ak.schema.applet_install_plan.v1
ak.schema.applet_install_plan.v1 · file: schemas/applet-install-plan.schema.json Canonical plan returned by ak.self.applet.install.command.preview.v1 and recomputed by ak.self.applet.command.install.v1 before commit. plan_digest is calculated over the canonical InstallPlan object with plan_digest omitted.
* $ · object
Canonical plan returned by ak.self.applet.install.command.preview.v1 and recomputed by ak.self.applet.command.install.v1 before commit. plan_digest is calculated over the canonical InstallPlan object with plan_digest omitted.
* schema ·
const "ak.schema.applet_install_plan.v1"enum:
"ak.schema.applet_install_plan.v1"* plan_id ·
stringpattern:
^ak:plan:[A-Za-z0-9_-]+$* applet_id ·
string · $ref #/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* package_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* registration_epoch ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* effective_scope · oneOf[2] · $ref #/$defs/effective_scope
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$* requested_scopes · array<$ref #/$defs/non_empty_string>
items ·
string · $ref #/$defs/non_empty_string* approved_scopes · array<$ref #/$defs/scope_grant>
items · object · $ref #/$defs/scope_grant
* actions · array<$ref #/$defs/non_empty_string>
items ·
string · $ref #/$defs/non_empty_string* realm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
items ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$circle_ids · array<$ref ./common-ids.schema.json#/$defs/circle_id>
items ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$* constraints · array<object>
items ·
object* denied_scopes · array<$ref #/$defs/denied_scope>
items · object · $ref #/$defs/denied_scope
* requested_scope ·
string · $ref #/$defs/non_empty_string* reason_code ·
string · $ref #/$defs/non_empty_string* event_submissions · array<$ref #/$defs/event_submission>
items · object · $ref #/$defs/event_submission
* event_kind ·
stringpattern:
^ak\.[a-z0-9_]+(?:\.[a-z0-9_]+)+$* payload ·
objectsemantic_refs · array<$ref ./event-envelope.schema.json#/$defs/semantic_ref>
items · anyOf[2] · $ref ./event-envelope.schema.json#/$defs/semantic_ref
Closed business-reference union. authorized_by names a stable GrantId; all other roles name an immutable Event. Commit continuity is carried only by RealmCommit.previous_commit_ref.
anyOf · anyOf[0] · object
* id ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_ref* role ·
const "authorized_by"enum:
"authorized_by"* critical ·
booleananyOf · anyOf[1] · object
* id ·
string · $ref #/$defs/event_refpattern:
^ak:event:[A-Za-z0-9_-]{44}$* role ·
string (enum)enum:
"attestation" "parent_event" "after" "audit_pair" "recovery_capability" "accountability" "bootstrap_genesis" "disclosure_authorization" "capture_stop" "direct_conversation_binding" "direct_conversation_founding_unit" "direct_conversation_contact_round" "direct_conversation_agent_provision" "applet_managed_actor_provision"* critical ·
boolean* capability_constraints · array<$ref #/$defs/capability_constraint>
items · object · $ref #/$defs/capability_constraint
* constraint_kind ·
string · $ref #/$defs/non_empty_stringparams ·
object* namespace_conflicts · array<$ref #/$defs/namespace_conflict>
items · object · $ref #/$defs/namespace_conflict
* namespace ·
string · $ref #/$defs/non_empty_stringexisting_owner ·
string · $ref #/$defs/non_empty_string* resolution ·
string (enum)enum:
"deny" "require_admin_approval" "override"* e2ee_effect · object · $ref #/$defs/e2ee_effect
* mls_join_required ·
boolean* plaintext_access ·
string (enum)enum:
"none" "metadata_only" "policy_declared"authorization_refs · array<$ref #/$defs/event_ref>
items ·
string · $ref #/$defs/event_refpattern:
^ak:event:[A-Za-z0-9_-]{44}$* widget_effect · object · $ref #/$defs/widget_effect
* widget_allowed ·
booleanpolicy_event_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref #/$defs/event_refpattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* warnings · array<$ref #/$defs/non_empty_string>
items ·
string · $ref #/$defs/non_empty_string* plan_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/applet-install-plan.schema.json