ak.schema.applet_managed_actor_provision.v1
ak.schema.applet_managed_actor_provision.v1 · file: schemas/applet-managed-actor.schema.json * $ · object · $ref #/$defs/applet_managed_actor_provision_payload
Immutable service-authored authority for one Applet-managed Bot or Ghost principal. It precedes and is cross-bound to the principal's applet_managed_control PCR genesis; it is not the actor's mutable resolution head.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* schema ·
const "ak.schema.applet_managed_actor_provision.v1"enum:
"ak.schema.applet_managed_actor_provision.v1"* applet_id ·
string · $ref ./common-ids.schema.json#/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* actor_id · allOf[2]
allOf · allOf[0] · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idallOf · allOf[1] · object
kind ·
const "account"enum:
"account"* actor_role ·
string (enum)enum:
"bot" "ghost"* initial_resolution · object · $ref ./identity-resolution.schema.json#/$defs/resolution_commitment
Owner-committed current did and method-native history position. For a deterministic method, method_history_head and version_id use the adapter-defined deterministic canonical values; they are never omitted.
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* method_history_evidence · object · $ref ./identity-resolution.schema.json#/$defs/webvh_method_history_evidence
Complete did:webvh log, proof and witness material routed by evidence_kind webvh_log to the active did:webvh adapter. log_entries is the gap-free native history from inception through boundary.to_version_id, not a resolver summary or a partial segment. witness_records is the complete did-witness.json record set required by every witness policy active in that interval and is empty only when no entry activates a witness policy. The receiver independently verifies SCID derivation, every versionId/hash-chain link, every controller proof, rotation authorization, all applicable witness thresholds, the exact boundary endpoints and canonical equality of the terminal state with normalized_did_document. Canonical encoded evidence MUST NOT exceed 1 MiB; an over-limit service history is ineligible for retained historical-signer and governance-Station bootstrap and fails closed rather than returning partial evidence.
* evidence_kind ·
const "webvh_log"enum:
"webvh_log"* boundary ·
$ref #/$defs/method_evidence_boundary · $ref #/$defs/method_evidence_boundary* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
const "ak.did.binding_evidence.v1"enum:
"ak.did.binding_evidence.v1"* method ·
$ref #/$defs/method_token · $ref #/$defs/method_token* document_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of the resolver's verified normalized DID Document projection (did-usage-and-verification.md section 5.1); never the raw response bytes (those use the differently named raw_document_digest).
* method_proofs · array<$ref #/$defs/webvh_log_evidence>
Closed per-method proof rows; empty for proofless methods (did:key, bare did:web). v1 registers exactly one row kind (webvh_log); receiving any unregistered proof kind fails closed. Rows never reuse resolver response order: each row kind registers its own canonical sort and duplicate-rejection rules.
items ·
$ref #/$defs/webvh_log_evidence · $ref #/$defs/webvh_log_evidence* log_entries · array<object>
Exact ordered native did:webvh entry objects from inception through the selected terminal entry. The adapter applies the registered did:webvh parameter-name and proof rules and rejects gaps, duplicates, surplus entries after boundary.to_version_id, or a first entry other than inception.
items ·
object* witness_records · array<object>
Exact native did-witness.json record objects needed by log_entries. Records are keyed uniquely by versionId; missing, duplicate, invalid or surplus records fail closed. The array is empty exactly when the verified log activates no witness policy.
items ·
object* registration_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* applet_authority_ref ·
string · $ref ./agent-operations.schema.json#/$defs/grant_idpattern:
^ak:grant:[A-Za-z0-9_-]{44}$external_ref · object · $ref #/$defs/ghost_external_tuple
* protocol ·
stringpattern:
^[a-z][a-z0-9_.-]{0,63}$* instance_id · allOf[2]
allOf · allOf[0] ·
string · $ref ./account-operations.schema.json#/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)* external_id · allOf[2]
allOf · allOf[0] ·
string · $ref ./account-operations.schema.json#/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/applet-managed-actor.schema.json