binding" "ak.mls.commit" "ak.mls.genesis" "ak.moderation.decision" "ak.moderation.decision.lift" "ak.moderation.franking_proof" "ak.morph.archive" "ak.morph.create" "ak.morph.restore" "ak.morph.stage.set" "ak.morph.update" "ak.organization.moderation_policy" "ak.pin.add" "ak.pin.remove" "ak.pin.reorder" "ak.policy.action" "ak.policy.set" "ak.profile.create" "ak.profile.realm_override" "ak.profile.update" "ak.reaction.add" "ak.reaction.remove" "ak.realm.alias" "ak.realm.archive" "ak.realm.asset_privacy_policy" "ak.realm.authority.reset" "ak.realm.create" "ak.realm.destroy" "ak.realm.discovery" "ak.realm.freeze" "ak.realm.governance_station.change" "ak.realm.history_access" "ak.realm.join_rule" "ak.realm.link" "ak.realm.media_service" "ak.realm.organization" "ak.realm.owner.transfer" "ak.realm.plaintext_visible_services" "ak.realm.policy_bundle" "ak.realm.preview_policy" "ak.realm.profile" "ak.realm.read_receipt_policy" "ak.realm.restore" "ak.realm.schema" "ak.realm.search_policy" "ak.realm.set_default_strand" "ak.realm.tombstone" "ak.realm.unfreeze" "ak.redaction" "ak.relation.create" "ak.relation.tombstone" "ak.relation.update" "ak.rsvp.set" "ak.schema.define" "ak.self.agent.deactivate" "ak.self.agent.pause" "ak.self.agent.resume" "ak.self.moderation.report" "ak.sidecar.context.attach" "ak.sidecar.create" "ak.space.archive" "ak.space.create" "ak.space.parent" "ak.space.restore" "ak.space.tombstone" "ak.space.update" "ak.strand.archive" "ak.strand.create" "ak.strand.move" "ak.strand.reorder" "ak.strand.restore" "ak.strand.stage.set" "ak.strand.tracks.update" "ak.strand.update" "ak.strand.watch.set" "ak.view.create" "ak.view.reconcile" "ak.view.update"
oneOf · oneOf[1] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · null
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · object · $ref #
Single NDJSON frame on the ak.self.account.stream.subscribe.v1 streaming channel (GET /_arkret/self/account/subscribe, Content-Type: application/x-ndjson). Each newline-delimited line is one frame object. Discriminated by the `kind` field: `delta` carries account-aggregate data (per-Realm stream heads, to_device, account_data, agent_draft_pending_intents, device_lists, notifications, unread counts); the other kinds are control frames that mirror ak.self.committed_event.stream.subscribe.v1 (`catchup_complete`, `checkpoint`, `heartbeat`, `dropped`, `resync_required`, `unauthorized`). Agent draft pending intents use their own holder-private baseline/delta channel and never reuse account_data.events, account_data.station_cas, notifications, or to_device. Encrypted broadcast signals use the optional Signal Extension rail and never appear in this durable/account aggregate stream. `dropped` and `resync_required` MAY carry `reconnect_after_ms` as a server-directed minimum delay before opening another account subscribe stream for the same principal/device/filter scope.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
cursor · …
recursion truncated at depth 8; see source schema for full shape
realms · …
recursion truncated at depth 8; see source schema for full shape
to_device · …
recursion truncated at depth 8; see source schema for full shape
device_lists · …
recursion truncated at depth 8; see source schema for full shape
account_data · …
recursion truncated at depth 8; see source schema for full shape
agent_draft_pending_intents · …
recursion truncated at depth 8; see source schema for full shape
notifications · …
recursion truncated at depth 8; see source schema for full shape
partial · …
recursion truncated at depth 8; see source schema for full shape
priority · …
recursion truncated at depth 8; see source schema for full shape
reconnect_after_ms · …
recursion truncated at depth 8; see source schema for full shape
realm_list · …
recursion truncated at depth 8; see source schema for full shape
realm_list_changes · …
recursion truncated at depth 8; see source schema for full shape
baseline · …
recursion truncated at depth 8; see source schema for full shape
realm_invalidations · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · …
recursion truncated at depth 8; see source schema for full shape
* event_disclosure · $ref #/$defs/EventDisclosure · $ref #/$defs/EventDisclosure
to_device · object · $ref #/$defs/recipient_delivery_container
To-device message batch on `delta` frames.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
* deliveries · array<$ref #/$defs/recipient_delivery>
items · oneOf[2] · $ref #/$defs/recipient_delivery
One exact recipient-private queue item. The discriminator selects an unchanged DeviceMessageEnvelope or producer-signed MlsWelcomeDelivery; neither payload is rewritten into the other.
oneOf · oneOf[0] · object
* delivery_kind · const "device_message"
enum: "device_message"
* device_message · object · $ref ./device-message.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · oneOf[3]
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
oneOf · oneOf[2] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
* device_message_id · $ref #/$defs/device_message_id · $ref #/$defs/device_message_id
Sender-assigned stable identity of one logical to-device message. Queue services MUST preserve it byte-for-byte across retries and redelivery. Receivers deduplicate by the exact closed sender identity and device_message_id: (sender_account_id, sender_device_id, device_message_id), (sender_agent_id, device_message_id), or (sender_id, device_message_id).
* kind · string
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
sender_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
sender_device_id · $ref #/$defs/device_id · $ref #/$defs/device_id
Authoring human device. Exactly one sender endpoint branch is present: sender_account_id plus this field, the complete sender_agent_* triple, or sender_id. An Agent runtime has no device identity and MUST NOT be disguised as an ak:device; the restricted Station materializer likewise has a service identity rather than a fake device.
sender_agent_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
Agent principal that authored this message. Present exactly when the sender is an Agent runtime, together with sender_agent_verification_method and sender_agent_key_authorize_event_id. It is the sole Agent identity carrier.
sender_agent_verification_method · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
sender_agent_key_authorize_event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
sender_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
Station service identity that internally materialized an actor-private update for the holder. This branch is restricted to actor_private_update_kind, and sender_id MUST equal recipient_account_id.station_id and the Station identity bound to the recipient's current authenticated self/to-device surface. It is not a bearer delegation and cannot be submitted through ak.self.device_messages.command.send.v1.
* recipient_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* recipient_device_id · $ref #/$defs/device_id · $ref #/$defs/device_id
* sent_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* expires_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* content · object
unsigned · object
Optional non-authenticated metadata block (transport-layer hints only). Receivers MUST NOT trust any field here for authorization, ordering, or cryptographic verification. Typical sub-fields: progress (delivery progress hint), error_context (transport-layer error diagnostics), retry_after_ms. By convention this block is excluded from the signed transcript of the enclosing transport envelope and is dropped on persist.
oneOf · oneOf[1] · object
* delivery_kind · const "mls_welcome"
enum: "mls_welcome"
* mls_welcome · object · $ref ./mls-welcome-delivery.schema.json
Producer-signed recipient delivery queued atomically with its winning MLS Commit. This is not a shared Realm Event and does not receive an independent RealmCommit.
* welcome_id · string · $ref ./common-ids.schema.json#/$defs/mls_welcome_delivery_id
pattern: ^ak:mls_welcome_delivery:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* effective_scope · oneOf[4] · $ref ./event-envelope.schema.json#/$defs/scope_ref
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind · const "realm_genesis"
enum: "realm_genesis"
* commit_event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* recipient_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* recipient_endpoint · oneOf[2]
oneOf · oneOf[0] · object
* kind · const "device"
enum: "device"
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[1] · object
* kind · const "agent_runtime"
enum: "agent_runtime"
* verification_method · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* keypackage_claim_ref · string
pattern: ^ak:keypackage_claim:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* ciphertext_b64 · string
pattern: ^[A-Za-z0-9_-]+$
* producer_proof · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/mls_welcome_delivery_signature
allOf · allOf[0] · object · $ref #
Single NDJSON frame on the ak.self.account.stream.subscribe.v1 streaming channel (GET /_arkret/self/account/subscribe, Content-Type: application/x-ndjson). Each newline-delimited line is one frame object. Discriminated by the `kind` field: `delta` carries account-aggregate data (per-Realm stream heads, to_device, account_data, agent_draft_pending_intents, device_lists, notifications, unread counts); the other kinds are control frames that mirror ak.self.committed_event.stream.subscribe.v1 (`catchup_complete`, `checkpoint`, `heartbeat`, `dropped`, `resync_required`, `unauthorized`). Agent draft pending intents use their own holder-private baseline/delta channel and never reuse account_data.events, account_data.station_cas, notifications, or to_device. Encrypted broadcast signals use the optional Signal Extension rail and never appear in this durable/account aggregate stream. `dropped` and `resync_required` MAY carry `reconnect_after_ms` as a server-directed minimum delay before opening another account subscribe stream for the same principal/device/filter scope.
oneOf · oneOf[0] · object
Account aggregate data frame.
* kind · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
This bounded catchup round completed. Per-channel and Realm baseline completion is declared separately.
* kind · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
Cursor-only checkpoint advancement; no data fields are allowed.
* kind · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object
Account stream gap signal; cursor is the account catch-up start. No data fields are allowed. `reconnect_after_ms` MAY be present to enforce a server-directed reconnect holdoff.
* kind · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · object
Keepalive frame; cursor and data fields are forbidden.
* kind · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object
Hard reset signal; cursor and data fields are forbidden. `reconnect_after_ms` MAY be present to enforce a server-directed reconnect holdoff.
* kind · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · object
Authorization-loss signal; cursor and data fields are forbidden.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* kind · string (enum)
enum: "delta" "catchup_complete" "checkpoint" "heartbeat" "dropped" "resync_required" "unauthorized"
cursor · string · $ref #/$defs/cursor_value
Stream cursor (purpose='stream'). On `delta` / `catchup_complete` / `checkpoint` frames it points to the position covered by this frame; pass back as `after=` on the next subscribe call to resume. REQUIRED on `dropped` frames as the account-aggregate catch-up start for `GET /account/subscribe?after=<cursor>&catchup=true`. MUST be present on `delta` / `catchup_complete` / `checkpoint` / `dropped`; absent on `heartbeat` / `resync_required` / `unauthorized`. This one stays opaque even though each individual stream now has a total order: the account aggregate spans N independent streams so there is no scalar position to state in the clear, a cleartext position vector would let the caller infer private streams it cannot see from the gaps (zh/sync/client-sync.md §4), and the server-side handle also binds filter_digest and device so a changed filter cannot silently skip events. Single-stream reads do NOT use a cursor — see zh/sync/api-conventions.md §7.2.
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
realms · object
Per-Realm map on `delta` frames. Keys are `ak:realm:*`; values are that Realm's aggregate entry: per-stream window boundaries (streams[]), delivered commit rows (committed_events[]), projection state and account data. Membership state (`join` / `knock` / `leave` / `ban`) is carried by the events inside the Realm entry; pending Invite lifecycle remains a caller-private inbox projection and is not membership.
(^ak:realm:[A-Za-z0-9_-]{44}$) · …
recursion truncated at depth 8; see source schema for full shape
to_device · object · $ref #/$defs/recipient_delivery_container
To-device message batch on `delta` frames.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* deliveries · …
recursion truncated at depth 8; see source schema for full shape
ack_token · …
recursion truncated at depth 8; see source schema for full shape
lost · …
recursion truncated at depth 8; see source schema for full shape
limited · …
recursion truncated at depth 8; see source schema for full shape
next_cursor · …
recursion truncated at depth 8; see source schema for full shape
device_lists · object · $ref #/$defs/device_list_changes
Principal DID sets whose authoritative device list changed or left the caller's visibility scope on `delta` frames.
* changed_ids · …
recursion truncated at depth 8; see source schema for full shape
* left_ids · …
recursion truncated at depth 8; see source schema for full shape
account_data · object · $ref #/$defs/account_data_container
Account-scoped private data on `delta` frames, split by authority: holder-authored durable Events remain in events[], while registry-declared station_cas registers use the closed station_cas branch.
* events · …
recursion truncated at depth 8; see source schema for full shape
station_cas · …
recursion truncated at depth 8; see source schema for full shape
agent_draft_pending_intents · oneOf[2] · $ref #/$defs/agent_draft_pending_intent_container
Independent pending-intent projection page. A frame carries at most 100 ordered changes in one items array; each upsert value's canonical JSON is at most 1 MiB and the complete canonical frame remains at most 8 MiB. The account cursor covers the independent pending-intent projection position.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
notifications · object · $ref #/$defs/notification_container
Account-private notification projection deltas on `delta` frames. They are not Realm Events: the channel is authorized by the authenticated account context and is never filtered by the detail Realm window. Ordinary source-Event rows are additionally re-evaluated against the recipient's current read authorization on every frame, frozen baseline pages included.
* items · …
recursion truncated at depth 8; see source schema for full shape
partial · boolean
This frame contains at least one limited stream window (some streams[].limited is true). Missing older history is loaded on user demand through ak.self.committed_event.read.scan.v1 with before_position; partial does not describe account baseline completion.
priority · string
Optional server-side priority hint for the frame (UX scheduling).
reconnect_after_ms · integer
Optional server-directed minimum delay, in milliseconds, before opening another `ak.self.account.stream.subscribe.v1` stream for the same principal/device/filter scope. MAY appear only on `dropped` and `resync_required` frames. This is a stream reconnect hint, not a generic error retry field; it does not apply to unrelated API calls. Clients MUST wait at least this delay before reconnecting, and servers MUST reject earlier reconnect attempts with `429 rate_limited` plus `Retry-After`.
realm_list · object · $ref #/$defs/realm_list_page
Only next_cursor presence indicates another page. A nonterminal page MUST contain at least one item; no duplicated terminal flag is carried.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* snapshot_cursor · …
recursion truncated at depth 8; see source schema for full shape
* snapshot_revision · …
recursion truncated at depth 8; see source schema for full shape
* items · …
recursion truncated at depth 8; see source schema for full shape
next_cursor · …
recursion truncated at depth 8; see source schema for full shape
realm_list_changes · object · $ref #/$defs/realm_list_changes
* upserts · …
recursion truncated at depth 8; see source schema for full shape
* removals · …
recursion truncated at depth 8; see source schema for full shape
baseline · object · $ref #/$defs/account_baseline_segment
* snapshot_cursor · …
recursion truncated at depth 8; see source schema for full shape
* channels · …
recursion truncated at depth 8; see source schema for full shape
* completed_channels · …
recursion truncated at depth 8; see source schema for full shape
realm_invalidations · array<$ref #/$defs/realm_invalidation>
items · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.mls_welcome_delivery_signature.v1"
enum: "ak.mls_welcome_delivery_signature.v1"
ack_token · string
Server-issued opaque acknowledgement token, REQUIRED whenever deliveries[] is non-empty. Bound server-side to the authenticated recipient endpoint and queue high-water position of this batch, covering both delivery kinds and all earlier queue items. NOT a cursor. The client passes it verbatim to ak.self.device_messages.command.ack.v1 only after durably processing every covered delivery (client-sync.md §10.1).
lost · boolean
SHOULD be true only when durable evidence proves a historical gap or failure since this recipient endpoint's last acknowledged position. Normal expiry and capacity MUST NOT delete unacknowledged deliveries of either kind; clients MUST NOT silently assume completeness when lost is true.
limited · boolean
True when this account subscribe recipient-delivery batch is truncated by the stream frame budget. When true, `next_cursor` is REQUIRED and the client MUST continue the same queue with ak.self.device_messages.read.list.v1?after=<next_cursor>.
next_cursor · string · $ref #/$defs/cursor_value
Read-only to-device queue continuation cursor for ak.self.device_messages.read.list.v1?after=... . It is not an acknowledgement and MUST NOT delete queued messages; queue deletion happens only through `ack_token` passed to ak.self.device_messages.command.ack.v1.
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
device_lists · object · $ref #/$defs/device_list_changes
Principal DID sets whose authoritative device list changed or left the caller's visibility scope on `delta` frames.
* changed_ids · array<$ref ./common-ids.schema.json#/$defs/actor_id>
items · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* left_ids · array<$ref ./common-ids.schema.json#/$defs/actor_id>
items · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
account_data · object · $ref #/$defs/account_data_container
Account-scoped private data on `delta` frames, split by authority: holder-authored durable Events remain in events[], while registry-declared station_cas registers use the closed station_cas branch.
* events · array<$ref ./event-envelope.schema.json>
Holder-authored ak.account_data.set Events only. Station-CAS rows MUST NOT be synthesized as Events.
items · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
station_cas · object · $ref #/$defs/station_cas_account_data_container
Bounded holder-readable Station-CAS upserts/removals. Initial completeness is carried only by baseline.channels/completed_channels; never clear absent keys on an intermediate page.
* upserts · array<$ref ./account-data-operations.schema.json#/$defs/account_data_entry>
items · object · $ref ./account-data-operations.schema.json#/$defs/account_data_entry
* account_data_key · $ref #/$defs/account_data_key · $ref #/$defs/account_data_key
* revision · $ref #/$defs/revision · $ref #/$defs/revision
Revision of this stored value. Pass it back as expected_server_revision inside the caller-signed ak.account_data.set payload to replace or delete the entry.
* content · ?
Caller-supplied opaque payload, stored verbatim. Any JSON value.
* updated_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* removals · array<$ref #/$defs/station_cas_account_data_removal>
items · object · $ref #/$defs/station_cas_account_data_removal
Explicit physical-delete delta. The revision is the per-key tombstone high-water revision; updated_at is diagnostic only and never selects a winner.
* account_data_key · string · $ref ./account-data-operations.schema.json#/$defs/account_data_key
Dot-delimited account_data namespace key (e.g. ak.contacts.realm.<realm_id>, ak.account.blocklist). Control chars / whitespace / path separators are forbidden so the key is URL- and log-safe.
pattern: ^[^\s/\\?#\u0000-\u001f]+$
* revision · integer · $ref ./account-data-operations.schema.json#/$defs/revision
Monotonic per-key revision counter. 0 means the key has never been written. Each accepted write or delete stores expected_server_revision + 1. The counter is a high-water mark: it MUST NOT go backwards, not even after a tombstone is garbage-collected, so a stale offline write can never resurrect a superseded value.
* updated_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
agent_draft_pending_intents · oneOf[2] · $ref #/$defs/agent_draft_pending_intent_container
Independent pending-intent projection page. A frame carries at most 100 ordered changes in one items array; each upsert value's canonical JSON is at most 1 MiB and the complete canonical frame remains at most 8 MiB. The account cursor covers the independent pending-intent projection position.
oneOf · oneOf[0] · object · $ref #/$defs/agent_draft_pending_intent_delta_container
* mode · const "delta"
enum: "delta"
* projection_position · integer
Highest independent pending-intent projection position covered by this container and its enclosing account cursor.
* items · array<$ref #/$defs/agent_draft_pending_intent_change>
items · oneOf[2] · $ref #/$defs/agent_draft_pending_intent_change
One ordered pending-intent projection change. The closed union and one shared items array make the per-frame 100-change bound apply to upserts and removals together.
oneOf · oneOf[0] · object · $ref #/$defs/agent_draft_pending_intent_upsert
* action · const "upsert"
enum: "upsert"
* value · oneOf[2] · $ref ./agent-draft-private.schema.json#/$defs/agent_draft_pending_intent
Closed live | terminal-redacted union. A live available record carries the HPKE content_handoff. A terminal-redacted consumed/expired record permanently omits ciphertext while retaining the create-once identity, source Event, canonical Event digest, expiry and exact terminal metadata.
oneOf · oneOf[0] · $ref #/$defs/agent_draft_pending_intent_live · $ref #/$defs/agent_draft_pending_intent_live
oneOf · oneOf[1] · $ref #/$defs/agent_draft_pending_intent_terminal_redacted · $ref #/$defs/agent_draft_pending_intent_terminal_redacted
oneOf · oneOf[1] · object · $ref #/$defs/agent_draft_pending_intent_remove
* action · const "remove"
enum: "remove"
* value · object · $ref #/$defs/agent_draft_pending_intent_removal
Explicit removal after terminal metadata retention. The stable key, source Event identity, canonical Event digest, content digest, expiry and exact last terminal outcome remain visible so a client cannot interpret the removal as permission to resurrect or recreate the intent.
oneOf · oneOf[0] · object
* state · const "consumed"
enum: "consumed"
oneOf · oneOf[1] · object
* state · const "expired"
enum: "expired"
* key · object · $ref #/$defs/agent_draft_pending_intent_key
Stable pending-intent item key. All three components are compared byte-for-byte and are never inferred from account-data digest-key components.
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · …
recursion truncated at depth 8; see source schema for full shape
* station_id · …
recursion truncated at depth 8; see source schema for full shape
* agent_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* draft_id · allOf[2]
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* accepted_event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* canonical_event_digest · string · $ref ./event-payload.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* content_digest · string · $ref ./event-payload.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* state · string (enum)
enum: "consumed" "expired"
consumption · object · $ref ./agent-draft-private.schema.json#/$defs/pending_intent_consumption
* account_data_set_event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* account_data_key · $ref #/$defs/agent_draft_account_data_key · $ref #/$defs/agent_draft_account_data_key
* accepted_revision · const 1
enum: 1
* consumed_at · string (date-time) · format=date-time · $ref ./event-payload.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
expired_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* removed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
oneOf · oneOf[1] · object · $ref #/$defs/agent_draft_pending_intent_baseline_container
* mode · const "baseline"
enum: "baseline"
* snapshot_cut_position · integer
Frozen pending-intent projection cut shared by every page under the enclosing baseline.snapshot_cursor.
* page_offset · integer
* next_page_offset · integer | null
Next offset in the same frozen cut, or null on the terminal page. Completion still requires baseline.completed_channels to name agent_draft_pending_intents.
* items · array<$ref #/$defs/agent_draft_pending_intent_change>
items · oneOf[2] · $ref #/$defs/agent_draft_pending_intent_change
One ordered pending-intent projection change. The closed union and one shared items array make the per-frame 100-change bound apply to upserts and removals together.
oneOf · oneOf[0] · object · $ref #/$defs/agent_draft_pending_intent_upsert
* action · const "upsert"
enum: "upsert"
* value · oneOf[2] · $ref ./agent-draft-private.schema.json#/$defs/agent_draft_pending_intent
Closed live | terminal-redacted union. A live available record carries the HPKE content_handoff. A terminal-redacted consumed/expired record permanently omits ciphertext while retaining the create-once identity, source Event, canonical Event digest, expiry and exact terminal metadata.
oneOf · oneOf[0] · $ref #/$defs/agent_draft_pending_intent_live · $ref #/$defs/agent_draft_pending_intent_live
oneOf · oneOf[1] · $ref #/$defs/agent_draft_pending_intent_terminal_redacted · $ref #/$defs/agent_draft_pending_intent_terminal_redacted
oneOf · oneOf[1] · object · $ref #/$defs/agent_draft_pending_intent_remove
* action · const "remove"
enum: "remove"
* value · object · $ref #/$defs/agent_draft_pending_intent_removal
Explicit removal after terminal metadata retention. The stable key, source Event identity, canonical Event digest, content digest, expiry and exact last terminal outcome remain visible so a client cannot interpret the removal as permission to resurrect or recreate the intent.
oneOf · oneOf[0] · object
* state · const "consumed"
enum: "consumed"
oneOf · oneOf[1] · object
* state · const "expired"
enum: "expired"
* key · object · $ref #/$defs/agent_draft_pending_intent_key
Stable pending-intent item key. All three components are compared byte-for-byte and are never inferred from account-data digest-key components.
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · …
recursion truncated at depth 8; see source schema for full shape
* station_id · …
recursion truncated at depth 8; see source schema for full shape
* agent_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* draft_id · allOf[2]
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* accepted_event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* canonical_event_digest · string · $ref ./event-payload.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* content_digest · string · $ref ./event-payload.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* state · string (enum)
enum: "consumed" "expired"
consumption · object · $ref ./agent-draft-private.schema.json#/$defs/pending_intent_consumption
* account_data_set_event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* account_data_key · $ref #/$defs/agent_draft_account_data_key · $ref #/$defs/agent_draft_account_data_key
* accepted_revision · const 1
enum: 1
* consumed_at · string (date-time) · format=date-time · $ref ./event-payload.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
expired_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* removed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
notifications · object · $ref #/$defs/notification_container
Account-private notification projection deltas on `delta` frames. They are not Realm Events: the channel is authorized by the authenticated account context and is never filtered by the detail Realm window. Ordinary source-Event rows are additionally re-evaluated against the recipient's current read authorization on every frame, frozen baseline pages included.
* items · array<$ref #/$defs/notification_delta>
items · object · $ref #/$defs/notification_delta
One account-private notification projection delta. The `id` form is the only branch discriminator: `ak:notification:<uuidv7>` selects the Agent runtime approval branch, `ak:notification_projection:<44-char token>` selects the ordinary source-Event current-row branch. Both branches share one projector, one channel position and the section 2.3 per-frame budget; there is no second notification list operation. See spec/v1/zh/sync/client-sync.md#31-account-notification-deltanormative
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
* id · string
oneOf · oneOf[0] · string
Agent runtime approval branch.
pattern: ^ak:notification:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[1] · string
Ordinary source-Event branch. The recipient recomputes it from its own complete AccountId plus data.realm_id, data.source_event_id and data.notification_kind.
pattern: ^ak:notification_projection:[A-Za-z0-9_-]{44}$
* action · string (enum)
enum: "upsert" "remove"
data · anyOf[4]
anyOf · anyOf[0] · object · $ref #/$defs/agent_runtime_approval_notification_data
* approval_request_id · string
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
* agent_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
anyOf · anyOf[1] · object · $ref #/$defs/agent_runtime_approval_notification_removal_data
* reason · string (enum)
enum: "approved" "expired" "renewed" "deactivated" "superseded"
anyOf · anyOf[2] · object · $ref ./notification.schema.json#/$defs/ordinary_projection_content
Server-materialized current content of one ordinary source-Event notification projection, as delivered on the account subscribe notifications channel (account-subscribe-frame.schema.json#/$defs/notification_delta). It reuses the ak.schema.notification.v1 field shapes and carries only what the recipient's own Station can state authoritatively: the projection identity is the delta id, the recipient is the authenticated account, and the inbox state (unread / read / dismissed / archived) stays in holder-private account data. See spec/v1/zh/sync/client-sync.md#312-普通源-event-当前行分支aknotification_projection
* realm_id · $ref #/properties/realm_id · $ref #/properties/realm_id
* source_event_id · $ref #/properties/source_event_id · $ref #/properties/source_event_id
source_ref · $ref #/properties/source_ref · $ref #/properties/source_ref
strand_id · $ref #/properties/strand_id · $ref #/properties/strand_id
track_name · $ref #/properties/track_name · $ref #/properties/track_name
* notification_kind · $ref #/$defs/ordinary_notification_kind · $ref #/$defs/ordinary_notification_kind
* priority · string · $ref #/properties/priority
Optional server-side priority hint for the frame (UX scheduling).
preview · $ref #/properties/preview · $ref #/properties/preview
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
updated_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
anyOf · anyOf[3] · object · $ref #/$defs/ordinary_notification_removal_data
Why one ordinary source-Event notification projection left the recipient's current set. It is a server-observable cause only: inbox disposition (read / dismissed / archived) stays in holder-private account data and never removes a current row.
* reason · string (enum)
enum: "source_removed" "access_revoked" "expired" "superseded"
partial · boolean
This frame contains at least one limited stream window (some streams[].limited is true). Missing older history is loaded on user demand through ak.self.committed_event.read.scan.v1 with before_position; partial does not describe account baseline completion.
priority · string
Optional server-side priority hint for the frame (UX scheduling).
reconnect_after_ms · integer
Optional server-directed minimum delay, in milliseconds, before opening another `ak.self.account.stream.subscribe.v1` stream for the same principal/device/filter scope. MAY appear only on `dropped` and `resync_required` frames. This is a stream reconnect hint, not a generic error retry field; it does not apply to unrelated API calls. Clients MUST wait at least this delay before reconnecting, and servers MUST reject earlier reconnect attempts with `429 rate_limited` plus `Retry-After`.
realm_list · object · $ref #/$defs/realm_list_page
Only next_cursor presence indicates another page. A nonterminal page MUST contain at least one item; no duplicated terminal flag is carried.
allOf · allOf[0] · ?
* snapshot_cursor · string · $ref #/$defs/cursor_value
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
* snapshot_revision · integer
* items · array<$ref #/$defs/realm_list_row>
items · object · $ref #/$defs/realm_list_row
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* revision · integer
* activity_position · integer
* membership · string (enum)
enum: "join" "knock"
title · string
default_strand_id · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
next_cursor · string · $ref #/$defs/cursor_value
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
realm_list_changes · object · $ref #/$defs/realm_list_changes
* upserts · array<$ref #/$defs/realm_list_row>
items · object · $ref #/$defs/realm_list_row
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* revision · integer
* activity_position · integer
* membership · string (enum)
enum: "join" "knock"
title · string
default_strand_id · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
* removals · array<$ref #/$defs/realm_list_removal>
items · object · $ref #/$defs/realm_list_removal
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* revision · integer
baseline · object · $ref #/$defs/account_baseline_segment
* snapshot_cursor · string · $ref #/$defs/cursor_value
pattern: ^ak:cursor:[A-Za-z0-9_-]{1,2028}$
* channels · array<string (enum)>
Global baseline channels carried by this segment. agent_draft_pending_intents is independent from account_data_events, station_cas, notifications and to_device.
items · string (enum)
enum: "account_data_events" "station_cas" "device_lists" "notifications" "agent_draft_pending_intents"
* completed_channels · array<string (enum)>
Channels whose complete frozen snapshot has been delivered. A pending-intent channel is complete only on its terminal page with next_page_offset=null; absent items on an earlier page never remove local records.
items · string (enum)
enum: "account_data_events" "station_cas" "device_lists" "notifications" "agent_draft_pending_intents"
realm_invalidations · array<$ref #/$defs/realm_invalidation>
items · object · $ref #/$defs/realm_invalidation
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* revision · integer

Source