ak.schema.applet_package.v1
ak.schema.applet_package.v1 · file: schemas/applet-package.schema.json Controller-signed package used to install an Applet. The package is a distribution object, not Realm history truth and not a grant. The Station authorization capability derives ak.applet.registration and capability grants during ak.applet.install.
* $ · object
Controller-signed package used to install an Applet. The package is a distribution object, not Realm history truth and not a grant. The Station authorization capability derives ak.applet.registration and capability grants during ak.applet.install.
* schema ·
const "ak.schema.applet_package.v1"enum:
"ak.schema.applet_package.v1"* package_id ·
stringDistribution identifier only. Not a grant subject.
pattern:
^(?!ak:)* applet_id ·
string · $ref #/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* controller_principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* base_url ·
string (uri) · format=uripattern:
^https://* claimed_profiles · array<$ref #/$defs/profile_id>
items ·
string · $ref #/$defs/profile_idpattern:
^ak\.profile\.[a-z0-9_.-]+\.v1$* protocols · array<$ref #/$defs/non_empty_string> · $ref #/$defs/non_empty_string_array
items ·
string · $ref #/$defs/non_empty_string* namespaces · object · $ref #/$defs/applet_namespaces
* actors · array<$ref #/$defs/actor_namespace_entry>
items · object · $ref #/$defs/actor_namespace_entry
* exclusive ·
boolean* pattern ·
string · $ref #/$defs/actor_namespace_patternActor namespace DID pattern. Segments are separated by ':' and '*' matches exactly one segment. The did:webvh SCID lives in the third segment and every Ghost MUST carry its own validated SCID, so a pattern that covers Ghosts wildcards that position; pinning the registration's own service SCID there can never match a compliant Ghost and MUST be rejected with applet_namespace_pattern_invalid. The host segment right after the SCID MUST be a literal (never '*') and MUST equal the host segment of the bare did that the registration service_id currently resolves to, and at least one further segment MUST follow it so a Ghost DID is never the service DID with a different SCID. Matching a pattern is a routing and exclusivity verdict only; it is never proof of ownership or authorization. See zh/extensions/applet-schema.md 2 and 2.1 and zh/extensions/applet-integration.md 3.4 and 5.
pattern:
^did:webvh:(?:\*|[A-Za-z0-9]+):[A-Za-z0-9](?:[A-Za-z0-9.%-]*[A-Za-z0-9])?(?::[^:]+)+$* realms · array<$ref #/$defs/namespace_entry>
items · object · $ref #/$defs/namespace_entry
* exclusive ·
boolean* pattern ·
string · $ref #/$defs/non_empty_string* handles · array<$ref #/$defs/namespace_entry>
items · object · $ref #/$defs/namespace_entry
* exclusive ·
boolean* pattern ·
string · $ref #/$defs/non_empty_string* requested_scopes · array<$ref #/$defs/non_empty_string> · $ref #/$defs/non_empty_string_array
items ·
string · $ref #/$defs/non_empty_string* endpoint_policy · object · $ref #/$defs/endpoint_policy
Supported Applet API endpoints and their auth requirement.
* endpoints · array<$ref #/$defs/endpoint_entry>
items · object · $ref #/$defs/endpoint_entry
* method ·
string (enum)enum:
"GET" "POST" "PUT" "PATCH" "DELETE"* path ·
string · $ref #/$defs/non_empty_stringauth ·
string (enum)enum:
"none" "webhook_signature" "bearer" "mtls"description ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/short_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$(^x_[a-z][a-z0-9_]{0,63}$) ·
any(^x_[a-z][a-z0-9_]{0,63}$) ·
any* webhook_auth · object · $ref #/$defs/webhook_auth
HTTP message signature verification policy for transaction push. key_ref is the Applet service DID URL used to verify the app/bridge->arkret inbound HTTP message signature. Verifiers MUST take its bare controller did, validate it with the registered method adapter, and require project(did) to equal service_id (did_core_id); direct DID/core-id string comparison is forbidden. The key is bound to the effective registration_epoch. accepted_signature_algorithms pins the acceptable RFC 9421 signature algorithms.
* key_ref ·
string · $ref #/$defs/did_urlDID URL under an Applet service did whose registered adapter projection equals service_id. For app/bridge->arkret inbound transaction push, Signature-Input keyid MUST equal this value. Node->Applet pushes verify the Arkret source service did/key binding selected by the Source-Service-ID did_core_id, not this field.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* accepted_signature_algorithms · array<$ref #/$defs/http_message_signature_algorithm>
items ·
string (enum) · $ref #/$defs/http_message_signature_algorithmenum:
"ed25519" "ecdsa-p256-sha256"signature_header ·
string · $ref #/$defs/non_empty_string* kind ·
string (enum)enum:
"http_message_signature"(^x_[a-z][a-z0-9_]{0,63}$) ·
any* receive_events ·
boolean* receive_signals ·
boolean* rate_limited ·
boolean* limits · object · $ref #/$defs/limits
Service-side resource hints derived into the registration manifest.
max_transaction_events ·
integermax_payload_bytes ·
integerrate_limit_per_minute ·
integer(^x_[a-z][a-z0-9_]{0,63}$) ·
any* ghost_policy · object · $ref #/$defs/ghost_policy
Ghost Actor support and accountability template. enabled defaults to false semantics; an explicit boolean is required.
* enabled ·
booleanaccountability_template ·
string · $ref #/$defs/non_empty_string(^x_[a-z][a-z0-9_]{0,63}$) ·
any* delegation_policy · object · $ref #/$defs/delegation_policy
Delegated native-user acting request. Defaults to false; enabled MUST be explicit.
* enabled ·
boolean(^x_[a-z][a-z0-9_]{0,63}$) ·
any* e2ee_policy · object · $ref #/$defs/e2ee_policy
MLS join request. Defaults to false; enabled MUST be explicit.
* enabled ·
booleanmls_join_requested ·
boolean(^x_[a-z][a-z0-9_]{0,63}$) ·
anywidget · object · $ref #/$defs/widget
Closed declaration for an Applet UI widget origin, CSP, scoped token capability scope, and consent gate.
* schema ·
const "ak.schema.applet_widget_declaration.v1"enum:
"ak.schema.applet_widget_declaration.v1"* widget_origin · allOf[2]
Canonical HTTPS Web Origin only: lowercase scheme and host plus an optional valid non-default port. Userinfo, path (including a trailing slash), query, fragment, explicit :443, and out-of-range ports are forbidden.
allOf · allOf[0] ·
string (uri) · format=uri · $ref ./common-ids.schema.json#/$defs/web_originCanonical HTTP(S) Web Origin: lowercase scheme/host plus an optional valid non-default effective port. Userinfo, path (including a trailing slash), query, fragment, explicit :80 on HTTP, and explicit :443 on HTTPS are forbidden.
pattern:
^(?:http://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!80$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?|https://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!443$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?)$allOf · allOf[1] ·
?pattern:
^https://* csp ·
stringContent-Security-Policy that the host client MUST enforce for the widget document.
* token_scope · object
Maximum capability scope for the short-lived widget token.
* actions · array<string>
items ·
stringpattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$* resources · array<$ref ./resource-selector.schema.json>
items · object · $ref ./resource-selector.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?* kind ·
string (enum)enum:
"realm" "space" "circle" "strand" "message" "morph" "object" "relation" "view" "event" "actor" "schema" "policy" "invite" "notification" "read_cursor" "blob" "*"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$space_id ·
stringpattern:
^ak:space:[A-Za-z0-9_-]{44}$circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$object_kind ·
stringobject_ref ·
stringCanonical object reference. Acceptable typed-id kinds match the v1 resource selector kind enum (see resource-selector-grammar.md §3.1). Notably MUST NOT include 'actor_profile' (use the 'actor' selector with did pattern), nor non-canonical 'board' / 'list' / 'card' / 'subject' / 'room' kinds — board / list / swimlane / calendar bucket are Space objects and MUST use the 'space' kind together with the 'allowed_space_kinds' constraint to restrict which Space kinds the grant covers.
pattern:
^(?:ak:realm:[A-Za-z0-9_-]{44}|ak:(space|circle|strand|message|morph|relation|view|event|invite):[A-Za-z0-9_-]{44}|ak:(policy|blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})$strand_id ·
stringpattern:
^ak:strand:[A-Za-z0-9_-]{44}$message_id ·
stringpattern:
^ak:message:[A-Za-z0-9_-]{44}$morph_id ·
stringpattern:
^ak:morph:[A-Za-z0-9_-]{44}$morph_kind ·
stringrelation_kind ·
stringrelation_id ·
stringpattern:
^ak:relation:[A-Za-z0-9_-]{44}$view_id ·
stringpattern:
^ak:view:[A-Za-z0-9_-]{44}$event_id ·
stringpattern:
^ak:event:[A-Za-z0-9_-]{44}$actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idschema_ref ·
stringpolicy_id ·
stringpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$invite_id ·
stringpattern:
^ak:invite:[A-Za-z0-9_-]{44}$blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$match_scope ·
string (enum)Authorization selector breadth. exact matches only the named resource; realm_wide is valid only for the registered resource kinds with an explicit realm_id. Neither current navigation ancestry nor creation ancestry expands authorization. Hierarchy traversal belongs to queries, not grant matching. The normative algorithm is zh/authz/resource-selector-grammar.md section 6.
enum:
"exact" "realm_wide"realm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
items ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* expires_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$max_ttl_seconds ·
integer(^x_[a-z][a-z0-9_]{0,63}$) ·
any* consent_required ·
boolean(^x_[a-z][a-z0-9_]{0,63}$) ·
any* package_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* registration_epoch ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref #/$defs/detached_proof
Controller-DID detached-JWS proof shape, aligned with event-envelope.schema.json#/$defs/proof (the generic non-Event signed-object proof). Non-Event objects bind their canonical payload via payload_digest; Event proofs MUST instead use event_digest and event_proof.
* kind ·
string (enum)enum:
"detached_jws"* verification_method ·
string · $ref #/$defs/did_urlpattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
string* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$(^x_[a-z][a-z0-9_]{0,63}$) ·
anySource
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/applet-package.schema.json