ak.schema.agent_draft_pending_intent.v1
ak.schema.agent_draft_pending_intent.v1 · file: schemas/agent-draft-private.schema.json Closed controller-private Agent draft plaintext and Station-private pending-intent contracts. The top-level schema is the plaintext encrypted by the controller holder inside ak.schema.account_data_encrypted_value.v1; Station never receives that plaintext.
* $ · object · $ref #/$defs/agent_draft_account_data_value
Closed controller-private Agent draft plaintext and Station-private pending-intent contracts. The top-level schema is the plaintext encrypted by the controller holder inside ak.schema.account_data_encrypted_value.v1; Station never receives that plaintext.
* schema ·
const "ak.schema.agent_draft.v1"enum:
"ak.schema.agent_draft.v1"* draft_id · allOf[2]
allOf · allOf[0] ·
string · $ref ./event-payload.schema.json#/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref ./string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)* agent_id ·
string · $ref ./event-payload.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* proposed_action ·
string · $ref ./event-payload.schema.json#/$defs/non_empty_string* target · object · $ref ./event-payload.schema.json#/$defs/agent_action_target
Minimal target descriptor for an actor-private agent draft or approval. It identifies the eventual shared write surface without disclosing private draft content.
anyOf · anyOf[0] ·
?anyOf · anyOf[1] ·
?anyOf · anyOf[2] ·
?anyOf · anyOf[3] ·
?* kind ·
string (enum)enum:
"realm" "space" "strand" "message" "object" "service_operation" "account_data"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$object_ref ·
$ref #/$defs/object_ref · $ref #/$defs/object_refoperation_id · allOf[2]
allOf · allOf[0] ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)account_data_key ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string* content ·
?Controller-visible proposal content recovered from the HPKE handoff. Its RFC 8785 JCS digest MUST equal content_digest before encryption and after decryption.
* content_digest ·
string · $ref ./event-payload.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* source_pending_event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* workflow_state ·
string (enum)enum:
"proposed" "approved" "published" "rejected"* expires_at ·
string (date-time) · format=date-time · $ref ./event-payload.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* created_at ·
string (date-time) · format=date-time · $ref ./event-payload.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/agent-draft-private.schema.json