跳转到内容

ak.schema.agent_pairing_bootstrap.v1

← Schemas

Arkret Account Pairing and Agent Operation DTOs
ak.schema.agent_pairing_bootstrap.v1 · file: schemas/agent-operations.schema.json

Closed request and response DTOs for account pairing and Agent management operations.

* $ · oneOf[23]
Closed request and response DTOs for account pairing and Agent management operations.
oneOf · oneOf[0] · object · $ref #/$defs/account_device_pair_request_body
Account Authority terminal pairing command. The Station TCB validates the sole pending ledger and current-device authority, admits the exact authorize_event once, stores its unique RealmCommit, consumes pending/code once, and stores a byte-identical terminal outcome. Exact retry returns the same Event, Commit and outcome; changed intent conflicts with zero writes. The request does not carry a client-selected Station, receipt, internal recovery state or private coordination member.
* pairing_code · string · $ref #/$defs/device_pairing_code
Eight-character human-readable Crockford-style code carrying 40 CSPRNG bits. The minting service MUST keep it unique across its whole live pending window, because it is also the sole lookup key of the authenticated code claim; it is bound to a short-lived pairing challenge transcript and protected by a ten-failure lockout.
pattern: ^[A-HJ-NP-Z2-9]{8}$
* new_device_pubkey · object · $ref #/$defs/public_key
Canonical public key. key carries the base64url key material; kid is the typed identifier of the key holder (for a device key, ak:device:<uuidv7>). There is no public_key member: that spelling is not canonical wire and MUST be rejected.
* kty · string · $ref #/$defs/non_empty_string
* kid · string · $ref #/$defs/non_empty_string
* algorithm · string · $ref #/$defs/non_empty_string
* key · string · $ref #/$defs/base64url
pattern: ^[A-Za-z0-9_-]+$
key_digest · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* authorize_event · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · $ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input
* proof · $ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proof
display_name · string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_256
NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern: ^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$
device_metadata · object · $ref #/$defs/device_metadata
display_name · string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_256
NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern: ^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$
platform · string · $ref #/$defs/non_empty_string
app_id · allOf[2]
allOf · allOf[0] · string · $ref #/$defs/non_empty_string
allOf · allOf[1] · ? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floor
Lexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern: ^(?!ak:)
app_version · string · $ref #/$defs/non_empty_string
* device_pairing_request_id · string · $ref #/$defs/device_pairing_request_id
Required pairing identity bound by the single target device_signature over the full final-account challenge descriptor, including metadata digest with explicit nulls. The verifier reconstructs and compares the transcript digest. Exact replay returns the durable terminal outcome without re-reading pending state.
pattern: ^device_pairing_request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[1] · object · $ref #/$defs/account_device_pair_outcome
Byte-identical terminal outcome stored by the Account Authority only after the owning Station RealmCommit has been verified and the local fence reaches completed. Exact replay returns these bytes without another Event submission or pending read.
* device_id · string · $ref #/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* authorized_event_ref · string · $ref #/$defs/event_id
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
device_grant · object · $ref #/$defs/grant_snapshot
* grant_id · string · $ref #/$defs/grant_id
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
grant_digest · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
key_backup_hint · object
oneOf · oneOf[2] · object · $ref #/$defs/agent_key_pair_request_body
One controller approval command bound to the frozen candidate and handle. The signed authorization Event supplies Agent, key, method, scope, expiry and exact supersedes. Verifiers load possession proof and candidate from the authoritative confidential record, never caller echoes. Accepted RealmCommit processing automatically advances the durable command; exact retries only observe or recover it.
* pairing_request_id · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
* approval_request_id · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
* requested_scope_disclosure · object · $ref ./agent-requested-scope-disclosure.schema.json
Controller-signed, verifier-bound private disclosure of an Agent's immutable requested_scope. This object is authorization evidence, not a grant. It MUST travel only over an authenticated confidential presentation/operation channel and MUST NOT be written to a public DID Document, durable Realm Event, public registry, pairing code, or notification. The verifier consumes request_id/challenge once, validates the short presentation window, verifies a current controller proof, recomputes the requested-scope commitment against the accepted-at Agent DID commitment, and then applies the Agent ceiling subset rules. After successful one-time admission, an implementation MAY retain the object only as encrypted verifier-private evidence keyed by the recomputed digest, verifier_id and audience.
* schema · const "ak.schema.agent_requested_scope_disclosure.v1"
enum: "ak.schema.agent_requested_scope_disclosure.v1"
* request_id · string
Identifier of the verifier's authenticated private challenge request. It is single-use at verifier_id.
pattern: ^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* agent_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* controller_principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* requested_scope · object · $ref ./event-payload.schema.json#/$defs/agent_key_scope
Agent scope object with two uses. In POST /_arkret/self/agents requested_scope it is the required immutable global Agent ceiling; in ak.agent.key.authorize it is a per-key ceiling that MAY be narrower but MUST be an actions/resources/constraints subset of the provision ceiling. It is never a capability grant. actions may contain service operation ids and content action tokens; an omitted action can never be restored by a key, Realm grant or session. resources constrain the service surface and may optionally narrow later content resources, but never authorize content by themselves. Provisioning and pairing do not materialize capability grants from this object; effective authority is the intersection of provision ceiling, key ceiling, independent Realm-scoped grants, session request, membership and policy, with participation applied as an additional deny gate.
* actions · $ref #/$defs/string_list · $ref #/$defs/string_list
Literal action ceiling. Every downstream key scope, grant or session action MUST appear here; action families, prefixes and subsumption do not widen it.
* resources · array<object>
Selector ceiling, not authorization. Each downstream selector must be covered by a parent selector. operation/service parents cover the same kind and matching explicit field and cannot carry content fields. The content-kind vocabulary is the ResourceSelector vocabulary except '*'; kind=realm covers every Realm-local content kind in the matching Realm and other content kinds cover only the same kind. Omitted parent realm_id is a cross-Realm ceiling wildcard and omitted exact ref is a same-kind/same-Realm wildcard. With no content selector, later Realm grants still choose concrete resources and no content wildcard is granted.
items · object
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
* kind · string (enum)
enum: "realm" "space" "circle" "strand" "message" "morph" "object" "relation" "view" "event" "actor" "schema" "policy" "invite" "notification" "read_cursor" "blob" "operation" "service"
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
resource_ref · $ref #/$defs/object_ref · $ref #/$defs/object_ref
schema_ref · string · $ref #/$defs/non_empty_string
operation · string · $ref #/$defs/non_empty_string
service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
constraints · array<$ref ./grant-constraint.schema.json>
Global mandatory constraints. Every effective key/grant/session evaluation MUST retain and AND these constraints; downstream scopes may add stricter constraints but MUST NOT omit or relax provision constraints.
items · object · $ref ./grant-constraint.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · ?
allOf · allOf[6] · ?
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
constraint_id · string
Optional stable identifier of this constraint within the grant; used for diagnostics and overrides.
pattern: ^(?!ak:)
* constraint_kind · string (enum)
Constraint family discriminator. v1 collapses what were 15 types into 8 by absorbing narrowly-scoped types into their conceptual parent: edit_window → temporal; container_move → scope_limitation; rate_limiting + resource_limit → quota; approval_workflow + accountability + device_session → claim_based (with constraint_subkind); encryption_requirement + visibility_control → confidentiality (with constraint_subkind). Use the optional 'constraint_subkind' field to indicate the original specialization where evaluation logic differs.
enum: "temporal" "field_access" "kind_restriction" "scope_limitation" "authority_control" "quota" "claim_based" "confidentiality"
* effect · string (enum)
enum: "allow" "deny" "quarantine" "require_review"
evaluation_class · string (enum)
Cacheability/dependency hint for the authorization evaluator. stateless = pure function of (constraint, op, now); grant_local = depends on the grant object only; realm_state = depends on the exact Realm authority revision (membership, policy_version, etc.); external = depends on data outside that authority state (claim revocation status, rate-limit counts, async approval). Each constraint_kind has a canonical evaluation_class declared in constraint-schema.md §2.3; implementations MAY tighten (e.g. grant_local → stateless) but MUST NOT loosen (e.g. external as stateless). Auth evaluators SHOULD use this hint to gate fast-path caching.
enum: "stateless" "grant_local" "realm_state" "external"
constraint_subkind · string (enum)
Optional discriminator within a constraint_kind. Standard values: claim_based.{claim,approval,accountability}; quota.{rate,resource}; confidentiality.{encryption,visibility}; temporal.{window,edit_window,redact_window,session}; authority_control.{applet_authority}. Per constraint-schema.md §2.2, device/session binding is NOT an independent constraint_subkind: it is the claim_based constraint_subkind=claim sub-case expressed via an accepted PCR device issuer. Implementations MAY require constraint_subkind for these families and fail closed on unknown values.
enum: "claim" "approval" "accountability" "rate" "resource" "encryption" "visibility" "window" "edit_window" "redact_window" "session" "applet_authority"
applies_to_actions · array<string>
Optional restriction of a temporal constraint to specific capability actions (e.g. ['ak.message.revise.own', 'ak.message.redact.own']). Action mismatch is neutral in the effect fold: satisfied for effect=allow and not matched for deny/quarantine/require_review.
items · string
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
not_before · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
recurrence · object
Recurrence rule for temporal constraints. Used by constraint-schema.md §3.1.
frequency · string (enum)
enum: "daily" "weekly" "monthly" "custom"
days · array<string (enum)>
items · string (enum)
enum: "mon" "tue" "wed" "thu" "fri" "sat" "sun"
window_start · string
pattern: ^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$
window_end · string
pattern: ^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$
timezone · string
max_duration · string
ISO 8601 duration.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_session_duration · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
inactivity_timeout · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
expires_after · string
ISO 8601 duration; used by approval_workflow constraint instead of expires_after_ms.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_edit_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_redact_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
redact_after_window_allowed · boolean
condition · object
Conditional predicate for field_access and similar constraints. The `kind` value is a registered named condition from constraint-schema.md §4.1; unknown kinds MUST fail closed. Implementations MUST NOT introduce ad hoc string DSL predicates.
* kind · string (enum)
enum: "object_is_owned_by_actor" "actor_is_assignee" "actor_is_responsible" "actor_is_guardian" "actor_is_controller" "object_in_actor_container" "object_is_unencrypted" "object_is_encrypted" "always" "never"
allowed_write_fields · array<string>
items · string
denied_write_fields · array<string>
items · string
allowed_read_fields · array<string>
items · string
denied_read_fields · array<string>
items · string
sensitive_fields · array<string>
items · string
sensitive_handling · string (enum)
enum: "redact" "hash" "omit"
allowed_object_kinds · array<string>
items · string
denied_object_kinds · array<string>
items · string
allowed_morph_kinds · array<string>
items · string
denied_morph_kinds · array<string>
items · string
allowed_space_kinds · array<string>
Allowed Space kinds (e.g. 'board', 'list', or profile-registered kinds like 'swimlane', 'calendar_bucket'). Reducer/profile MUST validate kind value.
items · string
denied_space_kinds · array<string>
items · string
allowed_facets · array<string (enum)>
items · string (enum)
enum: "container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"
denied_facets · array<string (enum)>
items · string (enum)
enum: "container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"
allowed_view_ids · array<string>
items · string
pattern: ^ak:view:[A-Za-z0-9_-]{44}$
allowed_strand_ids · array<string>
items · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
denied_strand_ids · array<string>
items · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
allowed_space_ids · array<string>
items · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
denied_space_ids · array<string>
items · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
allowed_circle_ids · array<$ref ./common-ids.schema.json#/$defs/circle_id>
Limits Circle-scoped capability actions to the listed Circle ids. Used by ak.circle.manage / ak.circle.member.manage style grants; unconstrained Realm-wide Circle management grants are not a normal permission shape.
items · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
allowed_session_ids · array<string>
Limits applet interop-session operations to the listed applet-defined session correlation ids.
items · string
pattern: ^(?!ak:)
allowed_view_kinds · array<string>
items · string
allowed_view_renderers · array<string>
items · string
denied_view_kinds · array<string>
items · string
denied_view_renderers · array<string>
items · string
allowed_relation_kinds · array<string>
items · string
allowed_from_container_refs · array<string>
items · string
pattern: ^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$
allowed_to_container_refs · array<string>
items · string
pattern: ^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$
wip_limit_override · boolean
example: false
allowed_tracks · array<string>
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
denied_tracks · array<string>
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
blob_presign_scope · object
Scope limiter for ak.self.blob.command.presign.v1 grants: allowed purposes plus optional blob/realm restrictions.
* allowed_purposes · array<string (enum)>
items · string (enum)
enum: "media_inline" "thumbnail" "download"
blob_ref_pattern · string
realm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
items · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
allowed_data_labels · array<string>
Data classification labels this grant may read, export, transform, or send to external endpoints.
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
allowed_endpoints · array<string>
Allowed outbound endpoint origins or deployment-approved endpoint patterns for applet / agent / connector operations.
items · string
max_authority_depth · integer
Maximum remaining authority hops. Bounded by the canonical authority-chain depth ceiling (4) defined in zh/conformance/scalability-constraints.md §3 and zh/authz/capabilities.md §10.2; reducers MUST reject grants declaring a larger value at accept time rather than only truncating during DFS.
authority_path_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
authority_regrant_allowed · boolean
authority_scope · string (enum)
enum: "narrowing_only" "same_scope" "custom"
applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
registration_epoch · string
authority_control(constraint_subkind=applet_authority) binding to the canonical Applet registration epoch.
pattern: ^sha256:[0-9a-f]{64}$
blob_max_bytes · integer
blob_presign_max_ttl_seconds · integer
Maximum TTL, in seconds, that this grant permits for ak.blob.presign. The service must clamp requested max_age_seconds to the smaller of this value and deployment policy.
max_total_blob_bytes · integer
max_artifact_bytes · integer
Maximum artifact size in bytes for applet / agent / export operations.
max_operations · integer
Maximum number of distinct accepted idempotency identities in one UTC epoch-aligned fixed period. Enforcement is a linearizable check-and-reserve at one logical quota authority shared by every node in the enforcing service; per-node duplicated budgets and overshoot are forbidden.
period · string
ISO 8601 duration. For quota constraints, a stricter conditional schema permits only a non-zero fixed-length week/day/hour/minute/second duration; year/month durations are forbidden so every authority derives the same UTC epoch-aligned window id.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
burst · integer
Optional token-bucket capacity at the same logical quota authority, capped by max_operations and refilled at max_operations/period. It never increases the fixed-window total budget.
constraint_scope · string (enum)
Closed v1 quota counting scope. Unknown values are schema violations and MUST fail closed. Quota counters are actor-bound; the enum selects the additional slicing dimension: actor only, actor+space, actor+realm, or actor across all nodes/regions of the enforcing service's global quota domain. global is not an implicit federation-wide counter. Every node in the service domain MUST share one logical linearizable quota authority.
enum: "per_actor" "per_space" "per_realm" "global"
max_resources · integer
resource_kind · string
approval_required · boolean
approval_mode · string (enum)
The only approval mode of v1. The approved write MUST NOT take effect before the approval evidence is verified and accepted in the same transaction (zh/authz/constraint-schema.md section 9.2.7). There is no second mode and no path that first materializes a proposal object and then approves that object.
enum: "before_commit"
approval_actor_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
approval_relation · string (enum)
Responsibility classification of this grant explicit approval_actor_ids roster. It never creates a second dynamic roster or supplies action/scope capability. Missing explicit roster cannot satisfy approval.
enum: "responsible" "controller" "guardian" "realm_admin" "custom"
timeout · string
Positive fixed ISO 8601 duration (week/day/hour/minute/second, no calendar year/month). Each approval vote is valid only when the target covering committed_at <= that vote input.approved_at + timeout, inclusive and with zero tolerance. The same rule applies to Event and operation targets; receiver clocks and first-seen timestamps never anchor it. Omission adds no grant-local age limit.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
approval_threshold · oneOf[2]
Closed executable vote threshold: majority means floor(N/2)+1, unanimous means N, and a positive integer is the exact quorum. N is the distinct eligible approver set at the accepting authority cut. Omission means unanimous. A missing or empty eligible set, or an integer greater than N, cannot satisfy approval. Repeated signatures by one approver count once. Parameterless quorum/custom strings are schema violations.
example: "unanimous"
oneOf · oneOf[0] · string (enum)
enum: "majority" "unanimous"
oneOf · oneOf[1] · integer
accountability_required · boolean
guardian_approval_required · boolean
controller_approval_required · boolean
required_claims · array<object>
Conditional claim requirements. resource-selector-grammar.md §3.3 caps this array at 32 entries as a normative DoS guard; the schema enforces maxItems:32 so condition-selector grants cannot smuggle in unbounded claim objects.
items · object
anyOf · anyOf[0] · ?
anyOf · anyOf[1] · ?
* claim_kind · string
issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
trusted_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · …
recursion truncated at depth 8; see source schema for full shape
subject_matches_actor · boolean
If true, the credential subject did_core_id MUST match the actor did_core_id after each proof's DID is independently validated and projected through its registered method adapter.
example: true
value_constraints · object
Per-field equality / membership constraints on credential claims.
organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
status · string
roles · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
trusted_claim_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
claim_refresh_required · boolean
claim_max_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
allowed_history_access_values · array<string (enum)>
items · string (enum)
enum: "since_join" "all_history_for_current_members"
redacted_history_allowed · boolean
encryption_required · boolean
min_encryption_level · string (enum)
confidentiality(constraint_subkind=encryption) static floor: the minimum content-encryption mechanism the grant requires. Pure static declaration evaluated as stateless unless cross-checked against the scope's current MLS activation state (see constraint-schema.md section 12).
enum: "none" "mls_rfc9420" "external"
plaintext_fallback_allowed · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant permits plaintext in a scope that has no accepted ak.mls.genesis. After activation the flag cannot restore plaintext; the write MUST be rejected with mls_activation_irreversible. See constraint-schema.md §12.
audit_trail_required · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant requires an audit trail (e.g. active Audit Applet Binding). See constraint-schema.md §12.
key_rotation_period · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_key_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
key_backup_required · boolean
approved_key_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
depends_on_moderation_state · boolean
Cache-invalidation hint: when true, this grant's authorization decisions depend on the moderation_state typed current result (see capabilities.md §18.1) and the grant's cache entry MUST be invalidated when that typed current result changes. Default false: ordinary grants (ak.strand.update / ak.message.create / organization membership grants) do NOT take a cache hit on every moderation decision. v1 capabilities.md §18.1 lists three conditions where MUST be explicitly true (moderator-role grants, condition-selector subjects referencing moderation state, constraints referencing moderation queue / typed current result). Schema-side enforcement of condition (2) is in capability-grant.schema.json via if/then on actions[]; conditions (1) and (3) are reducer-side lint. Cache invalidation hint outside the eight constraint families; it does not participate in allow/deny evaluation and is documented in capabilities.md §6 / constraint-schema.md.
allowed_managed_actor_roles · array<string (enum)>
Ordinary authority_control permits only these accepted roles of the Applet bound by the parent applet_authority constraint; no arbitrary third-party regrant.
items · string (enum)
enum: "bot" "ghost"
(^x_[a-z][a-z0-9_]{0,63}$) · any
* verifier_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* audience · string
Exact origin, service audience, or canonical operation audience requested by verifier_id.
* challenge · string
Verifier-generated unpredictable challenge. The (verifier_id, request_id, challenge) tuple is single-use; replay MUST fail closed.
* issued_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* proofs · array<$ref ./event-envelope.schema.json#/$defs/proof>
At least one current controller proof. The proof verification method MUST belong to controller_principal_id or one of its currently authorized devices. payload_digest is sha256(canonical_json(this object with proofs omitted)); detached JWS signs canonical_json({context:'ak.agent_requested_scope_disclosure_proof.v1', payload_digest, agent_id, controller_principal_id, verifier_id, audience, challenge, verification_method, created_at}).
items · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · string · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* created_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
* authorize_event · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · $ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input
* proof · $ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proof
oneOf · oneOf[3] · object · $ref #/$defs/agent_key_pair_outcome
* activation_state · string (enum)
Durable command state. awaiting_source_commit waits for the exact authorization Event covering RealmCommit; accepted RealmCommit processing activates automatically without another pair command. active preserves lifecycle intent and does not itself issue a session. cancelled is terminal after handle invalidation, expiry, changed authority or failed activation fence. Replays never revive a cancelled command.
enum: "awaiting_source_commit" "active" "cancelled"
* authorize_event_ref · string · $ref #/$defs/event_id
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[4] · object · $ref #/$defs/agent_runtime_approval_request_body
Runtime-to-controller pending approval request for Agent-agent key pairing. The runtime proves possession of the local key and the short pairing code; the controller still must approve by signing ak.agent.key.authorize and submitting agent_key_pair_request_body. The service computes ak.agent.runtime_key_binding.v1 from agent_id, pairing_request_id, verification_method, public-key digest and attestation digest. One open pairing_request_id has at most one pending stable binding: same-binding retry is idempotent and refreshes the full request while retaining approval/notification ids; a different binding fails with HTTP 409 agent_runtime_request_conflict without replacement.
* pairing_code · string · $ref #/$defs/pairing_secret
One-time eight-digit decimal pairing code generated uniformly by a CSPRNG, including leading zeroes. It is accepted only with the matching opaque pairing_request_id; the code alone is never a lookup credential. It is transmitted only in JSON bodies, never in URLs or logs.
pattern: ^[0-9]{8}$
* pairing_request_id · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
* agent_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* verification_method · string · $ref #/$defs/did_url
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* public_key · object · $ref #/$defs/agent_runtime_public_key
Closed v1 Agent runtime signing-key profile. Ed25519 is the fully-specified JOSE algorithm identifier from RFC 9864; polymorphic algorithm identifiers are rejected.
* kty · const "OKP"
enum: "OKP"
* kid · string · $ref #/$defs/non_empty_string
* algorithm · const "Ed25519"
enum: "Ed25519"
* key · string
pattern: ^[A-Za-z0-9_-]{43}$
* proof_of_possession · object · $ref #/$defs/agent_runtime_key_possession_proof
Closed Ed25519 proof that the submitter controls the proposed Agent runtime key and possesses the authoritative pairing secret. Canonical transcript, equality, freshness, and final-commit re-verification rules are defined in key-management.md section 3.6.2.
* kind · const "agent_runtime_key_possession"
enum: "agent_runtime_key_possession"
* verification_method · string · $ref #/$defs/did_url
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* signature_algorithm · const "Ed25519"
enum: "Ed25519"
* challenge · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
* audience_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* created_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* runtime_key_binding_digest · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* transcript_digest · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* signature · string · $ref #/$defs/base64url
Unpadded base64url encoding of the 64-byte raw Ed25519 signature over the canonical transcript.
pattern: ^[A-Za-z0-9_-]+$
runtime_attestation · object · $ref #/$defs/runtime_attestation
Optional runtime / workload attestation captured at pairing approval time. v1 enum includes self_asserted as baseline; future profiles MAY register TEE / SLSA / SPIFFE attestation kinds. Implementations encountering an unknown kind MUST fail closed.
* kind · string (enum)
v1 enum. Future profiles MAY extend via accepted attestation taxonomy.
enum: "self_asserted"
software · string
version · string
attestation_ref · string · $ref ./common-ids.schema.json#/$defs/blob_ref
Content-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
oneOf · oneOf[5] · object · $ref #/$defs/agent_runtime_approval_outcome
* approval_request_id · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
* status · string (enum) · $ref #/$defs/agent_status
Controller lifecycle intent axis. Closed enum; only the controller's pause / resume / deactivate lifecycle events change it. Pairing and key facts are reflected through the generic readiness axis and open-handle fields, never through a fourth generic state axis (key-management.md §3.6.1).
enum: "active" "paused" "deactivated"
oneOf · oneOf[6] · object · $ref #/$defs/agent_runtime_approval_status_request_body
Runtime-side poll for the controller decision on a previously submitted runtime key request. The pairing_request_id, pairing_code, and agent_id triple is the query credential and MUST be sent in the JSON body, never in URL path or query string. A record miss and a pairing_code or agent_id mismatch MUST be indistinguishable (both not_found). HTTP responses MUST carry Retry-After; clients wait at least that interval and stop polling after pairing expiry.
* pairing_request_id · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
* pairing_code · string · $ref #/$defs/pairing_secret
One-time eight-digit decimal pairing code generated uniformly by a CSPRNG, including leading zeroes. It is accepted only with the matching opaque pairing_request_id; the code alone is never a lookup credential. It is transmitted only in JSON bodies, never in URLs or logs.
pattern: ^[0-9]{8}$
* agent_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
oneOf · oneOf[7] · object · $ref #/$defs/agent_runtime_approval_status_outcome
Operation-local status for the exact handle/candidate. Authorization and signer-evidence fields are present only after durable RealmCommit activation. The runtime checks its own method/raw-key digest, validates the complete current_signer_evidence closure, independently rebuilds its authenticated root and signer_resolution_evidence_ref with the SDK canonical helper, then persists both for offline Event authoring; authorized_event_ref is provenance and MUST NOT be used as the signer evidence ref. Expired, unknown or invalidated handles use uniform anti-enumeration behavior. Status never authorizes a key by itself.
* lifecycle · string (enum) · $ref #/$defs/agent_status
Controller lifecycle intent axis. Closed enum; only the controller's pause / resume / deactivate lifecycle events change it. Pairing and key facts are reflected through the generic readiness axis and open-handle fields, never through a fourth generic state axis (key-management.md §3.6.1).
enum: "active" "paused" "deactivated"
* runtime_state · string (enum) · $ref #/$defs/agent_runtime_state
Operation-local diagnostic enum used only by agent_runtime_approval_status_outcome on the unauthenticated pairing poll. It is mechanically derived from the polled handle and key facts, is never writable, and MUST NOT appear in generic Agent list/get/key_state projections: no active accepted key authorization with an unexpired bootstrap handle is pending_runtime_key; no active key with the bootstrap handle expired is pairing_expired; an active key with no unconsumed replacement handle is ready; an active key with an unexpired replacement handle is replacing.
enum: "pending_runtime_key" "ready" "replacing" "pairing_expired"
* readiness · object · $ref #/$defs/agent_readiness
allOf · allOf[0] · ?
allOf · allOf[1] · ?
* state · string (enum)
enum: "ready" "not_ready"
* blockers · array<string (enum)>
items · string (enum)
enum: "runtime_key_missing" "pairing_open"
* presence · object · $ref #/$defs/agent_presence
Short-lived reachability signal only. It never substitutes for lifecycle or readiness and does not use a protocol-wide fixed five-minute refresh interval.
* state · string (enum)
enum: "online" "offline" "unknown"
* expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* refresh_after · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
approval_request_id · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
authorized_event_ref · string · $ref #/$defs/event_id
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
authorized_verification_method · string · $ref #/$defs/did_url
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
authorized_public_key_digest · string · $ref #/$defs/digest
SHA-256 of the decoded 32-byte Ed25519 public key using the unique agent_signing_public_key_digest helper; the runtime compares it to its own key.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
signer_resolution_evidence_ref · string · $ref ./authenticated-signer-resolution-evidence.schema.json#/$defs/signer_evidence_ref
Content address of current_signer_evidence.authenticated_signer_evidence. The runtime MUST recompute it from the complete canonical root and reject a mismatch.
pattern: ^ak:signer_evidence:sha256:[0-9a-f]{64}$
current_signer_evidence · object · $ref #/$defs/agent_current_signer_evidence
Complete content-addressed Agent signer root for the currently authorized runtime key. signer_resolution_evidence_ref MUST equal SHA-256(RFC8785-JCS(authenticated_signer_evidence)) in the registered ak:signer_evidence form, and MUST equal the sibling signer_resolution_evidence_ref of the carrier object byte for byte. authenticated_signer_evidence is the compact six-member signer-resolution evidence and carries no closure of its own; the portable Agent Authority closure travels as agent-authority-evidence.schema.json#/$defs/agent_authority_state_evidence, never inside this root.
* signer_resolution_evidence_ref · string · $ref ./authenticated-signer-resolution-evidence.schema.json#/$defs/signer_evidence_ref
pattern: ^ak:signer_evidence:sha256:[0-9a-f]{64}$
* authenticated_signer_evidence · allOf[2] · $ref ./authenticated-signer-resolution-evidence.schema.json#/$defs/agent_signer_evidence
allOf · allOf[0] · $ref #/$defs/base · $ref #/$defs/base
allOf · allOf[1] · object
signer_kind · const "agent"
enum: "agent"
oneOf · oneOf[8] · object · $ref #/$defs/agent_provision_request_body
Controller-authored Agent bootstrap. Before prepare, the controller publishes a signed, PCR-independent did:webvh inception whose document contains the managed-controller delegation but no ArkretPrincipalControlRealm service. prepare receives that did, verifies the accepted inception and returns its exact initial_resolution plus an opaque allocation. The controller freezes the Agent PCR genesis with that commitment, derives principal_control_realm_id, and commits one ak.agent.provision Event. After PCR acceptance, the controller publishes the pre-rotation-authorized DID update containing the create-locked Realm binding. The service exposes the Agent and pairing handle only after that update is accepted.
oneOf · oneOf[0] · object
phase · const "prepare"
enum: "prepare"
oneOf · oneOf[1] · object
phase · const "commit"
enum: "commit"
* phase · string (enum)
enum: "prepare" "commit"
* operation_id · string · $ref ./principal-operations.schema.json#/$defs/operation_id
pattern: ^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* idempotency_key · string · $ref ./principal-operations.schema.json#/$defs/opaque_id
agent_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* did · string · $ref ./common-ids.schema.json#/$defs/agent_did
Canonical bare did:webvh identity of a durable Agent. Its accepted bootstrap history is controller-authored and must contain a continuous inception followed by the create-locked PCR binding update.
pattern: ^did:webvh:[^\s:/?#]+:[^\s/?#]+$
principal_control_realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* slug · string (arkret-agent-slug) · format=arkret-agent-slug · $ref #/$defs/agent_slug
Canonical controller-scoped Agent Agent selector slug. Maximum 64 Unicode code points in prepared form.
pattern: ^[^\s:@/#?\\]+$
* requested_scope · object · $ref #/$defs/agent_key_scope
Agent scope object with two uses. In POST /_arkret/self/agents requested_scope it is the required immutable global Agent ceiling; in ak.agent.key.authorize it is a per-key ceiling that MAY be narrower but MUST be an actions/resources/constraints subset of the provision ceiling. It is never a capability grant. actions may contain service operation ids and content action tokens; an omitted action can never be restored by a key, Realm grant or session. resources constrain the service surface and may optionally narrow later content resources, but never authorize content by themselves. Provisioning and pairing do not materialize capability grants from this object; effective authority is the intersection of provision ceiling, key ceiling, independent Realm-scoped grants, session request, membership and policy, with participation applied as an additional deny gate.
* actions · $ref #/$defs/string_list · $ref #/$defs/string_list
Literal action ceiling. Every downstream key scope, grant or session action MUST appear here; action families, prefixes and subsumption do not widen it.
* resources · array<object>
Selector ceiling, not authorization. Each downstream selector must be covered by a parent selector. operation/service parents cover the same kind and matching explicit field and cannot carry content fields. The content-kind vocabulary is the ResourceSelector vocabulary except '*'; kind=realm covers every Realm-local content kind in the matching Realm and other content kinds cover only the same kind. Omitted parent realm_id is a cross-Realm ceiling wildcard and omitted exact ref is a same-kind/same-Realm wildcard. With no content selector, later Realm grants still choose concrete resources and no content wildcard is granted.
items · object
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
* kind · string (enum)
enum: "realm" "space" "circle" "strand" "message" "morph" "object" "relation" "view" "event" "actor" "schema" "policy" "invite" "notification" "read_cursor" "blob" "operation" "service"
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
resource_ref · $ref #/$defs/object_ref · $ref #/$defs/object_ref
schema_ref · string · $ref #/$defs/non_empty_string
operation · string · $ref #/$defs/non_empty_string
service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
constraints · array<$ref ./grant-constraint.schema.json>
Global mandatory constraints. Every effective key/grant/session evaluation MUST retain and AND these constraints; downstream scopes may add stricter constraints but MUST NOT omit or relax provision constraints.
items · object · $ref ./grant-constraint.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · ?
allOf · allOf[6] · ?
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
constraint_id · string
Optional stable identifier of this constraint within the grant; used for diagnostics and overrides.
pattern: ^(?!ak:)
* constraint_kind · string (enum)
Constraint family discriminator. v1 collapses what were 15 types into 8 by absorbing narrowly-scoped types into their conceptual parent: edit_window → temporal; container_move → scope_limitation; rate_limiting + resource_limit → quota; approval_workflow + accountability + device_session → claim_based (with constraint_subkind); encryption_requirement + visibility_control → confidentiality (with constraint_subkind). Use the optional 'constraint_subkind' field to indicate the original specialization where evaluation logic differs.
enum: "temporal" "field_access" "kind_restriction" "scope_limitation" "authority_control" "quota" "claim_based" "confidentiality"
* effect · string (enum)
enum: "allow" "deny" "quarantine" "require_review"
evaluation_class · string (enum)
Cacheability/dependency hint for the authorization evaluator. stateless = pure function of (constraint, op, now); grant_local = depends on the grant object only; realm_state = depends on the exact Realm authority revision (membership, policy_version, etc.); external = depends on data outside that authority state (claim revocation status, rate-limit counts, async approval). Each constraint_kind has a canonical evaluation_class declared in constraint-schema.md §2.3; implementations MAY tighten (e.g. grant_local → stateless) but MUST NOT loosen (e.g. external as stateless). Auth evaluators SHOULD use this hint to gate fast-path caching.
enum: "stateless" "grant_local" "realm_state" "external"
constraint_subkind · string (enum)
Optional discriminator within a constraint_kind. Standard values: claim_based.{claim,approval,accountability}; quota.{rate,resource}; confidentiality.{encryption,visibility}; temporal.{window,edit_window,redact_window,session}; authority_control.{applet_authority}. Per constraint-schema.md §2.2, device/session binding is NOT an independent constraint_subkind: it is the claim_based constraint_subkind=claim sub-case expressed via an accepted PCR device issuer. Implementations MAY require constraint_subkind for these families and fail closed on unknown values.
enum: "claim" "approval" "accountability" "rate" "resource" "encryption" "visibility" "window" "edit_window" "redact_window" "session" "applet_authority"
applies_to_actions · array<string>
Optional restriction of a temporal constraint to specific capability actions (e.g. ['ak.message.revise.own', 'ak.message.redact.own']). Action mismatch is neutral in the effect fold: satisfied for effect=allow and not matched for deny/quarantine/require_review.
items · string
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
not_before · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
recurrence · object
Recurrence rule for temporal constraints. Used by constraint-schema.md §3.1.
frequency · string (enum)
enum: "daily" "weekly" "monthly" "custom"
days · array<string (enum)>
items · string (enum)
enum: "mon" "tue" "wed" "thu" "fri" "sat" "sun"
window_start · string
pattern: ^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$
window_end · string
pattern: ^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$
timezone · string
max_duration · string
ISO 8601 duration.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_session_duration · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
inactivity_timeout · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
expires_after · string
ISO 8601 duration; used by approval_workflow constraint instead of expires_after_ms.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_edit_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_redact_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
redact_after_window_allowed · boolean
condition · object
Conditional predicate for field_access and similar constraints. The `kind` value is a registered named condition from constraint-schema.md §4.1; unknown kinds MUST fail closed. Implementations MUST NOT introduce ad hoc string DSL predicates.
* kind · string (enum)
enum: "object_is_owned_by_actor" "actor_is_assignee" "actor_is_responsible" "actor_is_guardian" "actor_is_controller" "object_in_actor_container" "object_is_unencrypted" "object_is_encrypted" "always" "never"
allowed_write_fields · array<string>
items · string
denied_write_fields · array<string>
items · string
allowed_read_fields · array<string>
items · string
denied_read_fields · array<string>
items · string
sensitive_fields · array<string>
items · string
sensitive_handling · string (enum)
enum: "redact" "hash" "omit"
allowed_object_kinds · array<string>
items · string
denied_object_kinds · array<string>
items · string
allowed_morph_kinds · array<string>
items · string
denied_morph_kinds · array<string>
items · string
allowed_space_kinds · array<string>
Allowed Space kinds (e.g. 'board', 'list', or profile-registered kinds like 'swimlane', 'calendar_bucket'). Reducer/profile MUST validate kind value.
items · string
denied_space_kinds · array<string>
items · string
allowed_facets · array<string (enum)>
items · string (enum)
enum: "container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"
denied_facets · array<string (enum)>
items · string (enum)
enum: "container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"
allowed_view_ids · array<string>
items · string
pattern: ^ak:view:[A-Za-z0-9_-]{44}$
allowed_strand_ids · array<string>
items · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
denied_strand_ids · array<string>
items · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
allowed_space_ids · array<string>
items · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
denied_space_ids · array<string>
items · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
allowed_circle_ids · array<$ref ./common-ids.schema.json#/$defs/circle_id>
Limits Circle-scoped capability actions to the listed Circle ids. Used by ak.circle.manage / ak.circle.member.manage style grants; unconstrained Realm-wide Circle management grants are not a normal permission shape.
items · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
allowed_session_ids · array<string>
Limits applet interop-session operations to the listed applet-defined session correlation ids.
items · string
pattern: ^(?!ak:)
allowed_view_kinds · array<string>
items · string
allowed_view_renderers · array<string>
items · string
denied_view_kinds · array<string>
items · string
denied_view_renderers · array<string>
items · string
allowed_relation_kinds · array<string>
items · string
allowed_from_container_refs · array<string>
items · string
pattern: ^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$
allowed_to_container_refs · array<string>
items · string
pattern: ^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$
wip_limit_override · boolean
example: false
allowed_tracks · array<string>
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
denied_tracks · array<string>
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
blob_presign_scope · object
Scope limiter for ak.self.blob.command.presign.v1 grants: allowed purposes plus optional blob/realm restrictions.
* allowed_purposes · array<string (enum)>
items · string (enum)
enum: "media_inline" "thumbnail" "download"
blob_ref_pattern · string
realm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
items · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
allowed_data_labels · array<string>
Data classification labels this grant may read, export, transform, or send to external endpoints.
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
allowed_endpoints · array<string>
Allowed outbound endpoint origins or deployment-approved endpoint patterns for applet / agent / connector operations.
items · string
max_authority_depth · integer
Maximum remaining authority hops. Bounded by the canonical authority-chain depth ceiling (4) defined in zh/conformance/scalability-constraints.md §3 and zh/authz/capabilities.md §10.2; reducers MUST reject grants declaring a larger value at accept time rather than only truncating during DFS.
authority_path_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
authority_regrant_allowed · boolean
authority_scope · string (enum)
enum: "narrowing_only" "same_scope" "custom"
applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
registration_epoch · string
authority_control(constraint_subkind=applet_authority) binding to the canonical Applet registration epoch.
pattern: ^sha256:[0-9a-f]{64}$
blob_max_bytes · integer
blob_presign_max_ttl_seconds · integer
Maximum TTL, in seconds, that this grant permits for ak.blob.presign. The service must clamp requested max_age_seconds to the smaller of this value and deployment policy.
max_total_blob_bytes · integer
max_artifact_bytes · integer
Maximum artifact size in bytes for applet / agent / export operations.
max_operations · integer
Maximum number of distinct accepted idempotency identities in one UTC epoch-aligned fixed period. Enforcement is a linearizable check-and-reserve at one logical quota authority shared by every node in the enforcing service; per-node duplicated budgets and overshoot are forbidden.
period · string
ISO 8601 duration. For quota constraints, a stricter conditional schema permits only a non-zero fixed-length week/day/hour/minute/second duration; year/month durations are forbidden so every authority derives the same UTC epoch-aligned window id.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
burst · integer
Optional token-bucket capacity at the same logical quota authority, capped by max_operations and refilled at max_operations/period. It never increases the fixed-window total budget.
constraint_scope · string (enum)
Closed v1 quota counting scope. Unknown values are schema violations and MUST fail closed. Quota counters are actor-bound; the enum selects the additional slicing dimension: actor only, actor+space, actor+realm, or actor across all nodes/regions of the enforcing service's global quota domain. global is not an implicit federation-wide counter. Every node in the service domain MUST share one logical linearizable quota authority.
enum: "per_actor" "per_space" "per_realm" "global"
max_resources · integer
resource_kind · string
approval_required · boolean
approval_mode · string (enum)
The only approval mode of v1. The approved write MUST NOT take effect before the approval evidence is verified and accepted in the same transaction (zh/authz/constraint-schema.md section 9.2.7). There is no second mode and no path that first materializes a proposal object and then approves that object.
enum: "before_commit"
approval_actor_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
approval_relation · string (enum)
Responsibility classification of this grant explicit approval_actor_ids roster. It never creates a second dynamic roster or supplies action/scope capability. Missing explicit roster cannot satisfy approval.
enum: "responsible" "controller" "guardian" "realm_admin" "custom"
timeout · string
Positive fixed ISO 8601 duration (week/day/hour/minute/second, no calendar year/month). Each approval vote is valid only when the target covering committed_at <= that vote input.approved_at + timeout, inclusive and with zero tolerance. The same rule applies to Event and operation targets; receiver clocks and first-seen timestamps never anchor it. Omission adds no grant-local age limit.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
approval_threshold · oneOf[2]
Closed executable vote threshold: majority means floor(N/2)+1, unanimous means N, and a positive integer is the exact quorum. N is the distinct eligible approver set at the accepting authority cut. Omission means unanimous. A missing or empty eligible set, or an integer greater than N, cannot satisfy approval. Repeated signatures by one approver count once. Parameterless quorum/custom strings are schema violations.
example: "unanimous"
oneOf · oneOf[0] · string (enum)
enum: "majority" "unanimous"
oneOf · oneOf[1] · integer
accountability_required · boolean
guardian_approval_required · boolean
controller_approval_required · boolean
required_claims · array<object>
Conditional claim requirements. resource-selector-grammar.md §3.3 caps this array at 32 entries as a normative DoS guard; the schema enforces maxItems:32 so condition-selector grants cannot smuggle in unbounded claim objects.
items · object
anyOf · anyOf[0] · ?
anyOf · anyOf[1] · ?
* claim_kind · string
issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
trusted_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
subject_matches_actor · boolean
If true, the credential subject did_core_id MUST match the actor did_core_id after each proof's DID is independently validated and projected through its registered method adapter.
example: true
value_constraints · object
Per-field equality / membership constraints on credential claims.
organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
status · string
roles · array<string>
items · string
trusted_claim_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
claim_refresh_required · boolean
claim_max_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
allowed_history_access_values · array<string (enum)>
items · string (enum)
enum: "since_join" "all_history_for_current_members"
redacted_history_allowed · boolean
encryption_required · boolean
min_encryption_level · string (enum)
confidentiality(constraint_subkind=encryption) static floor: the minimum content-encryption mechanism the grant requires. Pure static declaration evaluated as stateless unless cross-checked against the scope's current MLS activation state (see constraint-schema.md section 12).
enum: "none" "mls_rfc9420" "external"
plaintext_fallback_allowed · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant permits plaintext in a scope that has no accepted ak.mls.genesis. After activation the flag cannot restore plaintext; the write MUST be rejected with mls_activation_irreversible. See constraint-schema.md §12.
audit_trail_required · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant requires an audit trail (e.g. active Audit Applet Binding). See constraint-schema.md §12.
key_rotation_period · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_key_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
key_backup_required · boolean
approved_key_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
depends_on_moderation_state · boolean
Cache-invalidation hint: when true, this grant's authorization decisions depend on the moderation_state typed current result (see capabilities.md §18.1) and the grant's cache entry MUST be invalidated when that typed current result changes. Default false: ordinary grants (ak.strand.update / ak.message.create / organization membership grants) do NOT take a cache hit on every moderation decision. v1 capabilities.md §18.1 lists three conditions where MUST be explicitly true (moderator-role grants, condition-selector subjects referencing moderation state, constraints referencing moderation queue / typed current result). Schema-side enforcement of condition (2) is in capability-grant.schema.json via if/then on actions[]; conditions (1) and (3) are reducer-side lint. Cache invalidation hint outside the eight constraint families; it does not participate in allow/deny evaluation and is documented in capabilities.md §6 / constraint-schema.md.
allowed_managed_actor_roles · array<string (enum)>
Ordinary authority_control permits only these accepted roles of the Applet bound by the parent applet_authority constraint; no arbitrary third-party regrant.
items · string (enum)
enum: "bot" "ghost"
(^x_[a-z][a-z0-9_]{0,63}$) · any
allocation_handle · string · $ref ./principal-operations.schema.json#/$defs/opaque_id
provision_event · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · $ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input
* proof · $ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proof
pairing_ttl_ms · integer
controller_station_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
oneOf · oneOf[9] · object · $ref #/$defs/agent_provision_outcome
Four-stage outcome. prepare returns awaiting_controller_event with an accepted inception commitment. An accepted ak.agent.provision moves it to awaiting_pcr_genesis. PCR acceptance moves it to awaiting_did_binding until the controller-authored continuous WebVH update publishes the exact Realm service entry. The Agent, pairing handle and list/get projection become visible only at complete.
oneOf · oneOf[0] · object
status · const "awaiting_controller_event"
enum: "awaiting_controller_event"
oneOf · oneOf[1] · object
status · const "awaiting_pcr_genesis"
enum: "awaiting_pcr_genesis"
oneOf · oneOf[2] · object
status · const "awaiting_did_binding"
enum: "awaiting_did_binding"
oneOf · oneOf[3] · object
status · const "complete"
enum: "complete"
* status · string (enum)
enum: "awaiting_controller_event" "awaiting_pcr_genesis" "awaiting_did_binding" "complete"
* agent_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* did · string · $ref ./common-ids.schema.json#/$defs/agent_did
Canonical bare did:webvh identity of a durable Agent. Its accepted bootstrap history is controller-authored and must contain a continuous inception followed by the create-locked PCR binding update.
pattern: ^did:webvh:[^\s:/?#]+:[^\s/?#]+$
* initial_resolution · object · $ref ./identity-resolution.schema.json#/$defs/resolution_commitment
Owner-committed current did and method-native history position. For a deterministic method, method_history_head and version_id use the adapter-defined deterministic canonical values; they are never omitted.
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* method_history_head · string
* version_id · string
pattern: ^(?!ak:)
principal_control_realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
controller_realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
allocation_handle · string · $ref ./principal-operations.schema.json#/$defs/opaque_id
Service-signed opaque allocation binding returned only by prepare and presented unchanged by commit.
* controller_authorization_ref · string · $ref #/$defs/did_url
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
pairing_request_id · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
pairing_code · string · $ref #/$defs/pairing_secret
One-time eight-digit decimal pairing code generated uniformly by a CSPRNG, including leading zeroes. It is accepted only with the matching opaque pairing_request_id; the code alone is never a lookup credential. It is transmitted only in JSON bodies, never in URLs or logs.
pattern: ^[0-9]{8}$
expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
oneOf · oneOf[10] · object · $ref #/$defs/agent_renew_pairing_outcome
Fresh single-use opaque pairing handle and uniformly generated eight-digit decimal CSPRNG code. Attach or replacement is derived at approval from the complete current authorization set. Renew does not change principal, slug, lifecycle, keys, grants or history and never gates on sibling slug availability.
* agent_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* principal_control_realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* controller_authorization_ref · string · $ref #/$defs/did_url
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* requested_scope_digest · string · $ref #/$defs/digest
Unchanged digest of the immutable requested_scope commitment in the Agent DID binding; the complete scope remains controller-private.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* pairing_request_id · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
* pairing_code · string · $ref #/$defs/pairing_secret
One-time eight-digit decimal pairing code generated uniformly by a CSPRNG, including leading zeroes. It is accepted only with the matching opaque pairing_request_id; the code alone is never a lookup credential. It is transmitted only in JSON bodies, never in URLs or logs.
pattern: ^[0-9]{8}$
* expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
oneOf · oneOf[11] · object · $ref #/$defs/agent_pairing_bootstrap
One-time bootstrap material handed to an Agent runtime after provisioning. New resolver responses MUST include runtime_identity; its omission is only for reading older stored bootstrap material. This is not a session grant, capability grant or long-term secret.
* arkret_base_url · string (uri) · format=uri
pattern: ^https?://
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* agent_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* pairing_request_id · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
* pairing_code · string · $ref #/$defs/pairing_secret
One-time eight-digit decimal pairing code generated uniformly by a CSPRNG, including leading zeroes. It is accepted only with the matching opaque pairing_request_id; the code alone is never a lookup credential. It is transmitted only in JSON bodies, never in URLs or logs.
pattern: ^[0-9]{8}$
* pairing_expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
runtime_identity · object · $ref #/$defs/agent_pairing_runtime_identity
Identity context obtained from the accepted Agent/controller binding. It does not authorize the runtime key. The verification method controller MUST project to bootstrap.agent_id; its fragment is a key label, not a human device identity.
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* station_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* verification_method · string · $ref #/$defs/did_url
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
oneOf · oneOf[12] · object · $ref #/$defs/agent_pairing_resolve_request_body
Body-only resolver input for short agent pairing handoff links. The token is obtained from a URL fragment or equivalent out-of-band channel and MUST NOT be sent in URL path or query.
* pairing_token · string
pattern: ^[A-Za-z0-9_-]+$
oneOf · oneOf[13] · object · $ref #/$defs/agent_list
* agents · array<$ref #/$defs/agent_projection>
items · object · $ref #/$defs/agent_projection
* agent_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
display_name · string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_256
NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern: ^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$
* slug · string (arkret-agent-slug) · format=arkret-agent-slug · $ref #/$defs/agent_slug
Canonical controller-scoped Agent Agent selector slug. Maximum 64 Unicode code points in prepared form.
pattern: ^[^\s:@/#?\\]+$
avatar_blob_ref · string · $ref #/$defs/blob_ref
Content-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* lifecycle · string (enum) · $ref #/$defs/agent_status
Controller lifecycle intent axis. Closed enum; only the controller's pause / resume / deactivate lifecycle events change it. Pairing and key facts are reflected through the generic readiness axis and open-handle fields, never through a fourth generic state axis (key-management.md §3.6.1).
enum: "active" "paused" "deactivated"
* readiness · object · $ref #/$defs/agent_readiness
allOf · allOf[0] · ?
allOf · allOf[1] · ?
* state · string (enum)
enum: "ready" "not_ready"
* blockers · array<string (enum)>
items · string (enum)
enum: "runtime_key_missing" "pairing_open"
* presence · object · $ref #/$defs/agent_presence
Short-lived reachability signal only. It never substitutes for lifecycle or readiness and does not use a protocol-wide fixed five-minute refresh interval.
* state · string (enum)
enum: "online" "offline" "unknown"
* expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* refresh_after · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
created_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
updated_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
next_cursor · string
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
oneOf · oneOf[14] · object · $ref #/$defs/agent_view
* agent · object · $ref #/$defs/agent_projection
* agent_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
display_name · string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_256
NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern: ^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$
* slug · string (arkret-agent-slug) · format=arkret-agent-slug · $ref #/$defs/agent_slug
Canonical controller-scoped Agent Agent selector slug. Maximum 64 Unicode code points in prepared form.
pattern: ^[^\s:@/#?\\]+$
avatar_blob_ref · string · $ref #/$defs/blob_ref
Content-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* lifecycle · string (enum) · $ref #/$defs/agent_status
Controller lifecycle intent axis. Closed enum; only the controller's pause / resume / deactivate lifecycle events change it. Pairing and key facts are reflected through the generic readiness axis and open-handle fields, never through a fourth generic state axis (key-management.md §3.6.1).
enum: "active" "paused" "deactivated"
* readiness · object · $ref #/$defs/agent_readiness
allOf · allOf[0] · ?
allOf · allOf[1] · ?
* state · string (enum)
enum: "ready" "not_ready"
* blockers · array<string (enum)>
items · string (enum)
enum: "runtime_key_missing" "pairing_open"
* presence · object · $ref #/$defs/agent_presence
Short-lived reachability signal only. It never substitutes for lifecycle or readiness and does not use a protocol-wide fixed five-minute refresh interval.
* state · string (enum)
enum: "online" "offline" "unknown"
* expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* refresh_after · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
created_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
updated_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
grants · array<$ref #/$defs/grant_snapshot>
items · object · $ref #/$defs/grant_snapshot
* grant_id · string · $ref #/$defs/grant_id
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
grant_digest · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
key_state · object · $ref #/$defs/key_state
Controller-private key, pairing-handle and authorization material for a generic Agent view. When active authorization exists, signer_resolution_evidence_ref and current_signer_evidence provide the same complete activation closure delivered to the runtime; an Account Authority may independently rebuild it, while authorized_event_ref remains provenance only. This object deliberately carries no lifecycle, readiness, presence, runtime_state or backup-readiness field: the only three generic status axes are siblings on agent_projection, while pairing poll alone exposes its operation-local runtime_state diagnostic.
* agent_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* station_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* principal_control_realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* controller_authorization_ref · string · $ref #/$defs/did_url
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* requested_scope · object · $ref #/$defs/agent_key_scope
Agent scope object with two uses. In POST /_arkret/self/agents requested_scope it is the required immutable global Agent ceiling; in ak.agent.key.authorize it is a per-key ceiling that MAY be narrower but MUST be an actions/resources/constraints subset of the provision ceiling. It is never a capability grant. actions may contain service operation ids and content action tokens; an omitted action can never be restored by a key, Realm grant or session. resources constrain the service surface and may optionally narrow later content resources, but never authorize content by themselves. Provisioning and pairing do not materialize capability grants from this object; effective authority is the intersection of provision ceiling, key ceiling, independent Realm-scoped grants, session request, membership and policy, with participation applied as an additional deny gate.
* actions · $ref #/$defs/string_list · $ref #/$defs/string_list
Literal action ceiling. Every downstream key scope, grant or session action MUST appear here; action families, prefixes and subsumption do not widen it.
* resources · array<object>
Selector ceiling, not authorization. Each downstream selector must be covered by a parent selector. operation/service parents cover the same kind and matching explicit field and cannot carry content fields. The content-kind vocabulary is the ResourceSelector vocabulary except '*'; kind=realm covers every Realm-local content kind in the matching Realm and other content kinds cover only the same kind. Omitted parent realm_id is a cross-Realm ceiling wildcard and omitted exact ref is a same-kind/same-Realm wildcard. With no content selector, later Realm grants still choose concrete resources and no content wildcard is granted.
items · object
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
* kind · string (enum)
enum: "realm" "space" "circle" "strand" "message" "morph" "object" "relation" "view" "event" "actor" "schema" "policy" "invite" "notification" "read_cursor" "blob" "operation" "service"
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
resource_ref · $ref #/$defs/object_ref · $ref #/$defs/object_ref
schema_ref · string · $ref #/$defs/non_empty_string
operation · string · $ref #/$defs/non_empty_string
service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
constraints · array<$ref ./grant-constraint.schema.json>
Global mandatory constraints. Every effective key/grant/session evaluation MUST retain and AND these constraints; downstream scopes may add stricter constraints but MUST NOT omit or relax provision constraints.
items · object · $ref ./grant-constraint.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · ?
allOf · allOf[6] · ?
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
constraint_id · string
Optional stable identifier of this constraint within the grant; used for diagnostics and overrides.
pattern: ^(?!ak:)
* constraint_kind · string (enum)
Constraint family discriminator. v1 collapses what were 15 types into 8 by absorbing narrowly-scoped types into their conceptual parent: edit_window → temporal; container_move → scope_limitation; rate_limiting + resource_limit → quota; approval_workflow + accountability + device_session → claim_based (with constraint_subkind); encryption_requirement + visibility_control → confidentiality (with constraint_subkind). Use the optional 'constraint_subkind' field to indicate the original specialization where evaluation logic differs.
enum: "temporal" "field_access" "kind_restriction" "scope_limitation" "authority_control" "quota" "claim_based" "confidentiality"
* effect · string (enum)
enum: "allow" "deny" "quarantine" "require_review"
evaluation_class · string (enum)
Cacheability/dependency hint for the authorization evaluator. stateless = pure function of (constraint, op, now); grant_local = depends on the grant object only; realm_state = depends on the exact Realm authority revision (membership, policy_version, etc.); external = depends on data outside that authority state (claim revocation status, rate-limit counts, async approval). Each constraint_kind has a canonical evaluation_class declared in constraint-schema.md §2.3; implementations MAY tighten (e.g. grant_local → stateless) but MUST NOT loosen (e.g. external as stateless). Auth evaluators SHOULD use this hint to gate fast-path caching.
enum: "stateless" "grant_local" "realm_state" "external"
constraint_subkind · string (enum)
Optional discriminator within a constraint_kind. Standard values: claim_based.{claim,approval,accountability}; quota.{rate,resource}; confidentiality.{encryption,visibility}; temporal.{window,edit_window,redact_window,session}; authority_control.{applet_authority}. Per constraint-schema.md §2.2, device/session binding is NOT an independent constraint_subkind: it is the claim_based constraint_subkind=claim sub-case expressed via an accepted PCR device issuer. Implementations MAY require constraint_subkind for these families and fail closed on unknown values.
enum: "claim" "approval" "accountability" "rate" "resource" "encryption" "visibility" "window" "edit_window" "redact_window" "session" "applet_authority"
applies_to_actions · array<string>
Optional restriction of a temporal constraint to specific capability actions (e.g. ['ak.message.revise.own', 'ak.message.redact.own']). Action mismatch is neutral in the effect fold: satisfied for effect=allow and not matched for deny/quarantine/require_review.
items · string
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
not_before · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
recurrence · object
Recurrence rule for temporal constraints. Used by constraint-schema.md §3.1.
frequency · string (enum)
enum: "daily" "weekly" "monthly" "custom"
days · array<string (enum)>
items · string (enum)
enum: "mon" "tue" "wed" "thu" "fri" "sat" "sun"
window_start · string
pattern: ^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$
window_end · string
pattern: ^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$
timezone · string
max_duration · string
ISO 8601 duration.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_session_duration · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
inactivity_timeout · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
expires_after · string
ISO 8601 duration; used by approval_workflow constraint instead of expires_after_ms.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_edit_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_redact_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
redact_after_window_allowed · boolean
condition · object
Conditional predicate for field_access and similar constraints. The `kind` value is a registered named condition from constraint-schema.md §4.1; unknown kinds MUST fail closed. Implementations MUST NOT introduce ad hoc string DSL predicates.
* kind · string (enum)
enum: "object_is_owned_by_actor" "actor_is_assignee" "actor_is_responsible" "actor_is_guardian" "actor_is_controller" "object_in_actor_container" "object_is_unencrypted" "object_is_encrypted" "always" "never"
allowed_write_fields · array<string>
items · string
denied_write_fields · array<string>
items · string
allowed_read_fields · array<string>
items · string
denied_read_fields · array<string>
items · string
sensitive_fields · array<string>
items · string
sensitive_handling · string (enum)
enum: "redact" "hash" "omit"
allowed_object_kinds · array<string>
items · string
denied_object_kinds · array<string>
items · string
allowed_morph_kinds · array<string>
items · string
denied_morph_kinds · array<string>
items · string
allowed_space_kinds · array<string>
Allowed Space kinds (e.g. 'board', 'list', or profile-registered kinds like 'swimlane', 'calendar_bucket'). Reducer/profile MUST validate kind value.
items · string
denied_space_kinds · array<string>
items · string
allowed_facets · array<string (enum)>
items · string (enum)
enum: "container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"
denied_facets · array<string (enum)>
items · string (enum)
enum: "container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"
allowed_view_ids · array<string>
items · string
pattern: ^ak:view:[A-Za-z0-9_-]{44}$
allowed_strand_ids · array<string>
items · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
denied_strand_ids · array<string>
items · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
allowed_space_ids · array<string>
items · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
denied_space_ids · array<string>
items · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
allowed_circle_ids · array<$ref ./common-ids.schema.json#/$defs/circle_id>
Limits Circle-scoped capability actions to the listed Circle ids. Used by ak.circle.manage / ak.circle.member.manage style grants; unconstrained Realm-wide Circle management grants are not a normal permission shape.
items · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
allowed_session_ids · array<string>
Limits applet interop-session operations to the listed applet-defined session correlation ids.
items · string
pattern: ^(?!ak:)
allowed_view_kinds · array<string>
items · string
allowed_view_renderers · array<string>
items · string
denied_view_kinds · array<string>
items · string
denied_view_renderers · array<string>
items · string
allowed_relation_kinds · array<string>
items · string
allowed_from_container_refs · array<string>
items · string
pattern: ^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$
allowed_to_container_refs · array<string>
items · string
pattern: ^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$
wip_limit_override · boolean
example: false
allowed_tracks · array<string>
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
denied_tracks · array<string>
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
blob_presign_scope · object
Scope limiter for ak.self.blob.command.presign.v1 grants: allowed purposes plus optional blob/realm restrictions.
* allowed_purposes · array<string (enum)>
items · string (enum)
enum: "media_inline" "thumbnail" "download"
blob_ref_pattern · string
realm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
items · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
allowed_data_labels · array<string>
Data classification labels this grant may read, export, transform, or send to external endpoints.
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
allowed_endpoints · array<string>
Allowed outbound endpoint origins or deployment-approved endpoint patterns for applet / agent / connector operations.
items · string
max_authority_depth · integer
Maximum remaining authority hops. Bounded by the canonical authority-chain depth ceiling (4) defined in zh/conformance/scalability-constraints.md §3 and zh/authz/capabilities.md §10.2; reducers MUST reject grants declaring a larger value at accept time rather than only truncating during DFS.
authority_path_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
authority_regrant_allowed · boolean
authority_scope · string (enum)
enum: "narrowing_only" "same_scope" "custom"
applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
registration_epoch · string
authority_control(constraint_subkind=applet_authority) binding to the canonical Applet registration epoch.
pattern: ^sha256:[0-9a-f]{64}$
blob_max_bytes · integer
blob_presign_max_ttl_seconds · integer
Maximum TTL, in seconds, that this grant permits for ak.blob.presign. The service must clamp requested max_age_seconds to the smaller of this value and deployment policy.
max_total_blob_bytes · integer
max_artifact_bytes · integer
Maximum artifact size in bytes for applet / agent / export operations.
max_operations · integer
Maximum number of distinct accepted idempotency identities in one UTC epoch-aligned fixed period. Enforcement is a linearizable check-and-reserve at one logical quota authority shared by every node in the enforcing service; per-node duplicated budgets and overshoot are forbidden.
period · string
ISO 8601 duration. For quota constraints, a stricter conditional schema permits only a non-zero fixed-length week/day/hour/minute/second duration; year/month durations are forbidden so every authority derives the same UTC epoch-aligned window id.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
burst · integer
Optional token-bucket capacity at the same logical quota authority, capped by max_operations and refilled at max_operations/period. It never increases the fixed-window total budget.
constraint_scope · string (enum)
Closed v1 quota counting scope. Unknown values are schema violations and MUST fail closed. Quota counters are actor-bound; the enum selects the additional slicing dimension: actor only, actor+space, actor+realm, or actor across all nodes/regions of the enforcing service's global quota domain. global is not an implicit federation-wide counter. Every node in the service domain MUST share one logical linearizable quota authority.
enum: "per_actor" "per_space" "per_realm" "global"
max_resources · integer
resource_kind · string
approval_required · boolean
approval_mode · string (enum)
The only approval mode of v1. The approved write MUST NOT take effect before the approval evidence is verified and accepted in the same transaction (zh/authz/constraint-schema.md section 9.2.7). There is no second mode and no path that first materializes a proposal object and then approves that object.
enum: "before_commit"
approval_actor_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
approval_relation · string (enum)
Responsibility classification of this grant explicit approval_actor_ids roster. It never creates a second dynamic roster or supplies action/scope capability. Missing explicit roster cannot satisfy approval.
enum: "responsible" "controller" "guardian" "realm_admin" "custom"
timeout · string
Positive fixed ISO 8601 duration (week/day/hour/minute/second, no calendar year/month). Each approval vote is valid only when the target covering committed_at <= that vote input.approved_at + timeout, inclusive and with zero tolerance. The same rule applies to Event and operation targets; receiver clocks and first-seen timestamps never anchor it. Omission adds no grant-local age limit.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
approval_threshold · oneOf[2]
Closed executable vote threshold: majority means floor(N/2)+1, unanimous means N, and a positive integer is the exact quorum. N is the distinct eligible approver set at the accepting authority cut. Omission means unanimous. A missing or empty eligible set, or an integer greater than N, cannot satisfy approval. Repeated signatures by one approver count once. Parameterless quorum/custom strings are schema violations.
example: "unanimous"
oneOf · oneOf[0] · string (enum)
enum: "majority" "unanimous"
oneOf · oneOf[1] · integer
accountability_required · boolean
guardian_approval_required · boolean
controller_approval_required · boolean
required_claims · array<object>
Conditional claim requirements. resource-selector-grammar.md §3.3 caps this array at 32 entries as a normative DoS guard; the schema enforces maxItems:32 so condition-selector grants cannot smuggle in unbounded claim objects.
items · object
anyOf · anyOf[0] · ?
anyOf · anyOf[1] · ?
* claim_kind · string
issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
trusted_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · …
recursion truncated at depth 8; see source schema for full shape
subject_matches_actor · boolean
If true, the credential subject did_core_id MUST match the actor did_core_id after each proof's DID is independently validated and projected through its registered method adapter.
example: true
value_constraints · object
Per-field equality / membership constraints on credential claims.
organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
status · string
roles · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
trusted_claim_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
claim_refresh_required · boolean
claim_max_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
allowed_history_access_values · array<string (enum)>
items · string (enum)
enum: "since_join" "all_history_for_current_members"
redacted_history_allowed · boolean
encryption_required · boolean
min_encryption_level · string (enum)
confidentiality(constraint_subkind=encryption) static floor: the minimum content-encryption mechanism the grant requires. Pure static declaration evaluated as stateless unless cross-checked against the scope's current MLS activation state (see constraint-schema.md section 12).
enum: "none" "mls_rfc9420" "external"
plaintext_fallback_allowed · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant permits plaintext in a scope that has no accepted ak.mls.genesis. After activation the flag cannot restore plaintext; the write MUST be rejected with mls_activation_irreversible. See constraint-schema.md §12.
audit_trail_required · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant requires an audit trail (e.g. active Audit Applet Binding). See constraint-schema.md §12.
key_rotation_period · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_key_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
key_backup_required · boolean
approved_key_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
depends_on_moderation_state · boolean
Cache-invalidation hint: when true, this grant's authorization decisions depend on the moderation_state typed current result (see capabilities.md §18.1) and the grant's cache entry MUST be invalidated when that typed current result changes. Default false: ordinary grants (ak.strand.update / ak.message.create / organization membership grants) do NOT take a cache hit on every moderation decision. v1 capabilities.md §18.1 lists three conditions where MUST be explicitly true (moderator-role grants, condition-selector subjects referencing moderation state, constraints referencing moderation queue / typed current result). Schema-side enforcement of condition (2) is in capability-grant.schema.json via if/then on actions[]; conditions (1) and (3) are reducer-side lint. Cache invalidation hint outside the eight constraint families; it does not participate in allow/deny evaluation and is documented in capabilities.md §6 / constraint-schema.md.
allowed_managed_actor_roles · array<string (enum)>
Ordinary authority_control permits only these accepted roles of the Applet bound by the parent applet_authority constraint; no arbitrary third-party regrant.
items · string (enum)
enum: "bot" "ghost"
(^x_[a-z][a-z0-9_]{0,63}$) · any
pairing_request_id · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
pairing_code · string · $ref #/$defs/pairing_secret
One-time eight-digit decimal pairing code generated uniformly by a CSPRNG, including leading zeroes. It is accepted only with the matching opaque pairing_request_id; the code alone is never a lookup credential. It is transmitted only in JSON bodies, never in URLs or logs.
pattern: ^[0-9]{8}$
pairing_expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
approval_request_id · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
pending_runtime_key_request · object · $ref #/$defs/agent_runtime_approval_controller_projection
Authenticated minimal frozen candidate projection. Raw key/method and optional attestation are public approval inputs; approval_request_id and stable digest do not change when a fresh PoP is accepted for the same candidate. Full possession proof and pairing secret are not included. Controller must inspect exact Agent, key fingerprint, scope/expiry and supersedes in the Event before signing.
* pairing_request_id · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
* agent_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* verification_method · string · $ref #/$defs/did_url
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* public_key · object · $ref #/$defs/agent_runtime_public_key
Closed v1 Agent runtime signing-key profile. Ed25519 is the fully-specified JOSE algorithm identifier from RFC 9864; polymorphic algorithm identifiers are rejected.
* kty · const "OKP"
enum: "OKP"
* kid · string · $ref #/$defs/non_empty_string
* algorithm · const "Ed25519"
enum: "Ed25519"
* key · string
pattern: ^[A-Za-z0-9_-]{43}$
runtime_attestation · object · $ref #/$defs/runtime_attestation
Optional runtime / workload attestation captured at pairing approval time. v1 enum includes self_asserted as baseline; future profiles MAY register TEE / SLSA / SPIFFE attestation kinds. Implementations encountering an unknown kind MUST fail closed.
* kind · string (enum)
v1 enum. Future profiles MAY extend via accepted attestation taxonomy.
enum: "self_asserted"
software · string
version · string
attestation_ref · string · $ref ./common-ids.schema.json#/$defs/blob_ref
Content-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
* approval_request_id · string · $ref #/$defs/opaque_local_id
Deployment-local short-lived account/auth artifact id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
* runtime_key_binding_digest · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
approval_requested_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
authorized_event_ref · string · $ref #/$defs/event_id
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
authorized_verification_method · string · $ref #/$defs/did_url
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
authorized_public_key_digest · string · $ref #/$defs/digest
SHA-256 of the decoded 32-byte Ed25519 public key using the unique agent_signing_public_key_digest helper; the runtime compares it to its own key.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
active_authorizations · array<$ref #/$defs/agent_key_authorization_state>
items · object · $ref #/$defs/agent_key_authorization_state
* key_id · allOf[2]
allOf · allOf[0] · string · $ref #/$defs/non_empty_string
allOf · allOf[1] · ? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floor
Lexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern: ^(?!ak:)
* verification_method · string · $ref #/$defs/did_url
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* authorized_event_ref · string · $ref #/$defs/event_id
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
signer_resolution_evidence_ref · string · $ref ./authenticated-signer-resolution-evidence.schema.json#/$defs/signer_evidence_ref
pattern: ^ak:signer_evidence:sha256:[0-9a-f]{64}$
current_signer_evidence · object · $ref #/$defs/agent_current_signer_evidence
Complete content-addressed Agent signer root for the currently authorized runtime key. signer_resolution_evidence_ref MUST equal SHA-256(RFC8785-JCS(authenticated_signer_evidence)) in the registered ak:signer_evidence form, and MUST equal the sibling signer_resolution_evidence_ref of the carrier object byte for byte. authenticated_signer_evidence is the compact six-member signer-resolution evidence and carries no closure of its own; the portable Agent Authority closure travels as agent-authority-evidence.schema.json#/$defs/agent_authority_state_evidence, never inside this root.
* signer_resolution_evidence_ref · string · $ref ./authenticated-signer-resolution-evidence.schema.json#/$defs/signer_evidence_ref
pattern: ^ak:signer_evidence:sha256:[0-9a-f]{64}$
* authenticated_signer_evidence · allOf[2] · $ref ./authenticated-signer-resolution-evidence.schema.json#/$defs/agent_signer_evidence
allOf · allOf[0] · $ref #/$defs/base · $ref #/$defs/base
allOf · allOf[1] · object
signer_kind · const "agent"
enum: "agent"
oneOf · oneOf[15] · object · $ref #/$defs/agent_pause_request_body
reason · string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/audit_reason_text
NFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern: ^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$
* lifecycle_event · allOf[2]
Closed ak.self.agent.pause Event authored in the Agent PCR and executed/signed by the authenticated controller delegation. The service submits these exact bytes through authority Event submission and never synthesizes an Agent-authored Event. Its optional payload.reason MUST equal the request reason exactly (both absent or the same string).
allOf · allOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · $ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input
* proof · $ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proof
allOf · allOf[1] · object
* event · object
* kind · const "ak.self.agent.pause"
enum: "ak.self.agent.pause"
oneOf · oneOf[16] · object · $ref #/$defs/agent_lifecycle_state
* status · string (enum) · $ref #/$defs/agent_status
Controller lifecycle intent axis. Closed enum; only the controller's pause / resume / deactivate lifecycle events change it. Pairing and key facts are reflected through the generic readiness axis and open-handle fields, never through a fourth generic state axis (key-management.md §3.6.1).
enum: "active" "paused" "deactivated"
oneOf · oneOf[17] · object · $ref #/$defs/agent_resume_request_body
* lifecycle_event · allOf[2]
Closed ak.self.agent.resume Event authored in the Agent PCR and executed/signed by the authenticated controller delegation. Sidecar desired membership is re-derived from accepted lifecycle and exact Realm membership after admission; the request carries no writable Sidecar roster or acknowledgement.
allOf · allOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · $ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input
* proof · $ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proof
allOf · allOf[1] · object
* event · object
* kind · const "ak.self.agent.resume"
enum: "ak.self.agent.resume"
oneOf · oneOf[18] · object · $ref #/$defs/agent_deactivate_request_body
reason · string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/audit_reason_text
NFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern: ^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$
* lifecycle_event · allOf[2]
The single controller-authorized terminal ak.self.agent.deactivate Event. Once accepted, lifecycle is an unavoidable AND gate that makes every subordinate runtime key, session, pairing handle, capability grant, KeyPackage, presence and future submission ineffective. Cleanup Events are not part of this request. Optional payload.reason MUST equal request reason.
allOf · allOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · $ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input
* proof · $ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proof
allOf · allOf[1] · object
* event · object
* kind · const "ak.self.agent.deactivate"
enum: "ak.self.agent.deactivate"
oneOf · oneOf[19] · oneOf[3] · $ref #/$defs/agent_sidecar_ensure_request_body
oneOf · oneOf[0] · object
* phase · const "prepare"
enum: "prepare"
* operation_id · $ref #/$defs/operation_id · $ref #/$defs/operation_id
* idempotency_key · $ref #/$defs/opaque_id · $ref #/$defs/opaque_id
* source_realm_id · $ref #/$defs/realm_id · $ref #/$defs/realm_id
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* station_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* context_ref · $ref #/$defs/sidecar_context_ref · $ref #/$defs/sidecar_context_ref
oneOf · oneOf[1] · object
* phase · const "commit"
enum: "commit"
* operation_id · $ref #/$defs/operation_id · $ref #/$defs/operation_id
* idempotency_key · $ref #/$defs/opaque_id · $ref #/$defs/opaque_id
* reservation_handle · $ref #/$defs/opaque_id · $ref #/$defs/opaque_id
* create_event · $ref #/$defs/sidecar_create_event · $ref #/$defs/sidecar_create_event
* context_attach_event · $ref #/$defs/sidecar_context_attach_event · $ref #/$defs/sidecar_context_attach_event
oneOf · oneOf[2] · object
* phase · const "attach"
enum: "attach"
* operation_id · $ref #/$defs/operation_id · $ref #/$defs/operation_id
* idempotency_key · $ref #/$defs/opaque_id · $ref #/$defs/opaque_id
* reservation_handle · $ref #/$defs/opaque_id · $ref #/$defs/opaque_id
* context_attach_event · $ref #/$defs/sidecar_context_attach_event · $ref #/$defs/sidecar_context_attach_event
oneOf · oneOf[20] · oneOf[3] · $ref #/$defs/agent_sidecar_ensure_outcome
oneOf · oneOf[0] · object
* status · const "prepared"
enum: "prepared"
* branch · const "new"
enum: "new"
* operation_id · $ref #/$defs/operation_id · $ref #/$defs/operation_id
* reservation_handle · $ref #/$defs/opaque_id · $ref #/$defs/opaque_id
* expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* create_event_draft · $ref #/$defs/prepared_event_draft · $ref #/$defs/prepared_event_draft
* context_attach_event_draft · $ref #/$defs/prepared_event_draft · $ref #/$defs/prepared_event_draft
oneOf · oneOf[1] · object
* status · const "prepared"
enum: "prepared"
* branch · const "existing"
enum: "existing"
* operation_id · $ref #/$defs/operation_id · $ref #/$defs/operation_id
* reservation_handle · $ref #/$defs/opaque_id · $ref #/$defs/opaque_id
* expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* context_attach_event_draft · $ref #/$defs/prepared_event_draft · $ref #/$defs/prepared_event_draft
oneOf · oneOf[2] · object
* status · const "accepted"
enum: "accepted"
* operation_id · $ref #/$defs/operation_id · $ref #/$defs/operation_id
* accepted_phase · string (enum)
enum: "commit" "attach"
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* source_context_ref · $ref #/$defs/sidecar_context_ref · $ref #/$defs/sidecar_context_ref
* access_readiness · string (enum) · $ref ./agent-operations.schema.json#/$defs/agent_sidecar_access_readiness
enum: "opening" "key_material_pending" "epoch_update_required" "ready" "failed"
* pending_access_reconciliations · array<$ref ./agent-operations.schema.json#/$defs/pending_sidecar_access_reconciliation_row>
items · object · $ref ./agent-operations.schema.json#/$defs/pending_sidecar_access_reconciliation_row
* agent_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* provisioning_phase · string (enum)
Closed reconciliation phase. Clients derive localized explanatory text from this phase; no parallel reason string is carried.
enum: "mls_welcome" "mls_remove" "epoch_rotation" "device_key_material"
oneOf · oneOf[21] · object · $ref #/$defs/agent_sidecar_view
* sidecar · object · $ref ./agent-sidecar.schema.json
Controller-account-owned private AI workspace bound one-to-one to (realm_id, controller_account_id). Agent Sidecar is a first-class native protocol scope, not a Circle profile, backing Circle, or editable membership container. See spec/v1/zh/models/sidecar.md.
allOf · allOf[0] · ?
* id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* schema · const "ak.schema.agent_sidecar.v1"
enum: "ak.schema.agent_sidecar.v1"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* station_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* state · string (enum)
enum: "active" "suspended" "tombstoned"
state_changed_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* created_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
updated_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* desired_agent_ids · array<$ref #/$defs/did_core_id>
Read-only projection derived at the Sidecar stream's committed head: active, runtime-key-authorized Agent principals owned by the Sidecar controller and also active members of sidecar.realm_id. It is not caller-authored or reducer-stored and cannot be edited through Sidecar operations.
items · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* effective_agent_ids · array<$ref #/$defs/did_core_id>
Desired Agent principals that are members of the current accepted Sidecar MLS epoch and have completed target-device Welcome/KeyPackage consumption and key readiness. Reducer/service MUST enforce this set is a subset of desired_agent_ids. The controller is represented by sidecar.controller_account_id and is not duplicated in either Agent array.
items · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* mls_context · object · $ref #/$defs/agent_sidecar_mls_context
* participant_authority_digest · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* authority_stream_head · array<$ref #/$defs/event_id>
UTF-8 byte-lexicographically sorted accepted Event IDs for Sidecar genesis, ownership, Agent lifecycle/runtime-key authorization, and exact Realm membership. It excludes action grants, participation selections, and MLS/key-readiness results. Same value and bound as the signed mls_governance_binding.authority_stream_head.
items · string · $ref #/$defs/event_id
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
mls_group_id · string · $ref ./common-ids.schema.json#/$defs/mls_group_id
RFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern: ^[A-Za-z0-9_-]{43}$
epoch · integer
genesis_event_ref · string · $ref #/$defs/non_empty_string
* current_controller_device_ready · boolean
True only when the authenticated controller session device is the accepted genesis creator device or has completed matching Welcome and KeyPackage consume evidence.
* access_readiness · string (enum) · $ref #/$defs/agent_sidecar_access_readiness
enum: "opening" "key_material_pending" "epoch_update_required" "ready" "failed"
* pending_access_reconciliations · array<$ref #/$defs/pending_sidecar_access_reconciliation_row>
items · object · $ref #/$defs/pending_sidecar_access_reconciliation_row
* agent_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* provisioning_phase · string (enum)
Closed reconciliation phase. Clients derive localized explanatory text from this phase; no parallel reason string is carried.
enum: "mls_welcome" "mls_remove" "epoch_rotation" "device_key_material"
oneOf · oneOf[22] · object · $ref #/$defs/agent_sidecar_list
* sidecars · array<$ref #/$defs/agent_sidecar_view>
items · object · $ref #/$defs/agent_sidecar_view
* sidecar · object · $ref ./agent-sidecar.schema.json
Controller-account-owned private AI workspace bound one-to-one to (realm_id, controller_account_id). Agent Sidecar is a first-class native protocol scope, not a Circle profile, backing Circle, or editable membership container. See spec/v1/zh/models/sidecar.md.
allOf · allOf[0] · ?
* id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* schema · const "ak.schema.agent_sidecar.v1"
enum: "ak.schema.agent_sidecar.v1"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* station_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* state · string (enum)
enum: "active" "suspended" "tombstoned"
state_changed_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* created_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
updated_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* desired_agent_ids · array<$ref #/$defs/did_core_id>
Read-only projection derived at the Sidecar stream's committed head: active, runtime-key-authorized Agent principals owned by the Sidecar controller and also active members of sidecar.realm_id. It is not caller-authored or reducer-stored and cannot be edited through Sidecar operations.
items · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* effective_agent_ids · array<$ref #/$defs/did_core_id>
Desired Agent principals that are members of the current accepted Sidecar MLS epoch and have completed target-device Welcome/KeyPackage consumption and key readiness. Reducer/service MUST enforce this set is a subset of desired_agent_ids. The controller is represented by sidecar.controller_account_id and is not duplicated in either Agent array.
items · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* mls_context · object · $ref #/$defs/agent_sidecar_mls_context
* participant_authority_digest · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* authority_stream_head · array<$ref #/$defs/event_id>
UTF-8 byte-lexicographically sorted accepted Event IDs for Sidecar genesis, ownership, Agent lifecycle/runtime-key authorization, and exact Realm membership. It excludes action grants, participation selections, and MLS/key-readiness results. Same value and bound as the signed mls_governance_binding.authority_stream_head.
items · string · $ref #/$defs/event_id
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
mls_group_id · string · $ref ./common-ids.schema.json#/$defs/mls_group_id
RFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern: ^[A-Za-z0-9_-]{43}$
epoch · integer
genesis_event_ref · string · $ref #/$defs/non_empty_string
* current_controller_device_ready · boolean
True only when the authenticated controller session device is the accepted genesis creator device or has completed matching Welcome and KeyPackage consume evidence.
* access_readiness · string (enum) · $ref #/$defs/agent_sidecar_access_readiness
enum: "opening" "key_material_pending" "epoch_update_required" "ready" "failed"
* pending_access_reconciliations · array<$ref #/$defs/pending_sidecar_access_reconciliation_row>
items · object · $ref #/$defs/pending_sidecar_access_reconciliation_row
* agent_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* provisioning_phase · string (enum)
Closed reconciliation phase. Clients derive localized explanatory text from this phase; no parallel reason string is carried.
enum: "mls_welcome" "mls_remove" "epoch_rotation" "device_key_material"
next_cursor · string · $ref #/$defs/non_empty_string

Source