ak.schema.authority_commit_operations.v1
ak.schema.authority_commit_operations.v1 · file: schemas/authority-commit-operations.schema.json * $ · oneOf[7]
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idexecuted_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idauthorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input ·
$ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input* proof ·
$ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proofoneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idexecuted_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idauthorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
kind ·
const "ak.mls.commit"enum:
"ak.mls.commit"* welcomes · array<$ref ./mls-welcome-delivery.schema.json>
items · object · $ref ./mls-welcome-delivery.schema.json
Producer-signed recipient delivery queued atomically with its winning MLS Commit. This is not a shared Realm Event and does not receive an independent RealmCommit.
* welcome_id ·
string · $ref ./common-ids.schema.json#/$defs/mls_welcome_delivery_idpattern:
^ak:mls_welcome_delivery:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* effective_scope · oneOf[4] · $ref ./event-envelope.schema.json#/$defs/scope_ref
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind ·
const "realm_genesis"enum:
"realm_genesis"* commit_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* recipient_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* recipient_endpoint · oneOf[2]
oneOf · oneOf[0] · object
* kind ·
const "device"enum:
"device"* device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$oneOf · oneOf[1] · object
* kind ·
const "agent_runtime"enum:
"agent_runtime"* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* keypackage_claim_ref ·
stringpattern:
^ak:keypackage_claim:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* ciphertext_b64 ·
stringpattern:
^[A-Za-z0-9_-]+$* producer_proof · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/mls_welcome_delivery_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event ·
…recursion truncated at depth 8; see source schema for full shape
approval_signatures ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event ·
…recursion truncated at depth 8; see source schema for full shape
* welcomes ·
…recursion truncated at depth 8; see source schema for full shape
* idempotency_key ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status ·
…recursion truncated at depth 8; see source schema for full shape
* commit ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status ·
…recursion truncated at depth 8; see source schema for full shape
* reason_code ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
before_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* limit ·
integeroneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
…recursion truncated at depth 8; see source schema for full shape
* floor_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* floor_reason ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
…recursion truncated at depth 8; see source schema for full shape
* floor_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* floor_reason ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* nonce ·
stringpattern:
^[A-Za-z0-9_-]{43}$oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] ·
?* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* visible_stream_heads ·
…recursion truncated at depth 8; see source schema for full shape
* current_state_entries ·
…recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* genesis_event ·
…recursion truncated at depth 8; see source schema for full shape
* genesis_commit ·
…recursion truncated at depth 8; see source schema for full shape
* authority_transitions ·
…recursion truncated at depth 8; see source schema for full shape
* current_generation ·
…recursion truncated at depth 8; see source schema for full shape
* current_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* current_route_record ·
…recursion truncated at depth 8; see source schema for full shape
* realm_stream_head ·
…recursion truncated at depth 8; see source schema for full shape
* bundle_issued_at ·
…recursion truncated at depth 8; see source schema for full shape
* current_assertion ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.mls_welcome_delivery_signature.v1"enum:
"ak.mls_welcome_delivery_signature.v1"* idempotency_key ·
stringpattern:
^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status ·
string (enum)enum:
"committed" "duplicate"* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · allOf[2]
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* welcomes · array<$ref ./mls-welcome-delivery.schema.json>
items ·
…recursion truncated at depth 8; see source schema for full shape
* idempotency_key ·
stringpattern:
^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status ·
string (enum)enum:
"committed" "duplicate"* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* authority_ref ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
…recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status ·
string (enum)enum:
"rejected" "retryable_unavailable"* reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* circle_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* sidecar_id ·
…recursion truncated at depth 8; see source schema for full shape
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] ·
integeroneOf · oneOf[1] ·
nullbefore_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] ·
integeroneOf · oneOf[1] ·
null* limit ·
integeroneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
integerSmallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* floor_reason ·
string (enum)Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum:
"stream_start" "membership_join" "history_access_policy"* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
integerSmallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* floor_reason ·
string (enum)Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum:
"stream_start" "membership_join" "history_access_policy"* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* nonce ·
stringpattern:
^[A-Za-z0-9_-]{43}$oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] ·
?* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* governance_generation ·
integerStation tenure this snapshot is bound to. A consumer MUST refuse a snapshot whose generation is not the Realm's current governing Station tenure.
* visible_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
All and only the caller-visible stream heads at the same durable cut as current_state_entries and retention_and_history_floor; hidden Circle/Sidecar streams are not enumerated.
items ·
…recursion truncated at depth 8; see source schema for full shape
* current_state_entries · array<$ref ./typed-current-result.schema.json>
Inline closed typed current results for the caller-visible streams at the same durable cut as visible_stream_heads. An empty array is not a placeholder for an unregistered chunk fetch and proves nothing about hidden streams.
items ·
…recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor · object
Caller-authorized per-stream history floors and Realm history policy at the same durable cut as visible_stream_heads and current_state_entries; no floor for a hidden stream may be disclosed.
* history_access ·
…recursion truncated at depth 8; see source schema for full shape
* stream_floors ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_snapshot_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* genesis_event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
* genesis_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* authority_ref ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
…recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
* authority_transitions · array<$ref #/$defs/authority_transition>
items ·
…recursion truncated at depth 8; see source schema for full shape
* current_generation ·
integer* current_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* current_route_record · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* service_kind ·
…recursion truncated at depth 8; see source schema for full shape
* method_history_evidence ·
…recursion truncated at depth 8; see source schema for full shape
* normalized_did_document ·
…recursion truncated at depth 8; see source schema for full shape
* realm_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* bundle_issued_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* current_assertion ·
$ref #/$defs/current_assertion · $ref #/$defs/current_assertionhistorical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_commit_signature.v1"enum:
"ak.realm_commit_signature.v1"oneOf · oneOf[1] · object
* status ·
string (enum)enum:
"rejected" "retryable_unavailable"* reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] ·
integeroneOf · oneOf[1] ·
nullbefore_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] ·
integeroneOf · oneOf[1] ·
null* limit ·
integeroneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
after_position ·
…recursion truncated at depth 8; see source schema for full shape
before_position ·
…recursion truncated at depth 8; see source schema for full shape
* limit ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_facts ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* nonce ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* handoff ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot ·
…recursion truncated at depth 8; see source schema for full shape
* authority_bundle ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_commit_signature.v1"enum:
"ak.realm_commit_signature.v1"* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event ·
…recursion truncated at depth 8; see source schema for full shape
approval_signatures ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event ·
…recursion truncated at depth 8; see source schema for full shape
* welcomes ·
…recursion truncated at depth 8; see source schema for full shape
* idempotency_key ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status ·
…recursion truncated at depth 8; see source schema for full shape
* commit ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status ·
…recursion truncated at depth 8; see source schema for full shape
* reason_code ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
before_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* limit ·
integeroneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
…recursion truncated at depth 8; see source schema for full shape
* floor_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* floor_reason ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
…recursion truncated at depth 8; see source schema for full shape
* floor_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* floor_reason ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* nonce ·
stringpattern:
^[A-Za-z0-9_-]{43}$oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] ·
?* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* visible_stream_heads ·
…recursion truncated at depth 8; see source schema for full shape
* current_state_entries ·
…recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* genesis_event ·
…recursion truncated at depth 8; see source schema for full shape
* genesis_commit ·
…recursion truncated at depth 8; see source schema for full shape
* authority_transitions ·
…recursion truncated at depth 8; see source schema for full shape
* current_generation ·
…recursion truncated at depth 8; see source schema for full shape
* current_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* current_route_record ·
…recursion truncated at depth 8; see source schema for full shape
* realm_stream_head ·
…recursion truncated at depth 8; see source schema for full shape
* bundle_issued_at ·
…recursion truncated at depth 8; see source schema for full shape
* current_assertion ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind ·
string (enum)enum:
"ak.agent.action_approve" "ak.agent.interaction.set" "ak.agent.key.authorize" "ak.agent.key.revoke" "ak.agent.provision" "ak.agent.sidecar.exchange.control" "ak.applet.bridge_error" "ak.applet.discovery" "ak.applet.managed_actor.provision" "ak.applet.registration" "ak.audit.accessed" "ak.audit.erasure_receipt" "ak.call.create" "ak.call.recording.start" "ak.call.state" "ak.capability.grant" "ak.capability.relinquish" "ak.capability.revoke" "ak.circle.archive" "ak.circle.create" "ak.circle.history_access" "ak.circle.member.state" "ak.circle.restore" "ak.circle.tombstone" "ak.circle.update" "ak.consent.grant" "ak.consent.revoke" "ak.contact.accepted" "ak.contact.rejected" "ak.contact.requested" "ak.contact.scope.update" "ak.contact.tombstone" "ak.device.authorize" "ak.device.reanchor" "ak.device.revoke" "ak.direct_conversation.bound" "ak.identity.accountability_grant" "ak.identity.resolution.update" "ak.invite.accept" "ak.invite.cancel" "ak.invite.claim" "ak.invite.create" "ak.invite.revoke" "ak.invite.third_party" "ak.key_backup.active_series" "ak.member.identity.update" "ak.member.state" "ak.message.create" "ak.message.redact" "ak.message.revise" "ak.mimi.room_binding" "ak.mls.commit" "ak.mls.genesis" "ak.moderation.decision" "ak.moderation.decision.lift" "ak.moderation.franking_proof" "ak.morph.archive" "ak.morph.create" "ak.morph.restore" "ak.morph.stage.set" "ak.morph.update" "ak.organization.moderation_policy" "ak.pin.add" "ak.pin.remove" "ak.pin.reorder" "ak.policy.action" "ak.policy.set" "ak.profile.create" "ak.profile.realm_override" "ak.profile.update" "ak.reaction.add" "ak.reaction.remove" "ak.realm.alias" "ak.realm.archive" "ak.realm.asset_privacy_policy" "ak.realm.authority.reset" "ak.realm.create" "ak.realm.destroy" "ak.realm.discovery" "ak.realm.freeze" "ak.realm.governance_station.change" "ak.realm.history_access" "ak.realm.join_rule" "ak.realm.link" "ak.realm.media_service" "ak.realm.organization" "ak.realm.owner.transfer" "ak.realm.plaintext_visible_services" "ak.realm.policy_bundle" "ak.realm.preview_policy" "ak.realm.profile" "ak.realm.read_receipt_policy" "ak.realm.restore" "ak.realm.schema" "ak.realm.search_policy" "ak.realm.set_default_strand" "ak.realm.tombstone" "ak.realm.unfreeze" "ak.redaction" "ak.relation.create" "ak.relation.tombstone" "ak.relation.update" "ak.rsvp.set" "ak.schema.define" "ak.self.agent.deactivate" "ak.self.agent.pause" "ak.self.agent.resume" "ak.self.moderation.report" "ak.sidecar.context.attach" "ak.sidecar.create" "ak.space.archive" "ak.space.create" "ak.space.parent" "ak.space.restore" "ak.space.tombstone" "ak.space.update" "ak.strand.archive" "ak.strand.create" "ak.strand.move" "ak.strand.reorder" "ak.strand.restore" "ak.strand.stage.set" "ak.strand.tracks.update" "ak.strand.update" "ak.strand.watch.set" "ak.view.create" "ak.view.reconcile" "ak.view.update"oneOf · oneOf[1] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
after_position ·
…recursion truncated at depth 8; see source schema for full shape
before_position ·
…recursion truncated at depth 8; see source schema for full shape
* limit ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_facts ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* nonce ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* handoff ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot ·
…recursion truncated at depth 8; see source schema for full shape
* authority_bundle ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_commit_signature.v1"enum:
"ak.realm_commit_signature.v1"* event_disclosure ·
$ref #/$defs/EventDisclosure · $ref #/$defs/EventDisclosurereadable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
integerSmallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* floor_reason ·
string (enum)Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum:
"stream_start" "membership_join" "history_access_policy"* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
after_position ·
…recursion truncated at depth 8; see source schema for full shape
before_position ·
…recursion truncated at depth 8; see source schema for full shape
* limit ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_facts ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* nonce ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* handoff ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot ·
…recursion truncated at depth 8; see source schema for full shape
* authority_bundle ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_commit_signature.v1"enum:
"ak.realm_commit_signature.v1"* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event ·
…recursion truncated at depth 8; see source schema for full shape
approval_signatures ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event ·
…recursion truncated at depth 8; see source schema for full shape
* welcomes ·
…recursion truncated at depth 8; see source schema for full shape
* idempotency_key ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status ·
…recursion truncated at depth 8; see source schema for full shape
* commit ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status ·
…recursion truncated at depth 8; see source schema for full shape
* reason_code ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
before_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* limit ·
integeroneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
…recursion truncated at depth 8; see source schema for full shape
* floor_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* floor_reason ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
…recursion truncated at depth 8; see source schema for full shape
* floor_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* floor_reason ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* nonce ·
stringpattern:
^[A-Za-z0-9_-]{43}$oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] ·
?* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* visible_stream_heads ·
…recursion truncated at depth 8; see source schema for full shape
* current_state_entries ·
…recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* genesis_event ·
…recursion truncated at depth 8; see source schema for full shape
* genesis_commit ·
…recursion truncated at depth 8; see source schema for full shape
* authority_transitions ·
…recursion truncated at depth 8; see source schema for full shape
* current_generation ·
…recursion truncated at depth 8; see source schema for full shape
* current_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* current_route_record ·
…recursion truncated at depth 8; see source schema for full shape
* realm_stream_head ·
…recursion truncated at depth 8; see source schema for full shape
* bundle_issued_at ·
…recursion truncated at depth 8; see source schema for full shape
* current_assertion ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind ·
string (enum)enum:
"ak.agent.action_approve" "ak.agent.interaction.set" "ak.agent.key.authorize" "ak.agent.key.revoke" "ak.agent.provision" "ak.agent.sidecar.exchange.control" "ak.applet.bridge_error" "ak.applet.discovery" "ak.applet.managed_actor.provision" "ak.applet.registration" "ak.audit.accessed" "ak.audit.erasure_receipt" "ak.call.create" "ak.call.recording.start" "ak.call.state" "ak.capability.grant" "ak.capability.relinquish" "ak.capability.revoke" "ak.circle.archive" "ak.circle.create" "ak.circle.history_access" "ak.circle.member.state" "ak.circle.restore" "ak.circle.tombstone" "ak.circle.update" "ak.consent.grant" "ak.consent.revoke" "ak.contact.accepted" "ak.contact.rejected" "ak.contact.requested" "ak.contact.scope.update" "ak.contact.tombstone" "ak.device.authorize" "ak.device.reanchor" "ak.device.revoke" "ak.direct_conversation.bound" "ak.identity.accountability_grant" "ak.identity.resolution.update" "ak.invite.accept" "ak.invite.cancel" "ak.invite.claim" "ak.invite.create" "ak.invite.revoke" "ak.invite.third_party" "ak.key_backup.active_series" "ak.member.identity.update" "ak.member.state" "ak.message.create" "ak.message.redact" "ak.message.revise" "ak.mimi.room_binding" "ak.mls.commit" "ak.mls.genesis" "ak.moderation.decision" "ak.moderation.decision.lift" "ak.moderation.franking_proof" "ak.morph.archive" "ak.morph.create" "ak.morph.restore" "ak.morph.stage.set" "ak.morph.update" "ak.organization.moderation_policy" "ak.pin.add" "ak.pin.remove" "ak.pin.reorder" "ak.policy.action" "ak.policy.set" "ak.profile.create" "ak.profile.realm_override" "ak.profile.update" "ak.reaction.add" "ak.reaction.remove" "ak.realm.alias" "ak.realm.archive" "ak.realm.asset_privacy_policy" "ak.realm.authority.reset" "ak.realm.create" "ak.realm.destroy" "ak.realm.discovery" "ak.realm.freeze" "ak.realm.governance_station.change" "ak.realm.history_access" "ak.realm.join_rule" "ak.realm.link" "ak.realm.media_service" "ak.realm.organization" "ak.realm.owner.transfer" "ak.realm.plaintext_visible_services" "ak.realm.policy_bundle" "ak.realm.preview_policy" "ak.realm.profile" "ak.realm.read_receipt_policy" "ak.realm.restore" "ak.realm.schema" "ak.realm.search_policy" "ak.realm.set_default_strand" "ak.realm.tombstone" "ak.realm.unfreeze" "ak.redaction" "ak.relation.create" "ak.relation.tombstone" "ak.relation.update" "ak.rsvp.set" "ak.schema.define" "ak.self.agent.deactivate" "ak.self.agent.pause" "ak.self.agent.resume" "ak.self.moderation.report" "ak.sidecar.context.attach" "ak.sidecar.create" "ak.space.archive" "ak.space.create" "ak.space.parent" "ak.space.restore" "ak.space.tombstone" "ak.space.update" "ak.strand.archive" "ak.strand.create" "ak.strand.move" "ak.strand.reorder" "ak.strand.restore" "ak.strand.stage.set" "ak.strand.tracks.update" "ak.strand.update" "ak.strand.watch.set" "ak.view.create" "ak.view.reconcile" "ak.view.update"oneOf · oneOf[1] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
after_position ·
…recursion truncated at depth 8; see source schema for full shape
before_position ·
…recursion truncated at depth 8; see source schema for full shape
* limit ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor ·
…recursion truncated at depth 8; see source schema for full shape
* truncated ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_facts ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* nonce ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* handoff ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot ·
…recursion truncated at depth 8; see source schema for full shape
* authority_bundle ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_commit_signature.v1"enum:
"ak.realm_commit_signature.v1"* event_disclosure ·
$ref #/$defs/EventDisclosure · $ref #/$defs/EventDisclosurereadable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
integerSmallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* floor_reason ·
string (enum)Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum:
"stream_start" "membership_join" "history_access_policy"* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* stream_position ·
integer* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] · object · $ref #/$defs/human_historical_signer_fact
Minimal immutable original Human device signer source frozen in governance acceptance. Actual signing Account, independent authorization coordinates/revision/PCR tenure and source accepted time. No target CommitId/position, current permission, verified flag or private PCR bytes.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* actor · object · $ref ./signer-key-operations.schema.json#/$defs/signing_account_actor_id
Complete account ActorId of the exact verified signer, preserving its Station for either an ordinary device or Agent.
* kind ·
const "account"enum:
"account"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* verification_method ·
string (uri) · format=uripattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* key · object · $ref ./signer-key-operations.schema.json#/$defs/query_signing_key
Shared resolved key shape for existing current Agent and historical Agent/Human roles; each enclosing selector/outcome retains its own authority and source rules. Only new ordinary Human historical delivery uses original governance Commit-bound immutable facts. Independent original authorization coordinates/revision/PCR governance generation remain mandatory where the enclosing role requires them; no current fallback or new target source.
* public_key_b64u ·
stringCanonical unpadded base64url of exactly 32 Ed25519 public-key bytes; this is public material, not reusable current authorization.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* authorization_ref · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
integer* revision · object
Verified current revision of the authorization stream at resolution. The revision belongs to authorization_ref.stream_ref, is not older than authorization_ref.stream_position, and is never inferred from arrival order, a cursor or a current projection.
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* governance_generation ·
integerVerified governance generation of revision.commit_id.
* accepted_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[1] · object · $ref #/$defs/service_historical_signer_fact
Minimal immutable Applet Service producer source: original key, exact accepted registration epoch and installation authorization coordinates/scope. Frozen at target governance acceptance and bound by original Commit digest; no runtime completion, private Profile/control/history bodies or private signing material. This does not grant access to the source Events.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* actor · object · $ref ./signer-key-operations.schema.json#/$defs/signing_service_actor_id
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verification_method ·
string (uri) · format=uripattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* key · object · $ref ./signer-key-operations.schema.json#/$defs/service_historical_signing_key
* public_key_b64u ·
stringCanonical unpadded base64url of exactly 32 Ed25519 public-key bytes; this is public material, not reusable current authorization.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* applet_id ·
string · $ref ./common-ids.schema.json#/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* registration_epoch ·
string · $ref ./event-payload.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* registration_ref · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
integer* authorization_ref · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
integer* effective_scope · oneOf[4] · $ref ./event-envelope.schema.json#/$defs/scope_ref
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* circle_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* sidecar_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* accepted_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* nonce ·
stringpattern:
^[A-Za-z0-9_-]{43}$oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] ·
?* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input ·
…recursion truncated at depth 8; see source schema for full shape
* proof ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
kind ·
…recursion truncated at depth 8; see source schema for full shape
* welcomes · array<$ref ./mls-welcome-delivery.schema.json>
items · object · $ref ./mls-welcome-delivery.schema.json
Producer-signed recipient delivery queued atomically with its winning MLS Commit. This is not a shared Realm Event and does not receive an independent RealmCommit.
* welcome_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* effective_scope ·
…recursion truncated at depth 8; see source schema for full shape
* commit_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* recipient_actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* recipient_endpoint ·
…recursion truncated at depth 8; see source schema for full shape
* keypackage_claim_ref ·
…recursion truncated at depth 8; see source schema for full shape
* ciphertext_b64 ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
* idempotency_key ·
stringpattern:
^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status ·
string (enum)enum:
"committed" "duplicate"* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status ·
string (enum)enum:
"rejected" "retryable_unavailable"* reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] ·
integeroneOf · oneOf[1] ·
nullbefore_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] ·
integeroneOf · oneOf[1] ·
null* limit ·
integeroneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit ·
…recursion truncated at depth 8; see source schema for full shape
* event ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit ·
…recursion truncated at depth 8; see source schema for full shape
* event_disclosure ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
integerSmallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* floor_reason ·
string (enum)Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum:
"stream_start" "membership_join" "history_access_policy"* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit ·
…recursion truncated at depth 8; see source schema for full shape
* event ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit ·
…recursion truncated at depth 8; see source schema for full shape
* event_disclosure ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
integerSmallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* floor_reason ·
string (enum)Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum:
"stream_start" "membership_join" "history_access_policy"* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* nonce ·
stringpattern:
^[A-Za-z0-9_-]{43}$oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] ·
?* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* governance_generation ·
integerStation tenure this snapshot is bound to. A consumer MUST refuse a snapshot whose generation is not the Realm's current governing Station tenure.
* visible_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
All and only the caller-visible stream heads at the same durable cut as current_state_entries and retention_and_history_floor; hidden Circle/Sidecar streams are not enumerated.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* current_state_entries · array<$ref ./typed-current-result.schema.json>
Inline closed typed current results for the caller-visible streams at the same durable cut as visible_stream_heads. An empty array is not a placeholder for an unregistered chunk fetch and proves nothing about hidden streams.
items · oneOf[85] · $ref ./typed-current-result.schema.json
Closed domain result selected without protocol typed current result IDs. Every result names the last authority commit that affected the typed target.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor · object
Caller-authorized per-stream history floors and Realm history policy at the same durable cut as visible_stream_heads and current_state_entries; no floor for a hidden stream may be disclosed.
* history_access ·
string (enum)enum:
"since_join" "all_history_for_current_members"* stream_floors · array<object>
items ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_snapshot_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* genesis_event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
* genesis_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* authority_transitions · array<$ref #/$defs/authority_transition>
items ·
$ref #/$defs/authority_transition · $ref #/$defs/authority_transition* current_generation ·
integer* current_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* current_route_record · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* service_kind ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$* method_history_evidence ·
$ref #/$defs/method_history_evidence · $ref #/$defs/method_history_evidence* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did ·
…recursion truncated at depth 8; see source schema for full shape
* contexts ·
…recursion truncated at depth 8; see source schema for full shape
* controller_dids ·
…recursion truncated at depth 8; see source schema for full shape
* also_known_as ·
…recursion truncated at depth 8; see source schema for full shape
* verification_methods ·
…recursion truncated at depth 8; see source schema for full shape
* authentication ·
…recursion truncated at depth 8; see source schema for full shape
* assertion_methods ·
…recursion truncated at depth 8; see source schema for full shape
* key_agreements ·
…recursion truncated at depth 8; see source schema for full shape
* capability_invocations ·
…recursion truncated at depth 8; see source schema for full shape
* capability_delegations ·
…recursion truncated at depth 8; see source schema for full shape
* services ·
…recursion truncated at depth 8; see source schema for full shape
* metadata ·
…recursion truncated at depth 8; see source schema for full shape
* extensions ·
…recursion truncated at depth 8; see source schema for full shape
* realm_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* bundle_issued_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* current_assertion ·
$ref #/$defs/current_assertion · $ref #/$defs/current_assertionhistorical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_old_signature.v1"enum:
"ak.realm_authority_handoff_old_signature.v1"* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input ·
…recursion truncated at depth 8; see source schema for full shape
* proof ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
kind ·
…recursion truncated at depth 8; see source schema for full shape
* welcomes · array<$ref ./mls-welcome-delivery.schema.json>
items · object · $ref ./mls-welcome-delivery.schema.json
Producer-signed recipient delivery queued atomically with its winning MLS Commit. This is not a shared Realm Event and does not receive an independent RealmCommit.
* welcome_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* effective_scope ·
…recursion truncated at depth 8; see source schema for full shape
* commit_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* recipient_actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* recipient_endpoint ·
…recursion truncated at depth 8; see source schema for full shape
* keypackage_claim_ref ·
…recursion truncated at depth 8; see source schema for full shape
* ciphertext_b64 ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
* idempotency_key ·
stringpattern:
^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status ·
string (enum)enum:
"committed" "duplicate"* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status ·
string (enum)enum:
"rejected" "retryable_unavailable"* reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] ·
integeroneOf · oneOf[1] ·
nullbefore_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] ·
integeroneOf · oneOf[1] ·
null* limit ·
integeroneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit ·
…recursion truncated at depth 8; see source schema for full shape
* event ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit ·
…recursion truncated at depth 8; see source schema for full shape
* event_disclosure ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
integerSmallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* floor_reason ·
string (enum)Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum:
"stream_start" "membership_join" "history_access_policy"* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit ·
…recursion truncated at depth 8; see source schema for full shape
* event ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit ·
…recursion truncated at depth 8; see source schema for full shape
* event_disclosure ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
integerSmallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* floor_reason ·
string (enum)Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum:
"stream_start" "membership_join" "history_access_policy"* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* nonce ·
stringpattern:
^[A-Za-z0-9_-]{43}$oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] ·
?* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* governance_generation ·
integerStation tenure this snapshot is bound to. A consumer MUST refuse a snapshot whose generation is not the Realm's current governing Station tenure.
* visible_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
All and only the caller-visible stream heads at the same durable cut as current_state_entries and retention_and_history_floor; hidden Circle/Sidecar streams are not enumerated.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* current_state_entries · array<$ref ./typed-current-result.schema.json>
Inline closed typed current results for the caller-visible streams at the same durable cut as visible_stream_heads. An empty array is not a placeholder for an unregistered chunk fetch and proves nothing about hidden streams.
items · oneOf[85] · $ref ./typed-current-result.schema.json
Closed domain result selected without protocol typed current result IDs. Every result names the last authority commit that affected the typed target.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor · object
Caller-authorized per-stream history floors and Realm history policy at the same durable cut as visible_stream_heads and current_state_entries; no floor for a hidden stream may be disclosed.
* history_access ·
string (enum)enum:
"since_join" "all_history_for_current_members"* stream_floors · array<object>
items ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_snapshot_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* genesis_event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
* genesis_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* authority_transitions · array<$ref #/$defs/authority_transition>
items ·
$ref #/$defs/authority_transition · $ref #/$defs/authority_transition* current_generation ·
integer* current_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* current_route_record · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* service_kind ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$* method_history_evidence ·
$ref #/$defs/method_history_evidence · $ref #/$defs/method_history_evidence* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did ·
…recursion truncated at depth 8; see source schema for full shape
* contexts ·
…recursion truncated at depth 8; see source schema for full shape
* controller_dids ·
…recursion truncated at depth 8; see source schema for full shape
* also_known_as ·
…recursion truncated at depth 8; see source schema for full shape
* verification_methods ·
…recursion truncated at depth 8; see source schema for full shape
* authentication ·
…recursion truncated at depth 8; see source schema for full shape
* assertion_methods ·
…recursion truncated at depth 8; see source schema for full shape
* key_agreements ·
…recursion truncated at depth 8; see source schema for full shape
* capability_invocations ·
…recursion truncated at depth 8; see source schema for full shape
* capability_delegations ·
…recursion truncated at depth 8; see source schema for full shape
* services ·
…recursion truncated at depth 8; see source schema for full shape
* metadata ·
…recursion truncated at depth 8; see source schema for full shape
* extensions ·
…recursion truncated at depth 8; see source schema for full shape
* realm_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* bundle_issued_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* current_assertion ·
$ref #/$defs/current_assertion · $ref #/$defs/current_assertionhistorical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_new_acceptance_signature.v1"enum:
"ak.realm_authority_handoff_new_acceptance_signature.v1"* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* governance_generation ·
integerStation tenure this snapshot is bound to. A consumer MUST refuse a snapshot whose generation is not the Realm's current governing Station tenure.
* visible_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
All and only the caller-visible stream heads at the same durable cut as current_state_entries and retention_and_history_floor; hidden Circle/Sidecar streams are not enumerated.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* current_state_entries · array<$ref ./typed-current-result.schema.json>
Inline closed typed current results for the caller-visible streams at the same durable cut as visible_stream_heads. An empty array is not a placeholder for an unregistered chunk fetch and proves nothing about hidden streams.
items · oneOf[85] · $ref ./typed-current-result.schema.json
Closed domain result selected without protocol typed current result IDs. Every result names the last authority commit that affected the typed target.
oneOf · oneOf[0] ·
$ref #/$defs/agent_interaction_result · $ref #/$defs/agent_interaction_resultoneOf · oneOf[1] ·
$ref #/$defs/realm_authority_root_result · $ref #/$defs/realm_authority_root_resultoneOf · oneOf[2] ·
$ref #/$defs/realm_profile_result · $ref #/$defs/realm_profile_resultoneOf · oneOf[3] ·
$ref #/$defs/member_state_result · $ref #/$defs/member_state_resultoneOf · oneOf[4] ·
$ref #/$defs/strand_result · $ref #/$defs/strand_resultoneOf · oneOf[5] ·
$ref #/$defs/space_result · $ref #/$defs/space_resultoneOf · oneOf[6] ·
$ref #/$defs/message_reactions_result · $ref #/$defs/message_reactions_resultoneOf · oneOf[7] ·
$ref #/$defs/relation_result · $ref #/$defs/relation_resultoneOf · oneOf[8] ·
$ref #/$defs/mls_group_result · $ref #/$defs/mls_group_resultoneOf · oneOf[9] ·
$ref #/$defs/agent_key_result · $ref #/$defs/agent_key_resultoneOf · oneOf[10] ·
$ref #/$defs/agent_status_result · $ref #/$defs/agent_status_resultoneOf · oneOf[11] ·
$ref #/$defs/realm_genesis_result · $ref #/$defs/realm_genesis_resultoneOf · oneOf[12] ·
$ref #/$defs/realm_history_access_result · $ref #/$defs/realm_history_access_resultoneOf · oneOf[13] ·
$ref #/$defs/identity_resolution_result · $ref #/$defs/identity_resolution_resultoneOf · oneOf[14] ·
$ref #/$defs/identity_accountability_result · $ref #/$defs/identity_accountability_resultoneOf · oneOf[15] ·
$ref #/$defs/capability_grant_result · $ref #/$defs/capability_grant_resultoneOf · oneOf[16] ·
$ref #/$defs/call_state_result · $ref #/$defs/call_state_resultoneOf · oneOf[17] ·
$ref #/$defs/call_focus_result · $ref #/$defs/call_focus_resultoneOf · oneOf[18] ·
$ref #/$defs/call_recording_state_result · $ref #/$defs/call_recording_state_resultoneOf · oneOf[19] ·
$ref #/$defs/call_recording_artifact_result · $ref #/$defs/call_recording_artifact_resultoneOf · oneOf[20] ·
$ref #/$defs/call_transcript_state_result · $ref #/$defs/call_transcript_state_resultoneOf · oneOf[21] ·
$ref #/$defs/call_transcript_artifact_result · $ref #/$defs/call_transcript_artifact_resultoneOf · oneOf[22] ·
$ref #/$defs/call_moderation_result · $ref #/$defs/call_moderation_resultoneOf · oneOf[23] ·
$ref #/$defs/call_roster_result · $ref #/$defs/call_roster_resultoneOf · oneOf[24] ·
$ref #/$defs/call_mute_override_result · $ref #/$defs/call_mute_override_resultoneOf · oneOf[25] ·
$ref #/$defs/realm_schema_result · $ref #/$defs/realm_schema_resultoneOf · oneOf[26] ·
$ref #/$defs/realm_link_result · $ref #/$defs/realm_link_resultoneOf · oneOf[27] ·
$ref #/$defs/realm_join_rule_result · $ref #/$defs/realm_join_rule_resultoneOf · oneOf[28] ·
$ref #/$defs/realm_discovery_result · $ref #/$defs/realm_discovery_resultoneOf · oneOf[29] ·
$ref #/$defs/realm_alias_result · $ref #/$defs/realm_alias_resultoneOf · oneOf[30] ·
$ref #/$defs/realm_policy_bundle_result · $ref #/$defs/realm_policy_bundle_resultoneOf · oneOf[31] ·
$ref #/$defs/realm_asset_privacy_policy_result · $ref #/$defs/realm_asset_privacy_policy_resultoneOf · oneOf[32] ·
$ref #/$defs/realm_plaintext_visible_services_result · $ref #/$defs/realm_plaintext_visible_services_resultoneOf · oneOf[33] ·
$ref #/$defs/realm_media_service_result · $ref #/$defs/realm_media_service_resultoneOf · oneOf[34] ·
$ref #/$defs/realm_read_receipt_policy_result · $ref #/$defs/realm_read_receipt_policy_resultoneOf · oneOf[35] ·
$ref #/$defs/realm_preview_policy_result · $ref #/$defs/realm_preview_policy_resultoneOf · oneOf[36] ·
$ref #/$defs/mimi_room_binding_result · $ref #/$defs/mimi_room_binding_resultoneOf · oneOf[37] ·
$ref #/$defs/moderation_franking_proof_result · $ref #/$defs/moderation_franking_proof_resultoneOf · oneOf[38] ·
$ref #/$defs/realm_tombstone_result · $ref #/$defs/realm_tombstone_resultoneOf · oneOf[39] ·
$ref #/$defs/realm_destroy_result · $ref #/$defs/realm_destroy_resultoneOf · oneOf[40] ·
$ref #/$defs/realm_set_default_strand_result · $ref #/$defs/realm_set_default_strand_resultoneOf · oneOf[41] ·
$ref #/$defs/strand_position_result · $ref #/$defs/strand_position_resultoneOf · oneOf[42] ·
$ref #/$defs/invite_lifecycle_result · $ref #/$defs/invite_lifecycle_resultoneOf · oneOf[43] ·
$ref #/$defs/invite_live_target_result · $ref #/$defs/invite_live_target_resultoneOf · oneOf[44] ·
$ref #/$defs/invite_directed_invitee_result · $ref #/$defs/invite_directed_invitee_resultoneOf · oneOf[45] ·
$ref #/$defs/pin_result · $ref #/$defs/pin_resultoneOf · oneOf[46] ·
$ref #/$defs/space_parent_result · $ref #/$defs/space_parent_resultoneOf · oneOf[47] ·
$ref #/$defs/space_child_scope_policy_result · $ref #/$defs/space_child_scope_policy_resultoneOf · oneOf[48] ·
$ref #/$defs/agent_provisioning_result · $ref #/$defs/agent_provisioning_resultoneOf · oneOf[49] ·
$ref #/$defs/agent_pcr_genesis_declaration_result · $ref #/$defs/agent_pcr_genesis_declaration_resultoneOf · oneOf[50] ·
$ref #/$defs/agent_selector_claim_result · $ref #/$defs/agent_selector_claim_resultoneOf · oneOf[51] ·
$ref #/$defs/consent_result · $ref #/$defs/consent_resultoneOf · oneOf[52] ·
$ref #/$defs/moderation_state_result · $ref #/$defs/moderation_state_resultoneOf · oneOf[53] ·
$ref #/$defs/object_redaction_result · $ref #/$defs/object_redaction_resultoneOf · oneOf[54] ·
$ref #/$defs/organization_moderation_policy_result · $ref #/$defs/organization_moderation_policy_resultoneOf · oneOf[55] ·
$ref #/$defs/view_result · $ref #/$defs/view_resultoneOf · oneOf[56] ·
$ref #/$defs/policy_result · $ref #/$defs/policy_resultoneOf · oneOf[57] ·
$ref #/$defs/device_authorization_result · $ref #/$defs/device_authorization_resultoneOf · oneOf[58] ·
$ref #/$defs/device_generation_result · $ref #/$defs/device_generation_resultoneOf · oneOf[59] ·
$ref #/$defs/device_revocation_proposals_result · $ref #/$defs/device_revocation_proposals_resultoneOf · oneOf[60] ·
$ref #/$defs/agent_action_approval_result · $ref #/$defs/agent_action_approval_resultoneOf · oneOf[61] ·
$ref #/$defs/agent_sidecar_exchange_controls_result · $ref #/$defs/agent_sidecar_exchange_controls_resultoneOf · oneOf[62] ·
$ref #/$defs/applet_discovery_result · $ref #/$defs/applet_discovery_resultoneOf · oneOf[63] ·
$ref #/$defs/applet_registration_result · $ref #/$defs/applet_registration_resultoneOf · oneOf[64] ·
$ref #/$defs/key_backup_active_series_result · $ref #/$defs/key_backup_active_series_resultoneOf · oneOf[65] ·
$ref #/$defs/member_identity_updates_result · $ref #/$defs/member_identity_updates_resultoneOf · oneOf[66] ·
$ref #/$defs/message_revision_result · $ref #/$defs/message_revision_resultoneOf · oneOf[67] ·
$ref #/$defs/actor_profile_realm_override_result · $ref #/$defs/actor_profile_realm_override_resultoneOf · oneOf[68] ·
$ref #/$defs/realm_organization_result · $ref #/$defs/realm_organization_resultoneOf · oneOf[69] ·
$ref #/$defs/circle_member_state_result · $ref #/$defs/circle_member_state_resultoneOf · oneOf[70] ·
$ref #/$defs/circle_result · $ref #/$defs/circle_resultoneOf · oneOf[71] ·
$ref #/$defs/realm_search_policy_result · $ref #/$defs/realm_search_policy_resultoneOf · oneOf[72] ·
$ref #/$defs/rsvp_result · $ref #/$defs/rsvp_resultoneOf · oneOf[73] ·
$ref #/$defs/schema_definition_result · $ref #/$defs/schema_definition_resultoneOf · oneOf[74] ·
$ref #/$defs/sidecar_context_result · $ref #/$defs/sidecar_context_resultoneOf · oneOf[75] ·
$ref #/$defs/sidecar_result · $ref #/$defs/sidecar_resultoneOf · oneOf[76] ·
$ref #/$defs/strand_watch_result · $ref #/$defs/strand_watch_resultoneOf · oneOf[77] ·
$ref #/$defs/calendar_schedule_source_result · $ref #/$defs/calendar_schedule_source_resultoneOf · oneOf[78] ·
$ref #/$defs/actor_profile_result · $ref #/$defs/actor_profile_resultoneOf · oneOf[79] ·
$ref #/$defs/direct_conversation_binding_result · $ref #/$defs/direct_conversation_binding_resultoneOf · oneOf[80] ·
$ref #/$defs/moderation_report_result · $ref #/$defs/moderation_report_resultoneOf · oneOf[81] ·
$ref #/$defs/morph_result · $ref #/$defs/morph_resultoneOf · oneOf[82] ·
$ref #/$defs/policy_action_result · $ref #/$defs/policy_action_resultoneOf · oneOf[83] ·
$ref #/$defs/realm_archive_result · $ref #/$defs/realm_archive_resultoneOf · oneOf[84] ·
$ref #/$defs/realm_freeze_result · $ref #/$defs/realm_freeze_result* retention_and_history_floor · object
Caller-authorized per-stream history floors and Realm history policy at the same durable cut as visible_stream_heads and current_state_entries; no floor for a hidden stream may be disclosed.
* history_access ·
string (enum)enum:
"since_join" "all_history_for_current_members"* stream_floors · array<object>
items · object
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* oldest_position ·
integer* created_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_snapshot_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input ·
…recursion truncated at depth 8; see source schema for full shape
* proof ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
kind ·
…recursion truncated at depth 8; see source schema for full shape
* welcomes · array<$ref ./mls-welcome-delivery.schema.json>
items · object · $ref ./mls-welcome-delivery.schema.json
Producer-signed recipient delivery queued atomically with its winning MLS Commit. This is not a shared Realm Event and does not receive an independent RealmCommit.
* welcome_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* effective_scope ·
…recursion truncated at depth 8; see source schema for full shape
* commit_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* recipient_actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* recipient_endpoint ·
…recursion truncated at depth 8; see source schema for full shape
* keypackage_claim_ref ·
…recursion truncated at depth 8; see source schema for full shape
* ciphertext_b64 ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
* idempotency_key ·
stringpattern:
^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status ·
string (enum)enum:
"committed" "duplicate"* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status ·
string (enum)enum:
"rejected" "retryable_unavailable"* reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] ·
integeroneOf · oneOf[1] ·
nullbefore_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] ·
integeroneOf · oneOf[1] ·
null* limit ·
integeroneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit ·
…recursion truncated at depth 8; see source schema for full shape
* event ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit ·
…recursion truncated at depth 8; see source schema for full shape
* event_disclosure ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
integerSmallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* floor_reason ·
string (enum)Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum:
"stream_start" "membership_join" "history_access_policy"* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit ·
…recursion truncated at depth 8; see source schema for full shape
* event ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit ·
…recursion truncated at depth 8; see source schema for full shape
* event_disclosure ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
integerSmallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* floor_reason ·
string (enum)Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum:
"stream_start" "membership_join" "history_access_policy"* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* nonce ·
stringpattern:
^[A-Za-z0-9_-]{43}$oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] ·
?* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* governance_generation ·
integerStation tenure this snapshot is bound to. A consumer MUST refuse a snapshot whose generation is not the Realm's current governing Station tenure.
* visible_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
All and only the caller-visible stream heads at the same durable cut as current_state_entries and retention_and_history_floor; hidden Circle/Sidecar streams are not enumerated.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* current_state_entries · array<$ref ./typed-current-result.schema.json>
Inline closed typed current results for the caller-visible streams at the same durable cut as visible_stream_heads. An empty array is not a placeholder for an unregistered chunk fetch and proves nothing about hidden streams.
items · oneOf[85] · $ref ./typed-current-result.schema.json
Closed domain result selected without protocol typed current result IDs. Every result names the last authority commit that affected the typed target.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor · object
Caller-authorized per-stream history floors and Realm history policy at the same durable cut as visible_stream_heads and current_state_entries; no floor for a hidden stream may be disclosed.
* history_access ·
string (enum)enum:
"since_join" "all_history_for_current_members"* stream_floors · array<object>
items ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_snapshot_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* genesis_event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
* genesis_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* authority_transitions · array<$ref #/$defs/authority_transition>
items ·
$ref #/$defs/authority_transition · $ref #/$defs/authority_transition* current_generation ·
integer* current_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* current_route_record · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* service_kind ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$* method_history_evidence ·
$ref #/$defs/method_history_evidence · $ref #/$defs/method_history_evidence* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did ·
…recursion truncated at depth 8; see source schema for full shape
* contexts ·
…recursion truncated at depth 8; see source schema for full shape
* controller_dids ·
…recursion truncated at depth 8; see source schema for full shape
* also_known_as ·
…recursion truncated at depth 8; see source schema for full shape
* verification_methods ·
…recursion truncated at depth 8; see source schema for full shape
* authentication ·
…recursion truncated at depth 8; see source schema for full shape
* assertion_methods ·
…recursion truncated at depth 8; see source schema for full shape
* key_agreements ·
…recursion truncated at depth 8; see source schema for full shape
* capability_invocations ·
…recursion truncated at depth 8; see source schema for full shape
* capability_delegations ·
…recursion truncated at depth 8; see source schema for full shape
* services ·
…recursion truncated at depth 8; see source schema for full shape
* metadata ·
…recursion truncated at depth 8; see source schema for full shape
* extensions ·
…recursion truncated at depth 8; see source schema for full shape
* realm_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* bundle_issued_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* current_assertion ·
$ref #/$defs/current_assertion · $ref #/$defs/current_assertionhistorical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_snapshot_signature.v1"enum:
"ak.realm_snapshot_signature.v1"* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* genesis_event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idexecuted_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idauthorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
* genesis_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · allOf[2]
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* welcomes · array<$ref ./mls-welcome-delivery.schema.json>
items ·
…recursion truncated at depth 8; see source schema for full shape
* idempotency_key ·
stringpattern:
^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status ·
string (enum)enum:
"committed" "duplicate"* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* authority_ref ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
…recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status ·
string (enum)enum:
"rejected" "retryable_unavailable"* reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* circle_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* sidecar_id ·
…recursion truncated at depth 8; see source schema for full shape
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] ·
integeroneOf · oneOf[1] ·
nullbefore_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] ·
integeroneOf · oneOf[1] ·
null* limit ·
integeroneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
integerSmallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* floor_reason ·
string (enum)Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum:
"stream_start" "membership_join" "history_access_policy"* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position ·
integerSmallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* floor_reason ·
string (enum)Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum:
"stream_start" "membership_join" "history_access_policy"* truncated ·
booleanTrue when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* nonce ·
stringpattern:
^[A-Za-z0-9_-]{43}$oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] ·
?* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* governance_generation ·
integerStation tenure this snapshot is bound to. A consumer MUST refuse a snapshot whose generation is not the Realm's current governing Station tenure.
* visible_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
All and only the caller-visible stream heads at the same durable cut as current_state_entries and retention_and_history_floor; hidden Circle/Sidecar streams are not enumerated.
items ·
…recursion truncated at depth 8; see source schema for full shape
* current_state_entries · array<$ref ./typed-current-result.schema.json>
Inline closed typed current results for the caller-visible streams at the same durable cut as visible_stream_heads. An empty array is not a placeholder for an unregistered chunk fetch and proves nothing about hidden streams.
items ·
…recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor · object
Caller-authorized per-stream history floors and Realm history policy at the same durable cut as visible_stream_heads and current_state_entries; no floor for a hidden stream may be disclosed.
* history_access ·
…recursion truncated at depth 8; see source schema for full shape
* stream_floors ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_snapshot_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* genesis_event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
* genesis_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* authority_ref ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
…recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
* authority_transitions · array<$ref #/$defs/authority_transition>
items ·
…recursion truncated at depth 8; see source schema for full shape
* current_generation ·
integer* current_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* current_route_record · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* service_kind ·
…recursion truncated at depth 8; see source schema for full shape
* method_history_evidence ·
…recursion truncated at depth 8; see source schema for full shape
* normalized_did_document ·
…recursion truncated at depth 8; see source schema for full shape
* realm_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* bundle_issued_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* current_assertion ·
$ref #/$defs/current_assertion · $ref #/$defs/current_assertionhistorical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_commit_signature.v1"enum:
"ak.realm_commit_signature.v1"* authority_transitions · array<$ref #/$defs/authority_transition>
items ·
$ref #/$defs/authority_transition · $ref #/$defs/authority_transition* current_generation ·
integer* current_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* current_route_record · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* service_kind ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$* method_history_evidence ·
$ref #/$defs/method_history_evidence · $ref #/$defs/method_history_evidence* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did ·
$ref #/$defs/did · $ref #/$defs/did* contexts · array<oneOf[2]>
items · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] ·
object* controller_dids · array<$ref #/$defs/did>
items ·
$ref #/$defs/did · $ref #/$defs/did* also_known_as · array<string>
items ·
stringCanonical URI validated by the DID resolver before projection; this array may contain non-network schemes such as acct: and therefore is not a URL field.
pattern:
^[A-Za-z][A-Za-z0-9+.-]*:[^\s]+$* verification_methods · array<$ref #/$defs/normalized_did_verification_method>
items ·
$ref #/$defs/normalized_did_verification_method · $ref #/$defs/normalized_did_verification_method* authentication ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* assertion_methods ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* key_agreements ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* capability_invocations ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* capability_delegations ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* services · array<$ref #/$defs/normalized_did_service>
items ·
$ref #/$defs/normalized_did_service · $ref #/$defs/normalized_did_service* metadata ·
$ref #/$defs/normalized_did_document_metadata · $ref #/$defs/normalized_did_document_metadata* extensions · array<$ref #/$defs/normalized_did_document_extension>
items ·
$ref #/$defs/normalized_did_document_extension · $ref #/$defs/normalized_did_document_extension* realm_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* bundle_issued_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* current_assertion ·
$ref #/$defs/current_assertion · $ref #/$defs/current_assertionhistorical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* stream_position ·
integer* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] · object · $ref #/$defs/human_historical_signer_fact
Minimal immutable original Human device signer source frozen in governance acceptance. Actual signing Account, independent authorization coordinates/revision/PCR tenure and source accepted time. No target CommitId/position, current permission, verified flag or private PCR bytes.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* actor · object · $ref ./signer-key-operations.schema.json#/$defs/signing_account_actor_id
Complete account ActorId of the exact verified signer, preserving its Station for either an ordinary device or Agent.
* kind ·
const "account"enum:
"account"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* verification_method ·
string (uri) · format=uripattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* key · object · $ref ./signer-key-operations.schema.json#/$defs/query_signing_key
Shared resolved key shape for existing current Agent and historical Agent/Human roles; each enclosing selector/outcome retains its own authority and source rules. Only new ordinary Human historical delivery uses original governance Commit-bound immutable facts. Independent original authorization coordinates/revision/PCR governance generation remain mandatory where the enclosing role requires them; no current fallback or new target source.
* public_key_b64u ·
stringCanonical unpadded base64url of exactly 32 Ed25519 public-key bytes; this is public material, not reusable current authorization.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* authorization_ref · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
integer* revision · object
Verified current revision of the authorization stream at resolution. The revision belongs to authorization_ref.stream_ref, is not older than authorization_ref.stream_position, and is never inferred from arrival order, a cursor or a current projection.
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* governance_generation ·
integerVerified governance generation of revision.commit_id.
* accepted_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[1] · object · $ref #/$defs/service_historical_signer_fact
Minimal immutable Applet Service producer source: original key, exact accepted registration epoch and installation authorization coordinates/scope. Frozen at target governance acceptance and bound by original Commit digest; no runtime completion, private Profile/control/history bodies or private signing material. This does not grant access to the source Events.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* actor · object · $ref ./signer-key-operations.schema.json#/$defs/signing_service_actor_id
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verification_method ·
string (uri) · format=uripattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* key · object · $ref ./signer-key-operations.schema.json#/$defs/service_historical_signing_key
* public_key_b64u ·
stringCanonical unpadded base64url of exactly 32 Ed25519 public-key bytes; this is public material, not reusable current authorization.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* applet_id ·
string · $ref ./common-ids.schema.json#/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* registration_epoch ·
string · $ref ./event-payload.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* registration_ref · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
integer* authorization_ref · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
integer* effective_scope · oneOf[4] · $ref ./event-envelope.schema.json#/$defs/scope_ref
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* circle_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* sidecar_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* accepted_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/authority-commit-operations.schema.json