ak.schema.agent_requested_scope_disclosure.v1
ak.schema.agent_requested_scope_disclosure.v1 · file: schemas/agent-requested-scope-disclosure.schema.json Controller-signed, verifier-bound private disclosure of an Agent's immutable requested_scope. This object is authorization evidence, not a grant. It MUST travel only over an authenticated confidential presentation/operation channel and MUST NOT be written to a public DID Document, durable Realm Event, public registry, pairing code, or notification. The verifier consumes request_id/challenge once, validates the short presentation window, verifies a current controller proof, recomputes the requested-scope commitment against the accepted-at Agent DID commitment, and then applies the Agent ceiling subset rules. After successful one-time admission, an implementation MAY retain the object only as encrypted verifier-private evidence keyed by the recomputed digest, verifier_id and audience.
* $ · object
const "ak.schema.agent_requested_scope_disclosure.v1""ak.schema.agent_requested_scope_disclosure.v1"string^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$string · $ref ./common-ids.schema.json#/$defs/did_core_id^ak:did_core:[a-z0-9]+:[^\s/?#]+$string · $ref ./common-ids.schema.json#/$defs/did_core_id^ak:did_core:[a-z0-9]+:[^\s/?#]+$* requested_scope · object · $ref ./event-payload.schema.json#/$defs/agent_key_scope
$ref #/$defs/string_list · $ref #/$defs/string_list* resources · array<object>
items · object
?????string (enum)"realm" "space" "circle" "strand" "message" "morph" "object" "relation" "view" "event" "actor" "schema" "policy" "invite" "notification" "read_cursor" "blob" "operation" "service"string · $ref ./common-ids.schema.json#/$defs/realm_id^ak:realm:[A-Za-z0-9_-]{44}$$ref #/$defs/object_ref · $ref #/$defs/object_ref$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringstring · $ref ./common-ids.schema.json#/$defs/did_core_id^ak:did_core:[a-z0-9]+:[^\s/?#]+$constraints · array<$ref ./grant-constraint.schema.json>
items · object · $ref ./grant-constraint.schema.json
???????????????string^(?!ak:)string (enum)"temporal" "field_access" "kind_restriction" "scope_limitation" "authority_control" "quota" "claim_based" "confidentiality"string (enum)"allow" "deny" "quarantine" "require_review"string (enum)"stateless" "grant_local" "realm_state" "external"string (enum)"claim" "approval" "accountability" "rate" "resource" "encryption" "visibility" "window" "edit_window" "redact_window" "session" "applet_authority"applies_to_actions · array<string>
string^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$string (date-time) · format=date-time · $ref #/$defs/timestamp^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$string (date-time) · format=date-time · $ref #/$defs/timestamp^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$recurrence · object
string (enum)"daily" "weekly" "monthly" "custom"days · array<string (enum)>
string (enum)"mon" "tue" "wed" "thu" "fri" "sat" "sun"string^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$string^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$stringstring^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$string^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$string^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$string^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$string^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$string^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$booleancondition · object
string (enum)"object_is_owned_by_actor" "actor_is_assignee" "actor_is_responsible" "actor_is_guardian" "actor_is_controller" "object_in_actor_container" "object_is_unencrypted" "object_is_encrypted" "always" "never"allowed_write_fields · array<string>
stringdenied_write_fields · array<string>
stringallowed_read_fields · array<string>
stringdenied_read_fields · array<string>
stringsensitive_fields · array<string>
stringstring (enum)"redact" "hash" "omit"allowed_object_kinds · array<string>
stringdenied_object_kinds · array<string>
stringallowed_morph_kinds · array<string>
stringdenied_morph_kinds · array<string>
stringallowed_space_kinds · array<string>
stringdenied_space_kinds · array<string>
stringallowed_facets · array<string (enum)>
string (enum)"container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"denied_facets · array<string (enum)>
string (enum)"container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"allowed_view_ids · array<string>
string^ak:view:[A-Za-z0-9_-]{44}$allowed_strand_ids · array<string>
string^ak:strand:[A-Za-z0-9_-]{44}$denied_strand_ids · array<string>
string^ak:strand:[A-Za-z0-9_-]{44}$allowed_space_ids · array<string>
string^ak:space:[A-Za-z0-9_-]{44}$denied_space_ids · array<string>
string^ak:space:[A-Za-z0-9_-]{44}$allowed_circle_ids · array<$ref ./common-ids.schema.json#/$defs/circle_id>
string · $ref ./common-ids.schema.json#/$defs/circle_id^ak:circle:[A-Za-z0-9_-]{44}$allowed_session_ids · array<string>
string^(?!ak:)allowed_view_kinds · array<string>
stringallowed_view_renderers · array<string>
stringdenied_view_kinds · array<string>
stringdenied_view_renderers · array<string>
stringallowed_relation_kinds · array<string>
stringallowed_from_container_refs · array<string>
string^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$allowed_to_container_refs · array<string>
string^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$booleanfalseallowed_tracks · array<string>
string^[a-z][a-z0-9_]{0,63}$denied_tracks · array<string>
string^[a-z][a-z0-9_]{0,63}$blob_presign_scope · object
* allowed_purposes · array<string (enum)>
string (enum)"media_inline" "thumbnail" "download"stringrealm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
string · $ref ./common-ids.schema.json#/$defs/realm_id^ak:realm:[A-Za-z0-9_-]{44}$allowed_data_labels · array<string>
string^[a-z][a-z0-9_]{0,63}$allowed_endpoints · array<string>
stringintegerauthority_path_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
string · $ref ./common-ids.schema.json#/$defs/did_core_id^ak:did_core:[a-z0-9]+:[^\s/?#]+$booleanstring (enum)"narrowing_only" "same_scope" "custom"string · $ref ./common-ids.schema.json#/$defs/applet_id^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
oneOf · oneOf[0] · object
const "account""account"$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
const "service""service"$ref #/$defs/did_core_id · $ref #/$defs/did_core_idstring^sha256:[0-9a-f]{64}$integerintegerintegerintegerintegerstring^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$integerstring (enum)"per_actor" "per_space" "per_realm" "global"integerstringbooleanstring (enum)"before_commit"approval_actor_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
string · $ref ./common-ids.schema.json#/$defs/did_core_id^ak:did_core:[a-z0-9]+:[^\s/?#]+$string (enum)"responsible" "controller" "guardian" "realm_admin" "custom"string^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$approval_threshold · oneOf[2]
"unanimous"string (enum)"majority" "unanimous"integerbooleanbooleanbooleanrequired_claims · array<object>
items · object
??stringstring · $ref ./common-ids.schema.json#/$defs/did_core_id^ak:did_core:[a-z0-9]+:[^\s/?#]+$trusted_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
string · $ref ./common-ids.schema.json#/$defs/did_core_id^ak:did_core:[a-z0-9]+:[^\s/?#]+$booleantrueobjectstring · $ref ./common-ids.schema.json#/$defs/did_core_id^ak:did_core:[a-z0-9]+:[^\s/?#]+$stringroles · array<string>
stringtrusted_claim_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
string · $ref ./common-ids.schema.json#/$defs/did_core_id^ak:did_core:[a-z0-9]+:[^\s/?#]+$booleanstring^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$allowed_history_access_values · array<string (enum)>
string (enum)"since_join" "all_history_for_current_members"booleanbooleanstring (enum)"none" "mls_rfc9420" "external"booleanbooleanstring^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$string^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$booleanapproved_key_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
string · $ref ./common-ids.schema.json#/$defs/did_core_id^ak:did_core:[a-z0-9]+:[^\s/?#]+$booleanallowed_managed_actor_roles · array<string (enum)>
string (enum)"bot" "ghost"anystring · $ref ./common-ids.schema.json#/$defs/did_core_id^ak:did_core:[a-z0-9]+:[^\s/?#]+$stringstringstring (date-time) · format=date-time · $ref #/$defs/timestamp^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$string (date-time) · format=date-time · $ref #/$defs/timestamp^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proofs · array<$ref ./event-envelope.schema.json#/$defs/proof>
items · object · $ref ./event-envelope.schema.json#/$defs/proof
string (enum)"detached_jws"string^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$$ref #/$defs/digest · $ref #/$defs/digeststring (date-time) · format=date-time · $ref #/$defs/timestamp^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$stringaudience · oneOf[2]
stringoneOf · oneOf[1] · array<string>
stringstring (enum)"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"string^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/agent-requested-scope-disclosure.schema.json