ak.schema.applet_install_operations.v1
ak.schema.applet_install_operations.v1 · file: schemas/applet-install-operations.schema.json Closed request/response DTOs for ak.self.applet.install.command.preview.v1, ak.self.applet.command.install.v1, and ak.self.applet.command.revoke.v1. The InstallPlan body itself is defined in applet-install-plan.schema.json.
* $ · oneOf[11]
Closed request/response DTOs for ak.self.applet.install.command.preview.v1, ak.self.applet.command.install.v1, and ak.self.applet.command.revoke.v1. The InstallPlan body itself is defined in applet-install-plan.schema.json.
oneOf · oneOf[0] · object · $ref #/$defs/applet_install_preview_request_body
* applet_package ·
$ref ../schemas/applet-package.schema.json · $ref #/$defs/applet_package* authoring_request_basis · object · $ref ./applet-install-authoring.schema.json#/$defs/install_authoring_request_basis
Administrator-authored service installation intent. No Bot or Ghost is created by service installation.
* schema ·
const "ak.schema.applet_install_authoring_request_basis.v1"enum:
"ak.schema.applet_install_authoring_request_basis.v1"* purpose ·
const "install_applet"enum:
"install_applet"* target_station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* install_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* applet_id ·
string · $ref ./common-ids.schema.json#/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* package_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* effective_scope · oneOf[2] · $ref ./applet-install-plan.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$* approval_request ·
$ref #/$defs/approval_request · $ref #/$defs/approval_requestactor_policy ·
$ref #/$defs/actor_policy · $ref #/$defs/actor_policye2ee_policy ·
$ref #/$defs/e2ee_policy · $ref #/$defs/e2ee_policywidget_policy ·
$ref #/$defs/widget_policy · $ref #/$defs/widget_policy* registration_event ·
$ref #/$defs/registration_event · $ref #/$defs/registration_event* capability_grant_events · array<$ref #/$defs/capability_grant_event>
items ·
$ref #/$defs/capability_grant_event · $ref #/$defs/capability_grant_eventoneOf · oneOf[1] · object · $ref ./applet-install-authoring.schema.json#/$defs/install_preview_outcome
* plan · object · $ref ./applet-install-plan.schema.json
Canonical plan returned by ak.self.applet.install.command.preview.v1 and recomputed by ak.self.applet.command.install.v1 before commit. plan_digest is calculated over the canonical InstallPlan object with plan_digest omitted.
* schema ·
const "ak.schema.applet_install_plan.v1"enum:
"ak.schema.applet_install_plan.v1"* plan_id ·
stringpattern:
^ak:plan:[A-Za-z0-9_-]+$* applet_id ·
string · $ref #/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* package_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* registration_epoch ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* effective_scope ·
$ref ../schemas/applet-install-plan.schema.json#/$defs/effective_scope · $ref #/$defs/effective_scope* requested_scopes · array<$ref #/$defs/non_empty_string>
items ·
string · $ref #/$defs/non_empty_string* approved_scopes · array<$ref #/$defs/scope_grant>
items ·
$ref #/$defs/scope_grant · $ref #/$defs/scope_grant* denied_scopes · array<$ref #/$defs/denied_scope>
items ·
$ref #/$defs/denied_scope · $ref #/$defs/denied_scope* event_submissions · array<$ref #/$defs/event_submission>
items ·
$ref #/$defs/event_submission · $ref #/$defs/event_submission* capability_constraints · array<$ref #/$defs/capability_constraint>
items ·
$ref #/$defs/capability_constraint · $ref #/$defs/capability_constraint* namespace_conflicts · array<$ref #/$defs/namespace_conflict>
items ·
$ref #/$defs/namespace_conflict · $ref #/$defs/namespace_conflict* e2ee_effect ·
$ref #/$defs/e2ee_effect · $ref #/$defs/e2ee_effect* widget_effect ·
$ref #/$defs/widget_effect · $ref #/$defs/widget_effect* warnings · array<$ref #/$defs/non_empty_string>
items ·
string · $ref #/$defs/non_empty_string* plan_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[2] · object · $ref ./applet-install-authoring.schema.json#/$defs/author_request_body
* authoring_request ·
$ref #/$defs/authoring_request · $ref #/$defs/authoring_requestoneOf · oneOf[3] · object · $ref ./applet-install-authoring.schema.json#/$defs/author_outcome
* managed_actor_bundle ·
$ref #/$defs/managed_actor_bundle · $ref #/$defs/managed_actor_bundleoneOf · oneOf[4] ·
$ref ../schemas/applet-install-plan.schema.json · $ref ../schemas/applet-install-plan.schema.jsononeOf · oneOf[5] · object · $ref #/$defs/applet_install_request_body
* applet_package ·
$ref ../schemas/applet-package.schema.json · $ref #/$defs/applet_package* authoring_request_basis · object · $ref ./applet-install-authoring.schema.json#/$defs/install_authoring_request_basis
Administrator-authored service installation intent. No Bot or Ghost is created by service installation.
* schema ·
const "ak.schema.applet_install_authoring_request_basis.v1"enum:
"ak.schema.applet_install_authoring_request_basis.v1"* purpose ·
const "install_applet"enum:
"install_applet"* target_station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* install_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* applet_id ·
string · $ref ./common-ids.schema.json#/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* package_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* effective_scope · oneOf[2] · $ref ./applet-install-plan.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$* approval_request ·
$ref #/$defs/approval_request · $ref #/$defs/approval_requestactor_policy ·
$ref #/$defs/actor_policy · $ref #/$defs/actor_policye2ee_policy ·
$ref #/$defs/e2ee_policy · $ref #/$defs/e2ee_policywidget_policy ·
$ref #/$defs/widget_policy · $ref #/$defs/widget_policy* registration_event ·
$ref #/$defs/registration_event · $ref #/$defs/registration_event* capability_grant_events · array<$ref #/$defs/capability_grant_event>
items ·
$ref #/$defs/capability_grant_event · $ref #/$defs/capability_grant_event* plan_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[6] · object · $ref #/$defs/applet_install_outcome
* install_id · allOf[2]
allOf · allOf[0] ·
string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)* applet_id ·
string · $ref #/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* registration_event_ref ·
string · $ref #/$defs/event_refpattern:
^ak:event:[A-Za-z0-9_-]{44}$* registration_epoch ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* capability_grant_refs · array<$ref #/$defs/grant_id>
items ·
string · $ref #/$defs/grant_idpattern:
^ak:grant:[A-Za-z0-9_-]{44}$* e2ee_authorization_refs · array<$ref #/$defs/event_ref>
items ·
string · $ref #/$defs/event_refpattern:
^ak:event:[A-Za-z0-9_-]{44}$* widget_policy_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref #/$defs/event_refpattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* effective_status ·
string (enum)enum:
"installed" "partially_installed"* rejections · array<$ref #/$defs/rejected_scope_row>
items · object · $ref #/$defs/rejected_scope_row
requested_scope ·
string · $ref #/$defs/non_empty_string* reason_code ·
string · $ref #/$defs/non_empty_stringoneOf · oneOf[7] · object · $ref #/$defs/applet_revoke_preview_request_body
* effective_scope ·
$ref ../schemas/applet-install-plan.schema.json#/$defs/effective_scope · $ref #/$defs/effective_scope* reason_code ·
string · $ref #/$defs/non_empty_string* revoke_mode ·
string (enum)enum:
"revoke_all" "revoke_runtime_only" "revoke_widget_only"oneOf · oneOf[8] · object · $ref #/$defs/applet_revoke_preview_outcome
* revoke_plan · object · $ref #/$defs/applet_revoke_plan
Canonical exact revoke plan. The preview carries no revoke_plan_digest: the caller computes SHA-256 over RFC 8785 JCS of this plan and submits that value as applet_revoke_request_body.revoke_plan_digest.
* applet_id ·
string · $ref #/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* effective_scope ·
$ref ../schemas/applet-install-plan.schema.json#/$defs/effective_scope · $ref #/$defs/effective_scope* registration_epoch ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* reason_code ·
string · $ref #/$defs/non_empty_string* revoke_mode ·
string (enum)enum:
"revoke_all" "revoke_runtime_only" "revoke_widget_only"* capability_revocations · array<$ref #/$defs/applet_capability_revoke_intent>
items · object · $ref #/$defs/applet_capability_revoke_intent
* event_kind ·
const "ak.capability.revoke"enum:
"ak.capability.revoke"* grant_id ·
string · $ref #/$defs/grant_idpattern:
^ak:grant:[A-Za-z0-9_-]{44}$* expected_revision · object · $ref ./typed-current-result.schema.json#/$defs/revision
Exact revision of the same active capability_grant current result returned by the governing Station in this preview plan. It is covered by the canonical plan digest and MUST be copied byte-for-byte into the caller-signed ak.capability.revoke payload.
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* registration_epoch ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* reason_code ·
string · $ref #/$defs/non_empty_string* membership_removals · array<$ref #/$defs/applet_membership_remove_intent>
items · object · $ref #/$defs/applet_membership_remove_intent
* event_kind ·
const "ak.member.state"enum:
"ak.member.state"* member_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* membership ·
const "leave"enum:
"leave"* reason_code ·
string · $ref #/$defs/non_empty_string* widget_token_refs · array<$ref #/$defs/typed_ref>
items ·
string · $ref #/$defs/typed_refpattern:
^ak:[a-z][a-z0-9_]*:[A-Za-z0-9._:-]+$oneOf · oneOf[9] · object · $ref #/$defs/applet_revoke_request_body
* revoke_plan_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* effective_scope ·
$ref ../schemas/applet-install-plan.schema.json#/$defs/effective_scope · $ref #/$defs/effective_scope* reason_code ·
string · $ref #/$defs/non_empty_string* revoke_mode ·
string (enum)enum:
"revoke_all" "revoke_runtime_only" "revoke_widget_only"* capability_revoke_events · array<allOf[2]>
Exactly one caller-signed ak.capability.revoke initial submission for every active grant in the recomputed plan.
items · allOf[2]
allOf · allOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idexecuted_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idauthorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
string · $ref #/$defs/event_refpattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
string · $ref #/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input ·
$ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input* proof ·
$ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proofallOf · allOf[1] · object
event · allOf[2]
allOf · allOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventSubmitEnvelope
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
string · $ref #/$defs/event_refpattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
string · $ref #/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.capability.revoke"enum:
"ak.capability.revoke"* membership_state_events · array<allOf[2]>
Caller-signed membership removals in the plan, or an empty array when the install owns no managed membership.
items · allOf[2]
allOf · allOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idexecuted_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idauthorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
string · $ref #/$defs/event_refpattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
string · $ref #/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input ·
$ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input* proof ·
$ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proofallOf · allOf[1] · object
event · allOf[2]
allOf · allOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventSubmitEnvelope
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
string · $ref #/$defs/event_refpattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
string · $ref #/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.member.state"enum:
"ak.member.state"oneOf · oneOf[10] · object · $ref #/$defs/applet_revoke_outcome
* operation_id ·
stringpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* revoke_plan_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* status ·
string (enum)enum:
"complete" "in_progress" "partially_completed"* steps · array<$ref #/$defs/applet_revoke_step>
items · oneOf[3] · $ref #/$defs/applet_revoke_step
Closed state-dependent saga step. Event steps use the immutable submitted EventId before acceptance and the exact CommittedEventRef only after acceptance or duplicate resolution. Local effects always use a non-Event typed resource reference.
oneOf · oneOf[0] · object · $ref #/$defs/applet_revoke_submitted_event_step
* effect_kind ·
string (enum) · $ref #/$defs/applet_revoke_event_effect_kindenum:
"capability_revoke_event" "membership_state_event"* submitted_event_id ·
string · $ref #/$defs/event_refpattern:
^ak:event:[A-Za-z0-9_-]{44}$* status ·
string (enum)enum:
"pending" "rejected"reason_code ·
string · $ref #/$defs/non_empty_stringoneOf · oneOf[1] · object · $ref #/$defs/applet_revoke_committed_event_step
* effect_kind ·
string (enum) · $ref #/$defs/applet_revoke_event_effect_kindenum:
"capability_revoke_event" "membership_state_event"* committed_event_ref · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* stream_position ·
integer* status ·
string (enum)enum:
"accepted" "duplicate"reason_code ·
string · $ref #/$defs/non_empty_stringoneOf · oneOf[2] · object · $ref #/$defs/applet_revoke_local_effect_step
* effect_kind ·
string (enum)enum:
"widget_token_invalidation" "local_applet_fence"* effect_ref ·
string · $ref #/$defs/applet_revoke_local_effect_refTyped service-local revoke effect reference. EventId and RealmCommitId are forbidden because only Event admission can produce a committed Event coordinate.
pattern:
^ak:(?!event:|realm_commit:)[a-z][a-z0-9_]*:[A-Za-z0-9._~:/-]+$* status ·
string (enum)enum:
"pending" "accepted" "duplicate" "rejected"reason_code ·
string · $ref #/$defs/non_empty_stringrevoked_refs · array<$ref #/$defs/applet_revoke_effect_ref>
items · oneOf[2] · $ref #/$defs/applet_revoke_effect_ref
CommittedEventRef for a durable revoke Event, or a local typed resource reference for service-local widget token or fence effects. Bare EventId and RealmCommitId strings are not valid effect references.
oneOf · oneOf[0] · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* stream_position ·
integeroneOf · oneOf[1] ·
string · $ref #/$defs/applet_revoke_local_effect_refTyped service-local revoke effect reference. EventId and RealmCommitId are forbidden because only Event admission can produce a committed Event coordinate.
pattern:
^ak:(?!event:|realm_commit:)[a-z][a-z0-9_]*:[A-Za-z0-9._~:/-]+$rejections · array<$ref #/$defs/rejected_scope_row>
items · object · $ref #/$defs/rejected_scope_row
requested_scope ·
string · $ref #/$defs/non_empty_string* reason_code ·
string · $ref #/$defs/non_empty_stringSource
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/applet-install-operations.schema.json