Controller-authored payload that creates one Agent provisioning fact. One accepted reducer transaction atomically writes FOUR typed current results from it -- the provisioning fact, the accountability endorsement, the controller-scoped selector binding and the principal_control_realm_id claim -- and MUST NOT expose a partially completed state. zh/identity/key-management.md sections 3.6 and 3.6.3, zh/identity/account-lifecycle.md, zh/conformance/conformance-profiles.md and zh/extensions/applet-integration.md all enumerate the same four; this description used to name only two, which reads as a licence for the accountability/selector two-Event fan-out that conformance-profiles.md explicitly forbids. The containing Event proof is the only signature; this payload carries no nested proof.
allOf · allOf[0] · ?
* schema ·
const "ak.schema.agent_provision.v1"enum: "ak.schema.agent_provision.v1"
* agent_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* controller_principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* controller_authorization_ref ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* agent_slug ·
string (arkret-agent-slug) · format=arkret-agent-slug · $ref ./string-profiles.schema.json#/$defs/agent_slugCanonical controller-scoped Agent Agent selector slug. Maximum 64 Unicode code points in prepared form.
pattern: ^[^\s:@/#?\\]+$
* accountability_scope ·
const "agent_operator"Canonical closed accountability scope.
enum: "agent_operator"
* requested_scope_digest ·
string · $ref #/$defs/digestpattern: ^(sha256|blake3):[0-9a-f]{64}$
* selector_visibility ·
string (enum)enum: "public" "restricted" "private"
selector_audience · string
* created_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$