ak.schema.applet_widget_declaration.v1
ak.schema.applet_widget_declaration.v1 · file: schemas/applet-widget-declaration.schema.json Closed declaration for an Applet UI widget origin, CSP, scoped token capability scope, and consent gate.
* $ · object
Closed declaration for an Applet UI widget origin, CSP, scoped token capability scope, and consent gate.
* schema ·
const "ak.schema.applet_widget_declaration.v1"enum:
"ak.schema.applet_widget_declaration.v1"* widget_origin · allOf[2]
Canonical HTTPS Web Origin only: lowercase scheme and host plus an optional valid non-default port. Userinfo, path (including a trailing slash), query, fragment, explicit :443, and out-of-range ports are forbidden.
allOf · allOf[0] ·
string (uri) · format=uri · $ref ./common-ids.schema.json#/$defs/web_originCanonical HTTP(S) Web Origin: lowercase scheme/host plus an optional valid non-default effective port. Userinfo, path (including a trailing slash), query, fragment, explicit :80 on HTTP, and explicit :443 on HTTPS are forbidden.
pattern:
^(?:http://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!80$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?|https://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!443$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?)$allOf · allOf[1] ·
?pattern:
^https://* csp ·
stringContent-Security-Policy that the host client MUST enforce for the widget document.
* token_scope · object
Maximum capability scope for the short-lived widget token.
* actions · array<string>
items ·
stringpattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$* resources · array<$ref ./resource-selector.schema.json>
items · object · $ref ./resource-selector.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?* kind ·
string (enum)enum:
"realm" "space" "circle" "strand" "message" "morph" "object" "relation" "view" "event" "actor" "schema" "policy" "invite" "notification" "read_cursor" "blob" "*"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$space_id ·
stringpattern:
^ak:space:[A-Za-z0-9_-]{44}$circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$object_kind ·
stringobject_ref ·
stringCanonical object reference. Acceptable typed-id kinds match the v1 resource selector kind enum (see resource-selector-grammar.md §3.1). Notably MUST NOT include 'actor_profile' (use the 'actor' selector with did pattern), nor non-canonical 'board' / 'list' / 'card' / 'subject' / 'room' kinds — board / list / swimlane / calendar bucket are Space objects and MUST use the 'space' kind together with the 'allowed_space_kinds' constraint to restrict which Space kinds the grant covers.
pattern:
^(?:ak:realm:[A-Za-z0-9_-]{44}|ak:(space|circle|strand|message|morph|relation|view|event|invite):[A-Za-z0-9_-]{44}|ak:(policy|blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})$strand_id ·
stringpattern:
^ak:strand:[A-Za-z0-9_-]{44}$message_id ·
stringpattern:
^ak:message:[A-Za-z0-9_-]{44}$morph_id ·
stringpattern:
^ak:morph:[A-Za-z0-9_-]{44}$morph_kind ·
stringrelation_kind ·
stringrelation_id ·
stringpattern:
^ak:relation:[A-Za-z0-9_-]{44}$view_id ·
stringpattern:
^ak:view:[A-Za-z0-9_-]{44}$event_id ·
stringpattern:
^ak:event:[A-Za-z0-9_-]{44}$actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idschema_ref ·
stringpolicy_id ·
stringpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$invite_id ·
stringpattern:
^ak:invite:[A-Za-z0-9_-]{44}$blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$match_scope ·
string (enum)Authorization selector breadth. exact matches only the named resource; realm_wide is valid only for the registered resource kinds with an explicit realm_id. Neither current navigation ancestry nor creation ancestry expands authorization. Hierarchy traversal belongs to queries, not grant matching. The normative algorithm is zh/authz/resource-selector-grammar.md section 6.
enum:
"exact" "realm_wide"realm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
items ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* expires_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$max_ttl_seconds ·
integer(^x_[a-z][a-z0-9_]{0,63}$) ·
any* consent_required ·
boolean(^x_[a-z][a-z0-9_]{0,63}$) ·
anySource
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/applet-widget-declaration.schema.json