跳转到内容

ak.schema.applet_authority_material.v1

← Schemas

Arkret Applet Authority Material
ak.schema.applet_authority_material.v1 · file: schemas/applet-authority-material.schema.json
* $ · oneOf[2]
oneOf · oneOf[0] · object · $ref #/$defs/request
* effective_scope · oneOf[2] · $ref ./applet-install-plan.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
* grant_ids · array<$ref ./agent-operations.schema.json#/$defs/grant_id>
items · string · $ref ./agent-operations.schema.json#/$defs/grant_id
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object · $ref #/$defs/outcome
* applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* effective_scope · oneOf[2] · $ref ./applet-install-plan.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
* registration · object · $ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event
Exact producer-signed Event paired with its covering signed RealmCommit for Station-to-Applet delivery; withheld markers are forbidden. Device-determined producer_device_evidence carries the existing closed two-member account-device sibling; missing/surplus evidence is schema_violation before storing the pair. Later device revocation or evidence cache expiry does not invalidate accepted history.
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · null
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[2] · $ref #
oneOf · oneOf[0] · object · $ref #/$defs/request
* effective_scope · oneOf[2] · $ref ./applet-install-plan.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* circle_id · …
recursion truncated at depth 8; see source schema for full shape
* grant_ids · array<$ref ./agent-operations.schema.json#/$defs/grant_id>
items · string · $ref ./agent-operations.schema.json#/$defs/grant_id
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object · $ref #/$defs/outcome
* applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* effective_scope · oneOf[2] · $ref ./applet-install-plan.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* circle_id · …
recursion truncated at depth 8; see source schema for full shape
* registration · object · $ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event
Exact producer-signed Event paired with its covering signed RealmCommit for Station-to-Applet delivery; withheld markers are forbidden. Device-determined producer_device_evidence carries the existing closed two-member account-device sibling; missing/surplus evidence is schema_violation before storing the pair. Later device revocation or evidence cache expiry does not invalidate accepted history.
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* authority_ref · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · …
recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
producer_device_evidence · object · $ref ./account-device-signer-evidence.schema.json
Immutable account_device evidence for a human device producer. The origin Station persists this complete object before returning a keys/query row or before sending it as authority_forward producer_device_evidence, which it signs fresh for every forwarding attempt; the signer_evidence_ref is SHA-256(RFC 8785 JCS of this object). This sibling does not add a branch or member to AuthenticatedSignerResolutionEvidence. Conformance vector ak.vector.device.account_device_signer_evidence.v1 checks the exact closure and negative mutations.
* device_projection_attestation · …
recursion truncated at depth 8; see source schema for full shape
* service_resolution · …
recursion truncated at depth 8; see source schema for full shape
* grant_events · array<$ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event>
items · object · $ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event
Exact producer-signed Event paired with its covering signed RealmCommit for Station-to-Applet delivery; withheld markers are forbidden. Device-determined producer_device_evidence carries the existing closed two-member account-device sibling; missing/surplus evidence is schema_violation before storing the pair. Later device revocation or evidence cache expiry does not invalidate accepted history.
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event · …
recursion truncated at depth 8; see source schema for full shape
producer_device_evidence · …
recursion truncated at depth 8; see source schema for full shape
* current_results · array<$ref ./exact-current-results-read.schema.json#/$defs/exact_current_result_present>
items · object · $ref ./exact-current-results-read.schema.json#/$defs/exact_current_result_present
* status · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* effective_stream_head · …
recursion truncated at depth 8; see source schema for full shape
* entry · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.realm_commit_signature.v1"
enum: "ak.realm_commit_signature.v1"
* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · oneOf[2] · $ref #
oneOf · oneOf[0] · object · $ref #/$defs/request
* effective_scope · oneOf[2] · $ref ./applet-install-plan.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
* grant_ids · array<$ref ./agent-operations.schema.json#/$defs/grant_id>
items · string · $ref ./agent-operations.schema.json#/$defs/grant_id
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object · $ref #/$defs/outcome
* applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* effective_scope · oneOf[2] · $ref ./applet-install-plan.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
* registration · object · $ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event
Exact producer-signed Event paired with its covering signed RealmCommit for Station-to-Applet delivery; withheld markers are forbidden. Device-determined producer_device_evidence carries the existing closed two-member account-device sibling; missing/surplus evidence is schema_violation before storing the pair. Later device revocation or evidence cache expiry does not invalidate accepted history.
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · oneOf[2] · $ref #
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
producer_device_evidence · object · $ref ./account-device-signer-evidence.schema.json
Immutable account_device evidence for a human device producer. The origin Station persists this complete object before returning a keys/query row or before sending it as authority_forward producer_device_evidence, which it signs fresh for every forwarding attempt; the signer_evidence_ref is SHA-256(RFC 8785 JCS of this object). This sibling does not add a branch or member to AuthenticatedSignerResolutionEvidence. Conformance vector ak.vector.device.account_device_signer_evidence.v1 checks the exact closure and negative mutations.
* device_projection_attestation · object · $ref ./keys-operations.schema.json#/$defs/device_projection_attestation
Complete origin-Station-signed device projection attestation. The detached proof signs the ak.device_projection_attestation_proof.v1 transcript; proof.created_at MUST equal attestation.attested_at.
* attestation · …
recursion truncated at depth 8; see source schema for full shape
* proof · …
recursion truncated at depth 8; see source schema for full shape
* service_resolution · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id · …
recursion truncated at depth 8; see source schema for full shape
* service_kind · …
recursion truncated at depth 8; see source schema for full shape
* method_history_evidence · …
recursion truncated at depth 8; see source schema for full shape
* normalized_did_document · …
recursion truncated at depth 8; see source schema for full shape
* grant_events · array<$ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event>
items · object · $ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event
Exact producer-signed Event paired with its covering signed RealmCommit for Station-to-Applet delivery; withheld markers are forbidden. Device-determined producer_device_evidence carries the existing closed two-member account-device sibling; missing/surplus evidence is schema_violation before storing the pair. Later device revocation or evidence cache expiry does not invalidate accepted history.
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* authority_ref · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · …
recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
producer_device_evidence · object · $ref ./account-device-signer-evidence.schema.json
Immutable account_device evidence for a human device producer. The origin Station persists this complete object before returning a keys/query row or before sending it as authority_forward producer_device_evidence, which it signs fresh for every forwarding attempt; the signer_evidence_ref is SHA-256(RFC 8785 JCS of this object). This sibling does not add a branch or member to AuthenticatedSignerResolutionEvidence. Conformance vector ak.vector.device.account_device_signer_evidence.v1 checks the exact closure and negative mutations.
* device_projection_attestation · …
recursion truncated at depth 8; see source schema for full shape
* service_resolution · …
recursion truncated at depth 8; see source schema for full shape
* current_results · array<$ref ./exact-current-results-read.schema.json#/$defs/exact_current_result_present>
items · object · $ref ./exact-current-results-read.schema.json#/$defs/exact_current_result_present
* status · const "present"
enum: "present"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
* effective_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* entry · $ref #/$defs/exact_current_result_entry · $ref #/$defs/exact_current_result_entry
allOf · allOf[1] · object
* kind · string (enum)
enum: "ak.agent.action_approve" "ak.agent.interaction.set" "ak.agent.key.authorize" "ak.agent.key.revoke" "ak.agent.provision" "ak.agent.sidecar.exchange.control" "ak.applet.bridge_error" "ak.applet.discovery" "ak.applet.managed_actor.provision" "ak.applet.registration" "ak.audit.accessed" "ak.audit.erasure_receipt" "ak.call.create" "ak.call.recording.start" "ak.call.state" "ak.capability.grant" "ak.capability.relinquish" "ak.capability.revoke" "ak.circle.archive" "ak.circle.create" "ak.circle.history_access" "ak.circle.member.state" "ak.circle.restore" "ak.circle.tombstone" "ak.circle.update" "ak.consent.grant" "ak.consent.revoke" "ak.contact.accepted" "ak.contact.rejected" "ak.contact.requested" "ak.contact.scope.update" "ak.contact.tombstone" "ak.device.authorize" "ak.device.reanchor" "ak.device.revoke" "ak.direct_conversation.bound" "ak.identity.accountability_grant" "ak.identity.resolution.update" "ak.invite.accept" "ak.invite.cancel" "ak.invite.claim" "ak.invite.create" "ak.invite.revoke" "ak.invite.third_party" "ak.key_backup.active_series" "ak.member.identity.update" "ak.member.state" "ak.message.create" "ak.message.redact" "ak.message.revise" "ak.mimi.room_binding" "ak.mls.commit" "ak.mls.genesis" "ak.moderation.decision" "ak.moderation.decision.lift" "ak.moderation.franking_proof" "ak.morph.archive" "ak.morph.create" "ak.morph.restore" "ak.morph.stage.set" "ak.morph.update" "ak.organization.moderation_policy" "ak.pin.add" "ak.pin.remove" "ak.pin.reorder" "ak.policy.action" "ak.policy.set" "ak.profile.create" "ak.profile.realm_override" "ak.profile.update" "ak.reaction.add" "ak.reaction.remove" "ak.realm.alias" "ak.realm.archive" "ak.realm.asset_privacy_policy" "ak.realm.authority.reset" "ak.realm.create" "ak.realm.destroy" "ak.realm.discovery" "ak.realm.freeze" "ak.realm.governance_station.change" "ak.realm.history_access" "ak.realm.join_rule" "ak.realm.link" "ak.realm.media_service" "ak.realm.organization" "ak.realm.owner.transfer" "ak.realm.plaintext_visible_services" "ak.realm.policy_bundle" "ak.realm.preview_policy" "ak.realm.profile" "ak.realm.read_receipt_policy" "ak.realm.restore" "ak.realm.schema" "ak.realm.search_policy" "ak.realm.set_default_strand" "ak.realm.tombstone" "ak.realm.unfreeze" "ak.redaction" "ak.relation.create" "ak.relation.tombstone" "ak.relation.update" "ak.rsvp.set" "ak.schema.define" "ak.self.agent.deactivate" "ak.self.agent.pause" "ak.self.agent.resume" "ak.self.moderation.report" "ak.sidecar.context.attach" "ak.sidecar.create" "ak.space.archive" "ak.space.create" "ak.space.parent" "ak.space.restore" "ak.space.tombstone" "ak.space.update" "ak.strand.archive" "ak.strand.create" "ak.strand.move" "ak.strand.reorder" "ak.strand.restore" "ak.strand.stage.set" "ak.strand.tracks.update" "ak.strand.update" "ak.strand.watch.set" "ak.view.create" "ak.view.reconcile" "ak.view.update"
producer_device_evidence · object · $ref ./account-device-signer-evidence.schema.json
Immutable account_device evidence for a human device producer. The origin Station persists this complete object before returning a keys/query row or before sending it as authority_forward producer_device_evidence, which it signs fresh for every forwarding attempt; the signer_evidence_ref is SHA-256(RFC 8785 JCS of this object). This sibling does not add a branch or member to AuthenticatedSignerResolutionEvidence. Conformance vector ak.vector.device.account_device_signer_evidence.v1 checks the exact closure and negative mutations.
* device_projection_attestation · object · $ref ./keys-operations.schema.json#/$defs/device_projection_attestation
Complete origin-Station-signed device projection attestation. The detached proof signs the ak.device_projection_attestation_proof.v1 transcript; proof.created_at MUST equal attestation.attested_at.
* attestation · $ref #/$defs/device_projection_attestation_core · $ref #/$defs/device_projection_attestation_core
* proof · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
* service_resolution · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* service_kind · string
pattern: ^[a-z][a-z0-9_]{0,63}$
* method_history_evidence · $ref #/$defs/method_history_evidence · $ref #/$defs/method_history_evidence
* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did · $ref #/$defs/did · $ref #/$defs/did
* contexts · array<oneOf[2]>
items · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · object
* controller_dids · array<$ref #/$defs/did>
items · $ref #/$defs/did · $ref #/$defs/did
* also_known_as · array<string>
items · string
Canonical URI validated by the DID resolver before projection; this array may contain non-network schemes such as acct: and therefore is not a URL field.
pattern: ^[A-Za-z][A-Za-z0-9+.-]*:[^\s]+$
* verification_methods · array<$ref #/$defs/normalized_did_verification_method>
items · $ref #/$defs/normalized_did_verification_method · $ref #/$defs/normalized_did_verification_method
* authentication · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* assertion_methods · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* key_agreements · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* capability_invocations · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* capability_delegations · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* services · array<$ref #/$defs/normalized_did_service>
items · $ref #/$defs/normalized_did_service · $ref #/$defs/normalized_did_service
* metadata · $ref #/$defs/normalized_did_document_metadata · $ref #/$defs/normalized_did_document_metadata
* extensions · array<$ref #/$defs/normalized_did_document_extension>
items · $ref #/$defs/normalized_did_document_extension · $ref #/$defs/normalized_did_document_extension
* grant_events · array<$ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event>
items · object · $ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event
Exact producer-signed Event paired with its covering signed RealmCommit for Station-to-Applet delivery; withheld markers are forbidden. Device-determined producer_device_evidence carries the existing closed two-member account-device sibling; missing/surplus evidence is schema_violation before storing the pair. Later device revocation or evidence cache expiry does not invalidate accepted history.
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · null
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[2] · $ref #
oneOf · oneOf[0] · object · $ref #/$defs/request
* effective_scope · oneOf[2] · $ref ./applet-install-plan.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* grant_ids · array<$ref ./agent-operations.schema.json#/$defs/grant_id>
items · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/outcome
* applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* effective_scope · oneOf[2] · $ref ./applet-install-plan.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* registration · object · $ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event
Exact producer-signed Event paired with its covering signed RealmCommit for Station-to-Applet delivery; withheld markers are forbidden. Device-determined producer_device_evidence carries the existing closed two-member account-device sibling; missing/surplus evidence is schema_violation before storing the pair. Later device revocation or evidence cache expiry does not invalidate accepted history.
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event · …
recursion truncated at depth 8; see source schema for full shape
producer_device_evidence · …
recursion truncated at depth 8; see source schema for full shape
* grant_events · array<$ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event>
items · …
recursion truncated at depth 8; see source schema for full shape
* current_results · array<$ref ./exact-current-results-read.schema.json#/$defs/exact_current_result_present>
items · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.realm_commit_signature.v1"
enum: "ak.realm_commit_signature.v1"
* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · oneOf[2] · $ref #
oneOf · oneOf[0] · object · $ref #/$defs/request
* effective_scope · oneOf[2] · $ref ./applet-install-plan.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* circle_id · …
recursion truncated at depth 8; see source schema for full shape
* grant_ids · array<$ref ./agent-operations.schema.json#/$defs/grant_id>
items · string · $ref ./agent-operations.schema.json#/$defs/grant_id
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object · $ref #/$defs/outcome
* applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* effective_scope · oneOf[2] · $ref ./applet-install-plan.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* circle_id · …
recursion truncated at depth 8; see source schema for full shape
* registration · object · $ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event
Exact producer-signed Event paired with its covering signed RealmCommit for Station-to-Applet delivery; withheld markers are forbidden. Device-determined producer_device_evidence carries the existing closed two-member account-device sibling; missing/surplus evidence is schema_violation before storing the pair. Later device revocation or evidence cache expiry does not invalidate accepted history.
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* authority_ref · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · …
recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
producer_device_evidence · object · $ref ./account-device-signer-evidence.schema.json
Immutable account_device evidence for a human device producer. The origin Station persists this complete object before returning a keys/query row or before sending it as authority_forward producer_device_evidence, which it signs fresh for every forwarding attempt; the signer_evidence_ref is SHA-256(RFC 8785 JCS of this object). This sibling does not add a branch or member to AuthenticatedSignerResolutionEvidence. Conformance vector ak.vector.device.account_device_signer_evidence.v1 checks the exact closure and negative mutations.
* device_projection_attestation · …
recursion truncated at depth 8; see source schema for full shape
* service_resolution · …
recursion truncated at depth 8; see source schema for full shape
* grant_events · array<$ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event>
items · object · $ref ./applet-edge-operations.schema.json#/$defs/applet_committed_event
Exact producer-signed Event paired with its covering signed RealmCommit for Station-to-Applet delivery; withheld markers are forbidden. Device-determined producer_device_evidence carries the existing closed two-member account-device sibling; missing/surplus evidence is schema_violation before storing the pair. Later device revocation or evidence cache expiry does not invalidate accepted history.
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event · …
recursion truncated at depth 8; see source schema for full shape
producer_device_evidence · …
recursion truncated at depth 8; see source schema for full shape
* current_results · array<$ref ./exact-current-results-read.schema.json#/$defs/exact_current_result_present>
items · object · $ref ./exact-current-results-read.schema.json#/$defs/exact_current_result_present
* status · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* effective_stream_head · …
recursion truncated at depth 8; see source schema for full shape
* entry · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind · string (enum)
enum: "ak.agent.action_approve" "ak.agent.interaction.set" "ak.agent.key.authorize" "ak.agent.key.revoke" "ak.agent.provision" "ak.agent.sidecar.exchange.control" "ak.applet.bridge_error" "ak.applet.discovery" "ak.applet.managed_actor.provision" "ak.applet.registration" "ak.audit.accessed" "ak.audit.erasure_receipt" "ak.call.create" "ak.call.recording.start" "ak.call.state" "ak.capability.grant" "ak.capability.relinquish" "ak.capability.revoke" "ak.circle.archive" "ak.circle.create" "ak.circle.history_access" "ak.circle.member.state" "ak.circle.restore" "ak.circle.tombstone" "ak.circle.update" "ak.consent.grant" "ak.consent.revoke" "ak.contact.accepted" "ak.contact.rejected" "ak.contact.requested" "ak.contact.scope.update" "ak.contact.tombstone" "ak.device.authorize" "ak.device.reanchor" "ak.device.revoke" "ak.direct_conversation.bound" "ak.identity.accountability_grant" "ak.identity.resolution.update" "ak.invite.accept" "ak.invite.cancel" "ak.invite.claim" "ak.invite.create" "ak.invite.revoke" "ak.invite.third_party" "ak.key_backup.active_series" "ak.member.identity.update" "ak.member.state" "ak.message.create" "ak.message.redact" "ak.message.revise" "ak.mimi.room_binding" "ak.mls.commit" "ak.mls.genesis" "ak.moderation.decision" "ak.moderation.decision.lift" "ak.moderation.franking_proof" "ak.morph.archive" "ak.morph.create" "ak.morph.restore" "ak.morph.stage.set" "ak.morph.update" "ak.organization.moderation_policy" "ak.pin.add" "ak.pin.remove" "ak.pin.reorder" "ak.policy.action" "ak.policy.set" "ak.profile.create" "ak.profile.realm_override" "ak.profile.update" "ak.reaction.add" "ak.reaction.remove" "ak.realm.alias" "ak.realm.archive" "ak.realm.asset_privacy_policy" "ak.realm.authority.reset" "ak.realm.create" "ak.realm.destroy" "ak.realm.discovery" "ak.realm.freeze" "ak.realm.governance_station.change" "ak.realm.history_access" "ak.realm.join_rule" "ak.realm.link" "ak.realm.media_service" "ak.realm.organization" "ak.realm.owner.transfer" "ak.realm.plaintext_visible_services" "ak.realm.policy_bundle" "ak.realm.preview_policy" "ak.realm.profile" "ak.realm.read_receipt_policy" "ak.realm.restore" "ak.realm.schema" "ak.realm.search_policy" "ak.realm.set_default_strand" "ak.realm.tombstone" "ak.realm.unfreeze" "ak.redaction" "ak.relation.create" "ak.relation.tombstone" "ak.relation.update" "ak.rsvp.set" "ak.schema.define" "ak.self.agent.deactivate" "ak.self.agent.pause" "ak.self.agent.resume" "ak.self.moderation.report" "ak.sidecar.context.attach" "ak.sidecar.create" "ak.space.archive" "ak.space.create" "ak.space.parent" "ak.space.restore" "ak.space.tombstone" "ak.space.update" "ak.strand.archive" "ak.strand.create" "ak.strand.move" "ak.strand.reorder" "ak.strand.restore" "ak.strand.stage.set" "ak.strand.tracks.update" "ak.strand.update" "ak.strand.watch.set" "ak.view.create" "ak.view.reconcile" "ak.view.update"
producer_device_evidence · object · $ref ./account-device-signer-evidence.schema.json
Immutable account_device evidence for a human device producer. The origin Station persists this complete object before returning a keys/query row or before sending it as authority_forward producer_device_evidence, which it signs fresh for every forwarding attempt; the signer_evidence_ref is SHA-256(RFC 8785 JCS of this object). This sibling does not add a branch or member to AuthenticatedSignerResolutionEvidence. Conformance vector ak.vector.device.account_device_signer_evidence.v1 checks the exact closure and negative mutations.
* device_projection_attestation · object · $ref ./keys-operations.schema.json#/$defs/device_projection_attestation
Complete origin-Station-signed device projection attestation. The detached proof signs the ak.device_projection_attestation_proof.v1 transcript; proof.created_at MUST equal attestation.attested_at.
* attestation · $ref #/$defs/device_projection_attestation_core · $ref #/$defs/device_projection_attestation_core
* proof · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
* service_resolution · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* service_kind · string
pattern: ^[a-z][a-z0-9_]{0,63}$
* method_history_evidence · $ref #/$defs/method_history_evidence · $ref #/$defs/method_history_evidence
* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did · $ref #/$defs/did · $ref #/$defs/did
* contexts · array<oneOf[2]>
items · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* controller_dids · array<$ref #/$defs/did>
items · $ref #/$defs/did · $ref #/$defs/did
* also_known_as · array<string>
items · string
Canonical URI validated by the DID resolver before projection; this array may contain non-network schemes such as acct: and therefore is not a URL field.
pattern: ^[A-Za-z][A-Za-z0-9+.-]*:[^\s]+$
* verification_methods · array<$ref #/$defs/normalized_did_verification_method>
items · $ref #/$defs/normalized_did_verification_method · $ref #/$defs/normalized_did_verification_method
* authentication · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* assertion_methods · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* key_agreements · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* capability_invocations · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* capability_delegations · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* services · array<$ref #/$defs/normalized_did_service>
items · $ref #/$defs/normalized_did_service · $ref #/$defs/normalized_did_service
* metadata · $ref #/$defs/normalized_did_document_metadata · $ref #/$defs/normalized_did_document_metadata
* extensions · array<$ref #/$defs/normalized_did_document_extension>
items · $ref #/$defs/normalized_did_document_extension · $ref #/$defs/normalized_did_document_extension
* current_results · array<$ref ./exact-current-results-read.schema.json#/$defs/exact_current_result_present>
items · object · $ref ./exact-current-results-read.schema.json#/$defs/exact_current_result_present
* status · const "present"
enum: "present"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
* effective_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* entry · $ref #/$defs/exact_current_result_entry · $ref #/$defs/exact_current_result_entry

Source