跳转到内容

ak.schema.authority_commit_operations.v1

← Schemas

Arkret Authority Commit Operations
ak.schema.authority_commit_operations.v1 · file: schemas/authority-commit-operations.schema.json
* $ · oneOf[7]
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · $ref #/$defs/approval_signature_input · $ref #/$defs/approval_signature_input
* proof · $ref #/$defs/approval_signature_proof · $ref #/$defs/approval_signature_proof
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
kind · const "ak.mls.commit"
enum: "ak.mls.commit"
* welcomes · array<$ref ./mls-welcome-delivery.schema.json>
items · object · $ref ./mls-welcome-delivery.schema.json
Producer-signed recipient delivery queued atomically with its winning MLS Commit. This is not a shared Realm Event and does not receive an independent RealmCommit.
* welcome_id · string · $ref ./common-ids.schema.json#/$defs/mls_welcome_delivery_id
pattern: ^ak:mls_welcome_delivery:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* effective_scope · oneOf[4] · $ref ./event-envelope.schema.json#/$defs/scope_ref
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind · const "realm_genesis"
enum: "realm_genesis"
* commit_event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* recipient_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* recipient_endpoint · oneOf[2]
oneOf · oneOf[0] · object
* kind · const "device"
enum: "device"
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[1] · object
* kind · const "agent_runtime"
enum: "agent_runtime"
* verification_method · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* keypackage_claim_ref · string
pattern: ^ak:keypackage_claim:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* ciphertext_b64 · string
pattern: ^[A-Za-z0-9_-]+$
* producer_proof · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/mls_welcome_delivery_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · …
recursion truncated at depth 8; see source schema for full shape
approval_signatures · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · …
recursion truncated at depth 8; see source schema for full shape
* welcomes · …
recursion truncated at depth 8; see source schema for full shape
* idempotency_key · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status · …
recursion truncated at depth 8; see source schema for full shape
* commit · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status · …
recursion truncated at depth 8; see source schema for full shape
* reason_code · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
before_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* limit · integer
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · …
recursion truncated at depth 8; see source schema for full shape
* floor_commit_id · …
recursion truncated at depth 8; see source schema for full shape
* floor_reason · …
recursion truncated at depth 8; see source schema for full shape
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · …
recursion truncated at depth 8; see source schema for full shape
* floor_commit_id · …
recursion truncated at depth 8; see source schema for full shape
* floor_reason · …
recursion truncated at depth 8; see source schema for full shape
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* nonce · string
pattern: ^[A-Za-z0-9_-]{43}$
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] · ?
* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* from_generation · …
recursion truncated at depth 8; see source schema for full shape
* to_generation · …
recursion truncated at depth 8; see source schema for full shape
* from_service_id · …
recursion truncated at depth 8; see source schema for full shape
* to_service_id · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest · …
recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest · …
recursion truncated at depth 8; see source schema for full shape
* snapshot_ref · …
recursion truncated at depth 8; see source schema for full shape
* change_event_ref · …
recursion truncated at depth 8; see source schema for full shape
* change_commit_id · …
recursion truncated at depth 8; see source schema for full shape
* old_authority_signature · …
recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · …
recursion truncated at depth 8; see source schema for full shape
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* visible_stream_heads · …
recursion truncated at depth 8; see source schema for full shape
* current_state_entries · …
recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* genesis_event · …
recursion truncated at depth 8; see source schema for full shape
* genesis_commit · …
recursion truncated at depth 8; see source schema for full shape
* authority_transitions · …
recursion truncated at depth 8; see source schema for full shape
* current_generation · …
recursion truncated at depth 8; see source schema for full shape
* current_service_id · …
recursion truncated at depth 8; see source schema for full shape
* current_route_record · …
recursion truncated at depth 8; see source schema for full shape
* realm_stream_head · …
recursion truncated at depth 8; see source schema for full shape
* bundle_issued_at · …
recursion truncated at depth 8; see source schema for full shape
* current_assertion · …
recursion truncated at depth 8; see source schema for full shape
historical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.mls_welcome_delivery_signature.v1"
enum: "ak.mls_welcome_delivery_signature.v1"
* idempotency_key · string
pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status · string (enum)
enum: "committed" "duplicate"
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · null
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] · …
recursion truncated at depth 8; see source schema for full shape
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
realm_id · …
recursion truncated at depth 8; see source schema for full shape
* scope_ref · …
recursion truncated at depth 8; see source schema for full shape
* actor_id · …
recursion truncated at depth 8; see source schema for full shape
executed_by · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · …
recursion truncated at depth 8; see source schema for full shape
applet_id · …
recursion truncated at depth 8; see source schema for full shape
external_ref · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
semantic_refs · …
recursion truncated at depth 8; see source schema for full shape
* payload · …
recursion truncated at depth 8; see source schema for full shape
* producer_proof · …
recursion truncated at depth 8; see source schema for full shape
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · allOf[2]
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* welcomes · array<$ref ./mls-welcome-delivery.schema.json>
items · …
recursion truncated at depth 8; see source schema for full shape
* idempotency_key · string
pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status · string (enum)
enum: "committed" "duplicate"
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* authority_ref · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · …
recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status · string (enum)
enum: "rejected" "retryable_unavailable"
* reason_code · string
pattern: ^[a-z][a-z0-9_]{0,63}$
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* circle_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* sidecar_id · …
recursion truncated at depth 8; see source schema for full shape
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] · integer
oneOf · oneOf[1] · null
before_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] · integer
oneOf · oneOf[1] · null
* limit · integer
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · integer
Smallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* floor_reason · string (enum)
Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum: "stream_start" "membership_join" "history_access_policy"
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · integer
Smallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* floor_reason · string (enum)
Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum: "stream_start" "membership_join" "history_access_policy"
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* nonce · string
pattern: ^[A-Za-z0-9_-]{43}$
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] · ?
* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* from_generation · integer
* to_generation · integer
* from_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* to_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* final_stream_heads_digest · string · $ref ./event-envelope.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
historical_signer_facts_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
New handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern: ^sha256:[0-9a-f]{64}$
* snapshot_ref · string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_id
Content-addressed identity of an authority-signed typed Realm snapshot.
pattern: ^ak:realm_snapshot:[A-Za-z0-9_-]{44}$
* change_event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* change_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id · string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_id
Content-addressed identity of an authority-signed typed Realm snapshot.
pattern: ^ak:realm_snapshot:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Station tenure this snapshot is bound to. A consumer MUST refuse a snapshot whose generation is not the Realm's current governing Station tenure.
* visible_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
All and only the caller-visible stream heads at the same durable cut as current_state_entries and retention_and_history_floor; hidden Circle/Sidecar streams are not enumerated.
items · …
recursion truncated at depth 8; see source schema for full shape
* current_state_entries · array<$ref ./typed-current-result.schema.json>
Inline closed typed current results for the caller-visible streams at the same durable cut as visible_stream_heads. An empty array is not a placeholder for an unregistered chunk fetch and proves nothing about hidden streams.
items · …
recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor · object
Caller-authorized per-stream history floors and Realm history policy at the same durable cut as visible_stream_heads and current_state_entries; no floor for a hidden stream may be disclosed.
* history_access · …
recursion truncated at depth 8; see source schema for full shape
* stream_floors · …
recursion truncated at depth 8; see source schema for full shape
* created_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_snapshot_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* genesis_event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] · …
recursion truncated at depth 8; see source schema for full shape
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
realm_id · …
recursion truncated at depth 8; see source schema for full shape
* scope_ref · …
recursion truncated at depth 8; see source schema for full shape
* actor_id · …
recursion truncated at depth 8; see source schema for full shape
executed_by · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · …
recursion truncated at depth 8; see source schema for full shape
applet_id · …
recursion truncated at depth 8; see source schema for full shape
external_ref · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
semantic_refs · …
recursion truncated at depth 8; see source schema for full shape
* payload · …
recursion truncated at depth 8; see source schema for full shape
* producer_proof · …
recursion truncated at depth 8; see source schema for full shape
* genesis_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* authority_ref · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · …
recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
* authority_transitions · array<$ref #/$defs/authority_transition>
items · …
recursion truncated at depth 8; see source schema for full shape
* current_generation · integer
* current_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* current_route_record · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id · …
recursion truncated at depth 8; see source schema for full shape
* service_kind · …
recursion truncated at depth 8; see source schema for full shape
* method_history_evidence · …
recursion truncated at depth 8; see source schema for full shape
* normalized_did_document · …
recursion truncated at depth 8; see source schema for full shape
* realm_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* bundle_issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* current_assertion · $ref #/$defs/current_assertion · $ref #/$defs/current_assertion
historical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.realm_commit_signature.v1"
enum: "ak.realm_commit_signature.v1"
oneOf · oneOf[1] · object
* status · string (enum)
enum: "rejected" "retryable_unavailable"
* reason_code · string
pattern: ^[a-z][a-z0-9_]{0,63}$
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] · integer
oneOf · oneOf[1] · null
before_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] · integer
oneOf · oneOf[1] · null
* limit · integer
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · null
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
after_position · …
recursion truncated at depth 8; see source schema for full shape
before_position · …
recursion truncated at depth 8; see source schema for full shape
* limit · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · …
recursion truncated at depth 8; see source schema for full shape
* truncated · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · …
recursion truncated at depth 8; see source schema for full shape
* truncated · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_facts · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* nonce · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* handoff · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · …
recursion truncated at depth 8; see source schema for full shape
* snapshot · …
recursion truncated at depth 8; see source schema for full shape
* authority_bundle · …
recursion truncated at depth 8; see source schema for full shape
historical_signer_facts · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.realm_commit_signature.v1"
enum: "ak.realm_commit_signature.v1"
* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · …
recursion truncated at depth 8; see source schema for full shape
approval_signatures · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · …
recursion truncated at depth 8; see source schema for full shape
* welcomes · …
recursion truncated at depth 8; see source schema for full shape
* idempotency_key · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status · …
recursion truncated at depth 8; see source schema for full shape
* commit · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status · …
recursion truncated at depth 8; see source schema for full shape
* reason_code · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
before_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* limit · integer
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · …
recursion truncated at depth 8; see source schema for full shape
* floor_commit_id · …
recursion truncated at depth 8; see source schema for full shape
* floor_reason · …
recursion truncated at depth 8; see source schema for full shape
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · …
recursion truncated at depth 8; see source schema for full shape
* floor_commit_id · …
recursion truncated at depth 8; see source schema for full shape
* floor_reason · …
recursion truncated at depth 8; see source schema for full shape
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* nonce · string
pattern: ^[A-Za-z0-9_-]{43}$
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] · ?
* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* from_generation · …
recursion truncated at depth 8; see source schema for full shape
* to_generation · …
recursion truncated at depth 8; see source schema for full shape
* from_service_id · …
recursion truncated at depth 8; see source schema for full shape
* to_service_id · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest · …
recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest · …
recursion truncated at depth 8; see source schema for full shape
* snapshot_ref · …
recursion truncated at depth 8; see source schema for full shape
* change_event_ref · …
recursion truncated at depth 8; see source schema for full shape
* change_commit_id · …
recursion truncated at depth 8; see source schema for full shape
* old_authority_signature · …
recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · …
recursion truncated at depth 8; see source schema for full shape
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* visible_stream_heads · …
recursion truncated at depth 8; see source schema for full shape
* current_state_entries · …
recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* genesis_event · …
recursion truncated at depth 8; see source schema for full shape
* genesis_commit · …
recursion truncated at depth 8; see source schema for full shape
* authority_transitions · …
recursion truncated at depth 8; see source schema for full shape
* current_generation · …
recursion truncated at depth 8; see source schema for full shape
* current_service_id · …
recursion truncated at depth 8; see source schema for full shape
* current_route_record · …
recursion truncated at depth 8; see source schema for full shape
* realm_stream_head · …
recursion truncated at depth 8; see source schema for full shape
* bundle_issued_at · …
recursion truncated at depth 8; see source schema for full shape
* current_assertion · …
recursion truncated at depth 8; see source schema for full shape
historical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind · string (enum)
enum: "ak.agent.action_approve" "ak.agent.interaction.set" "ak.agent.key.authorize" "ak.agent.key.revoke" "ak.agent.provision" "ak.agent.sidecar.exchange.control" "ak.applet.bridge_error" "ak.applet.discovery" "ak.applet.managed_actor.provision" "ak.applet.registration" "ak.audit.accessed" "ak.audit.erasure_receipt" "ak.call.create" "ak.call.recording.start" "ak.call.state" "ak.capability.grant" "ak.capability.relinquish" "ak.capability.revoke" "ak.circle.archive" "ak.circle.create" "ak.circle.history_access" "ak.circle.member.state" "ak.circle.restore" "ak.circle.tombstone" "ak.circle.update" "ak.consent.grant" "ak.consent.revoke" "ak.contact.accepted" "ak.contact.rejected" "ak.contact.requested" "ak.contact.scope.update" "ak.contact.tombstone" "ak.device.authorize" "ak.device.reanchor" "ak.device.revoke" "ak.direct_conversation.bound" "ak.identity.accountability_grant" "ak.identity.resolution.update" "ak.invite.accept" "ak.invite.cancel" "ak.invite.claim" "ak.invite.create" "ak.invite.revoke" "ak.invite.third_party" "ak.key_backup.active_series" "ak.member.identity.update" "ak.member.state" "ak.message.create" "ak.message.redact" "ak.message.revise" "ak.mimi.room_binding" "ak.mls.commit" "ak.mls.genesis" "ak.moderation.decision" "ak.moderation.decision.lift" "ak.moderation.franking_proof" "ak.morph.archive" "ak.morph.create" "ak.morph.restore" "ak.morph.stage.set" "ak.morph.update" "ak.organization.moderation_policy" "ak.pin.add" "ak.pin.remove" "ak.pin.reorder" "ak.policy.action" "ak.policy.set" "ak.profile.create" "ak.profile.realm_override" "ak.profile.update" "ak.reaction.add" "ak.reaction.remove" "ak.realm.alias" "ak.realm.archive" "ak.realm.asset_privacy_policy" "ak.realm.authority.reset" "ak.realm.create" "ak.realm.destroy" "ak.realm.discovery" "ak.realm.freeze" "ak.realm.governance_station.change" "ak.realm.history_access" "ak.realm.join_rule" "ak.realm.link" "ak.realm.media_service" "ak.realm.organization" "ak.realm.owner.transfer" "ak.realm.plaintext_visible_services" "ak.realm.policy_bundle" "ak.realm.preview_policy" "ak.realm.profile" "ak.realm.read_receipt_policy" "ak.realm.restore" "ak.realm.schema" "ak.realm.search_policy" "ak.realm.set_default_strand" "ak.realm.tombstone" "ak.realm.unfreeze" "ak.redaction" "ak.relation.create" "ak.relation.tombstone" "ak.relation.update" "ak.rsvp.set" "ak.schema.define" "ak.self.agent.deactivate" "ak.self.agent.pause" "ak.self.agent.resume" "ak.self.moderation.report" "ak.sidecar.context.attach" "ak.sidecar.create" "ak.space.archive" "ak.space.create" "ak.space.parent" "ak.space.restore" "ak.space.tombstone" "ak.space.update" "ak.strand.archive" "ak.strand.create" "ak.strand.move" "ak.strand.reorder" "ak.strand.restore" "ak.strand.stage.set" "ak.strand.tracks.update" "ak.strand.update" "ak.strand.watch.set" "ak.view.create" "ak.view.reconcile" "ak.view.update"
oneOf · oneOf[1] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · null
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
after_position · …
recursion truncated at depth 8; see source schema for full shape
before_position · …
recursion truncated at depth 8; see source schema for full shape
* limit · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · …
recursion truncated at depth 8; see source schema for full shape
* truncated · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · …
recursion truncated at depth 8; see source schema for full shape
* truncated · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_facts · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* nonce · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* handoff · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · …
recursion truncated at depth 8; see source schema for full shape
* snapshot · …
recursion truncated at depth 8; see source schema for full shape
* authority_bundle · …
recursion truncated at depth 8; see source schema for full shape
historical_signer_facts · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.realm_commit_signature.v1"
enum: "ak.realm_commit_signature.v1"
* event_disclosure · $ref #/$defs/EventDisclosure · $ref #/$defs/EventDisclosure
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · integer
Smallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* floor_reason · string (enum)
Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum: "stream_start" "membership_join" "history_access_policy"
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · null
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
after_position · …
recursion truncated at depth 8; see source schema for full shape
before_position · …
recursion truncated at depth 8; see source schema for full shape
* limit · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · …
recursion truncated at depth 8; see source schema for full shape
* truncated · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · …
recursion truncated at depth 8; see source schema for full shape
* truncated · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_facts · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* nonce · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* handoff · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · …
recursion truncated at depth 8; see source schema for full shape
* snapshot · …
recursion truncated at depth 8; see source schema for full shape
* authority_bundle · …
recursion truncated at depth 8; see source schema for full shape
historical_signer_facts · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.realm_commit_signature.v1"
enum: "ak.realm_commit_signature.v1"
* event · allOf[2] · $ref ./event-envelope.schema.json#/$defs/shared_event_envelope
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · …
recursion truncated at depth 8; see source schema for full shape
approval_signatures · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · …
recursion truncated at depth 8; see source schema for full shape
* welcomes · …
recursion truncated at depth 8; see source schema for full shape
* idempotency_key · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status · …
recursion truncated at depth 8; see source schema for full shape
* commit · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status · …
recursion truncated at depth 8; see source schema for full shape
* reason_code · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
before_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* limit · integer
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · …
recursion truncated at depth 8; see source schema for full shape
* floor_commit_id · …
recursion truncated at depth 8; see source schema for full shape
* floor_reason · …
recursion truncated at depth 8; see source schema for full shape
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · …
recursion truncated at depth 8; see source schema for full shape
* floor_commit_id · …
recursion truncated at depth 8; see source schema for full shape
* floor_reason · …
recursion truncated at depth 8; see source schema for full shape
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* nonce · string
pattern: ^[A-Za-z0-9_-]{43}$
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] · ?
* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* from_generation · …
recursion truncated at depth 8; see source schema for full shape
* to_generation · …
recursion truncated at depth 8; see source schema for full shape
* from_service_id · …
recursion truncated at depth 8; see source schema for full shape
* to_service_id · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest · …
recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest · …
recursion truncated at depth 8; see source schema for full shape
* snapshot_ref · …
recursion truncated at depth 8; see source schema for full shape
* change_event_ref · …
recursion truncated at depth 8; see source schema for full shape
* change_commit_id · …
recursion truncated at depth 8; see source schema for full shape
* old_authority_signature · …
recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · …
recursion truncated at depth 8; see source schema for full shape
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* visible_stream_heads · …
recursion truncated at depth 8; see source schema for full shape
* current_state_entries · …
recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* genesis_event · …
recursion truncated at depth 8; see source schema for full shape
* genesis_commit · …
recursion truncated at depth 8; see source schema for full shape
* authority_transitions · …
recursion truncated at depth 8; see source schema for full shape
* current_generation · …
recursion truncated at depth 8; see source schema for full shape
* current_service_id · …
recursion truncated at depth 8; see source schema for full shape
* current_route_record · …
recursion truncated at depth 8; see source schema for full shape
* realm_stream_head · …
recursion truncated at depth 8; see source schema for full shape
* bundle_issued_at · …
recursion truncated at depth 8; see source schema for full shape
* current_assertion · …
recursion truncated at depth 8; see source schema for full shape
historical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind · string (enum)
enum: "ak.agent.action_approve" "ak.agent.interaction.set" "ak.agent.key.authorize" "ak.agent.key.revoke" "ak.agent.provision" "ak.agent.sidecar.exchange.control" "ak.applet.bridge_error" "ak.applet.discovery" "ak.applet.managed_actor.provision" "ak.applet.registration" "ak.audit.accessed" "ak.audit.erasure_receipt" "ak.call.create" "ak.call.recording.start" "ak.call.state" "ak.capability.grant" "ak.capability.relinquish" "ak.capability.revoke" "ak.circle.archive" "ak.circle.create" "ak.circle.history_access" "ak.circle.member.state" "ak.circle.restore" "ak.circle.tombstone" "ak.circle.update" "ak.consent.grant" "ak.consent.revoke" "ak.contact.accepted" "ak.contact.rejected" "ak.contact.requested" "ak.contact.scope.update" "ak.contact.tombstone" "ak.device.authorize" "ak.device.reanchor" "ak.device.revoke" "ak.direct_conversation.bound" "ak.identity.accountability_grant" "ak.identity.resolution.update" "ak.invite.accept" "ak.invite.cancel" "ak.invite.claim" "ak.invite.create" "ak.invite.revoke" "ak.invite.third_party" "ak.key_backup.active_series" "ak.member.identity.update" "ak.member.state" "ak.message.create" "ak.message.redact" "ak.message.revise" "ak.mimi.room_binding" "ak.mls.commit" "ak.mls.genesis" "ak.moderation.decision" "ak.moderation.decision.lift" "ak.moderation.franking_proof" "ak.morph.archive" "ak.morph.create" "ak.morph.restore" "ak.morph.stage.set" "ak.morph.update" "ak.organization.moderation_policy" "ak.pin.add" "ak.pin.remove" "ak.pin.reorder" "ak.policy.action" "ak.policy.set" "ak.profile.create" "ak.profile.realm_override" "ak.profile.update" "ak.reaction.add" "ak.reaction.remove" "ak.realm.alias" "ak.realm.archive" "ak.realm.asset_privacy_policy" "ak.realm.authority.reset" "ak.realm.create" "ak.realm.destroy" "ak.realm.discovery" "ak.realm.freeze" "ak.realm.governance_station.change" "ak.realm.history_access" "ak.realm.join_rule" "ak.realm.link" "ak.realm.media_service" "ak.realm.organization" "ak.realm.owner.transfer" "ak.realm.plaintext_visible_services" "ak.realm.policy_bundle" "ak.realm.preview_policy" "ak.realm.profile" "ak.realm.read_receipt_policy" "ak.realm.restore" "ak.realm.schema" "ak.realm.search_policy" "ak.realm.set_default_strand" "ak.realm.tombstone" "ak.realm.unfreeze" "ak.redaction" "ak.relation.create" "ak.relation.tombstone" "ak.relation.update" "ak.rsvp.set" "ak.schema.define" "ak.self.agent.deactivate" "ak.self.agent.pause" "ak.self.agent.resume" "ak.self.moderation.report" "ak.sidecar.context.attach" "ak.sidecar.create" "ak.space.archive" "ak.space.create" "ak.space.parent" "ak.space.restore" "ak.space.tombstone" "ak.space.update" "ak.strand.archive" "ak.strand.create" "ak.strand.move" "ak.strand.reorder" "ak.strand.restore" "ak.strand.stage.set" "ak.strand.tracks.update" "ak.strand.update" "ak.strand.watch.set" "ak.view.create" "ak.view.reconcile" "ak.view.update"
oneOf · oneOf[1] · object
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · null
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
after_position · …
recursion truncated at depth 8; see source schema for full shape
before_position · …
recursion truncated at depth 8; see source schema for full shape
* limit · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · …
recursion truncated at depth 8; see source schema for full shape
* truncated · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · …
recursion truncated at depth 8; see source schema for full shape
* truncated · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_facts · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* nonce · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* handoff · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · …
recursion truncated at depth 8; see source schema for full shape
* snapshot · …
recursion truncated at depth 8; see source schema for full shape
* authority_bundle · …
recursion truncated at depth 8; see source schema for full shape
historical_signer_facts · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.realm_commit_signature.v1"
enum: "ak.realm_commit_signature.v1"
* event_disclosure · $ref #/$defs/EventDisclosure · $ref #/$defs/EventDisclosure
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · integer
Smallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* floor_reason · string (enum)
Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum: "stream_start" "membership_join" "history_access_policy"
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* stream_position · integer
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] · object · $ref #/$defs/human_historical_signer_fact
Minimal immutable original Human device signer source frozen in governance acceptance. Actual signing Account, independent authorization coordinates/revision/PCR tenure and source accepted time. No target CommitId/position, current permission, verified flag or private PCR bytes.
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* actor · object · $ref ./signer-key-operations.schema.json#/$defs/signing_account_actor_id
Complete account ActorId of the exact verified signer, preserving its Station for either an ordinary device or Agent.
* kind · const "account"
enum: "account"
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* verification_method · string (uri) · format=uri
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* key · object · $ref ./signer-key-operations.schema.json#/$defs/query_signing_key
Shared resolved key shape for existing current Agent and historical Agent/Human roles; each enclosing selector/outcome retains its own authority and source rules. Only new ordinary Human historical delivery uses original governance Commit-bound immutable facts. Independent original authorization coordinates/revision/PCR governance generation remain mandatory where the enclosing role requires them; no current fallback or new target source.
* public_key_b64u · string
Canonical unpadded base64url of exactly 32 Ed25519 public-key bytes; this is public material, not reusable current authorization.
pattern: ^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$
* authorization_ref · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · integer
* revision · object
Verified current revision of the authorization stream at resolution. The revision belongs to authorization_ref.stream_ref, is not older than authorization_ref.stream_position, and is never inferred from arrival order, a cursor or a current projection.
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* stream_position · integer
* governance_generation · integer
Verified governance generation of revision.commit_id.
* accepted_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
oneOf · oneOf[1] · object · $ref #/$defs/service_historical_signer_fact
Minimal immutable Applet Service producer source: original key, exact accepted registration epoch and installation authorization coordinates/scope. Frozen at target governance acceptance and bound by original Commit digest; no runtime completion, private Profile/control/history bodies or private signing material. This does not grant access to the source Events.
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* actor · object · $ref ./signer-key-operations.schema.json#/$defs/signing_service_actor_id
* kind · const "service"
enum: "service"
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* verification_method · string (uri) · format=uri
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* key · object · $ref ./signer-key-operations.schema.json#/$defs/service_historical_signing_key
* public_key_b64u · string
Canonical unpadded base64url of exactly 32 Ed25519 public-key bytes; this is public material, not reusable current authorization.
pattern: ^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$
* applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* registration_epoch · string · $ref ./event-payload.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* registration_ref · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · integer
* authorization_ref · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · integer
* effective_scope · oneOf[4] · $ref ./event-envelope.schema.json#/$defs/scope_ref
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* circle_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* sidecar_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* accepted_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* nonce · string
pattern: ^[A-Za-z0-9_-]{43}$
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] · ?
* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* from_generation · integer
* to_generation · integer
* from_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* to_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* final_stream_heads_digest · string · $ref ./event-envelope.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
historical_signer_facts_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
New handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern: ^sha256:[0-9a-f]{64}$
* snapshot_ref · string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_id
Content-addressed identity of an authority-signed typed Realm snapshot.
pattern: ^ak:realm_snapshot:[A-Za-z0-9_-]{44}$
* change_event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* change_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · …
recursion truncated at depth 8; see source schema for full shape
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · …
recursion truncated at depth 8; see source schema for full shape
* proof · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] · …
recursion truncated at depth 8; see source schema for full shape
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
realm_id · …
recursion truncated at depth 8; see source schema for full shape
* scope_ref · …
recursion truncated at depth 8; see source schema for full shape
* actor_id · …
recursion truncated at depth 8; see source schema for full shape
executed_by · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · …
recursion truncated at depth 8; see source schema for full shape
applet_id · …
recursion truncated at depth 8; see source schema for full shape
external_ref · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
semantic_refs · …
recursion truncated at depth 8; see source schema for full shape
* payload · …
recursion truncated at depth 8; see source schema for full shape
* producer_proof · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
kind · …
recursion truncated at depth 8; see source schema for full shape
* welcomes · array<$ref ./mls-welcome-delivery.schema.json>
items · object · $ref ./mls-welcome-delivery.schema.json
Producer-signed recipient delivery queued atomically with its winning MLS Commit. This is not a shared Realm Event and does not receive an independent RealmCommit.
* welcome_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* effective_scope · …
recursion truncated at depth 8; see source schema for full shape
* commit_event_ref · …
recursion truncated at depth 8; see source schema for full shape
* recipient_actor_id · …
recursion truncated at depth 8; see source schema for full shape
* recipient_endpoint · …
recursion truncated at depth 8; see source schema for full shape
* keypackage_claim_ref · …
recursion truncated at depth 8; see source schema for full shape
* ciphertext_b64 · …
recursion truncated at depth 8; see source schema for full shape
* producer_proof · …
recursion truncated at depth 8; see source schema for full shape
* idempotency_key · string
pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status · string (enum)
enum: "committed" "duplicate"
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status · string (enum)
enum: "rejected" "retryable_unavailable"
* reason_code · string
pattern: ^[a-z][a-z0-9_]{0,63}$
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] · integer
oneOf · oneOf[1] · null
before_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] · integer
oneOf · oneOf[1] · null
* limit · integer
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event_disclosure · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · integer
Smallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* floor_reason · string (enum)
Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum: "stream_start" "membership_join" "history_access_policy"
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event_disclosure · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · integer
Smallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* floor_reason · string (enum)
Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum: "stream_start" "membership_join" "history_access_policy"
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* nonce · string
pattern: ^[A-Za-z0-9_-]{43}$
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] · ?
* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* from_generation · integer
* to_generation · integer
* from_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* to_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* final_stream_heads_digest · string · $ref ./event-envelope.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
historical_signer_facts_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
New handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern: ^sha256:[0-9a-f]{64}$
* snapshot_ref · string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_id
Content-addressed identity of an authority-signed typed Realm snapshot.
pattern: ^ak:realm_snapshot:[A-Za-z0-9_-]{44}$
* change_event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* change_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · …
recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id · string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_id
Content-addressed identity of an authority-signed typed Realm snapshot.
pattern: ^ak:realm_snapshot:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Station tenure this snapshot is bound to. A consumer MUST refuse a snapshot whose generation is not the Realm's current governing Station tenure.
* visible_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
All and only the caller-visible stream heads at the same durable cut as current_state_entries and retention_and_history_floor; hidden Circle/Sidecar streams are not enumerated.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* current_state_entries · array<$ref ./typed-current-result.schema.json>
Inline closed typed current results for the caller-visible streams at the same durable cut as visible_stream_heads. An empty array is not a placeholder for an unregistered chunk fetch and proves nothing about hidden streams.
items · oneOf[85] · $ref ./typed-current-result.schema.json
Closed domain result selected without protocol typed current result IDs. Every result names the last authority commit that affected the typed target.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[7] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[8] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[9] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[10] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[11] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[12] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[13] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[14] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[15] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[16] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[17] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[18] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[19] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[20] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[21] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[22] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[23] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[24] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[25] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[26] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[27] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[28] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[29] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[30] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[31] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[32] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[33] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[34] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[35] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[36] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[37] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[38] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[39] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[40] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[41] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[42] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[43] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[44] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[45] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[46] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[47] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[48] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[49] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[50] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[51] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[52] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[53] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[54] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[55] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[56] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[57] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[58] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[59] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[60] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[61] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[62] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[63] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[64] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[65] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[66] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[67] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[68] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[69] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[70] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[71] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[72] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[73] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[74] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[75] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[76] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[77] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[78] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[79] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[80] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[81] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[82] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[83] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[84] · …
recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor · object
Caller-authorized per-stream history floors and Realm history policy at the same durable cut as visible_stream_heads and current_state_entries; no floor for a hidden stream may be disclosed.
* history_access · string (enum)
enum: "since_join" "all_history_for_current_members"
* stream_floors · array<object>
items · …
recursion truncated at depth 8; see source schema for full shape
* created_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_snapshot_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · …
recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* genesis_event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · …
recursion truncated at depth 8; see source schema for full shape
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
* genesis_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* authority_transitions · array<$ref #/$defs/authority_transition>
items · $ref #/$defs/authority_transition · $ref #/$defs/authority_transition
* current_generation · integer
* current_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* current_route_record · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* service_kind · string
pattern: ^[a-z][a-z0-9_]{0,63}$
* method_history_evidence · $ref #/$defs/method_history_evidence · $ref #/$defs/method_history_evidence
* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did · …
recursion truncated at depth 8; see source schema for full shape
* contexts · …
recursion truncated at depth 8; see source schema for full shape
* controller_dids · …
recursion truncated at depth 8; see source schema for full shape
* also_known_as · …
recursion truncated at depth 8; see source schema for full shape
* verification_methods · …
recursion truncated at depth 8; see source schema for full shape
* authentication · …
recursion truncated at depth 8; see source schema for full shape
* assertion_methods · …
recursion truncated at depth 8; see source schema for full shape
* key_agreements · …
recursion truncated at depth 8; see source schema for full shape
* capability_invocations · …
recursion truncated at depth 8; see source schema for full shape
* capability_delegations · …
recursion truncated at depth 8; see source schema for full shape
* services · …
recursion truncated at depth 8; see source schema for full shape
* metadata · …
recursion truncated at depth 8; see source schema for full shape
* extensions · …
recursion truncated at depth 8; see source schema for full shape
* realm_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* bundle_issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* current_assertion · $ref #/$defs/current_assertion · $ref #/$defs/current_assertion
historical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.realm_authority_handoff_old_signature.v1"
enum: "ak.realm_authority_handoff_old_signature.v1"
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · …
recursion truncated at depth 8; see source schema for full shape
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · …
recursion truncated at depth 8; see source schema for full shape
* proof · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] · …
recursion truncated at depth 8; see source schema for full shape
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
realm_id · …
recursion truncated at depth 8; see source schema for full shape
* scope_ref · …
recursion truncated at depth 8; see source schema for full shape
* actor_id · …
recursion truncated at depth 8; see source schema for full shape
executed_by · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · …
recursion truncated at depth 8; see source schema for full shape
applet_id · …
recursion truncated at depth 8; see source schema for full shape
external_ref · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
semantic_refs · …
recursion truncated at depth 8; see source schema for full shape
* payload · …
recursion truncated at depth 8; see source schema for full shape
* producer_proof · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
kind · …
recursion truncated at depth 8; see source schema for full shape
* welcomes · array<$ref ./mls-welcome-delivery.schema.json>
items · object · $ref ./mls-welcome-delivery.schema.json
Producer-signed recipient delivery queued atomically with its winning MLS Commit. This is not a shared Realm Event and does not receive an independent RealmCommit.
* welcome_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* effective_scope · …
recursion truncated at depth 8; see source schema for full shape
* commit_event_ref · …
recursion truncated at depth 8; see source schema for full shape
* recipient_actor_id · …
recursion truncated at depth 8; see source schema for full shape
* recipient_endpoint · …
recursion truncated at depth 8; see source schema for full shape
* keypackage_claim_ref · …
recursion truncated at depth 8; see source schema for full shape
* ciphertext_b64 · …
recursion truncated at depth 8; see source schema for full shape
* producer_proof · …
recursion truncated at depth 8; see source schema for full shape
* idempotency_key · string
pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status · string (enum)
enum: "committed" "duplicate"
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status · string (enum)
enum: "rejected" "retryable_unavailable"
* reason_code · string
pattern: ^[a-z][a-z0-9_]{0,63}$
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] · integer
oneOf · oneOf[1] · null
before_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] · integer
oneOf · oneOf[1] · null
* limit · integer
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event_disclosure · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · integer
Smallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* floor_reason · string (enum)
Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum: "stream_start" "membership_join" "history_access_policy"
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event_disclosure · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · integer
Smallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* floor_reason · string (enum)
Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum: "stream_start" "membership_join" "history_access_policy"
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* nonce · string
pattern: ^[A-Za-z0-9_-]{43}$
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] · ?
* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* from_generation · integer
* to_generation · integer
* from_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* to_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* final_stream_heads_digest · string · $ref ./event-envelope.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
historical_signer_facts_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
New handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern: ^sha256:[0-9a-f]{64}$
* snapshot_ref · string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_id
Content-addressed identity of an authority-signed typed Realm snapshot.
pattern: ^ak:realm_snapshot:[A-Za-z0-9_-]{44}$
* change_event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* change_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · …
recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id · string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_id
Content-addressed identity of an authority-signed typed Realm snapshot.
pattern: ^ak:realm_snapshot:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Station tenure this snapshot is bound to. A consumer MUST refuse a snapshot whose generation is not the Realm's current governing Station tenure.
* visible_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
All and only the caller-visible stream heads at the same durable cut as current_state_entries and retention_and_history_floor; hidden Circle/Sidecar streams are not enumerated.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* current_state_entries · array<$ref ./typed-current-result.schema.json>
Inline closed typed current results for the caller-visible streams at the same durable cut as visible_stream_heads. An empty array is not a placeholder for an unregistered chunk fetch and proves nothing about hidden streams.
items · oneOf[85] · $ref ./typed-current-result.schema.json
Closed domain result selected without protocol typed current result IDs. Every result names the last authority commit that affected the typed target.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[7] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[8] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[9] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[10] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[11] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[12] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[13] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[14] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[15] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[16] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[17] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[18] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[19] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[20] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[21] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[22] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[23] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[24] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[25] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[26] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[27] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[28] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[29] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[30] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[31] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[32] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[33] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[34] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[35] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[36] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[37] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[38] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[39] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[40] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[41] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[42] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[43] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[44] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[45] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[46] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[47] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[48] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[49] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[50] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[51] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[52] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[53] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[54] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[55] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[56] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[57] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[58] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[59] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[60] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[61] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[62] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[63] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[64] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[65] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[66] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[67] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[68] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[69] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[70] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[71] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[72] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[73] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[74] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[75] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[76] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[77] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[78] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[79] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[80] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[81] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[82] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[83] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[84] · …
recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor · object
Caller-authorized per-stream history floors and Realm history policy at the same durable cut as visible_stream_heads and current_state_entries; no floor for a hidden stream may be disclosed.
* history_access · string (enum)
enum: "since_join" "all_history_for_current_members"
* stream_floors · array<object>
items · …
recursion truncated at depth 8; see source schema for full shape
* created_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_snapshot_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · …
recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* genesis_event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · …
recursion truncated at depth 8; see source schema for full shape
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
* genesis_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* authority_transitions · array<$ref #/$defs/authority_transition>
items · $ref #/$defs/authority_transition · $ref #/$defs/authority_transition
* current_generation · integer
* current_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* current_route_record · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* service_kind · string
pattern: ^[a-z][a-z0-9_]{0,63}$
* method_history_evidence · $ref #/$defs/method_history_evidence · $ref #/$defs/method_history_evidence
* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did · …
recursion truncated at depth 8; see source schema for full shape
* contexts · …
recursion truncated at depth 8; see source schema for full shape
* controller_dids · …
recursion truncated at depth 8; see source schema for full shape
* also_known_as · …
recursion truncated at depth 8; see source schema for full shape
* verification_methods · …
recursion truncated at depth 8; see source schema for full shape
* authentication · …
recursion truncated at depth 8; see source schema for full shape
* assertion_methods · …
recursion truncated at depth 8; see source schema for full shape
* key_agreements · …
recursion truncated at depth 8; see source schema for full shape
* capability_invocations · …
recursion truncated at depth 8; see source schema for full shape
* capability_delegations · …
recursion truncated at depth 8; see source schema for full shape
* services · …
recursion truncated at depth 8; see source schema for full shape
* metadata · …
recursion truncated at depth 8; see source schema for full shape
* extensions · …
recursion truncated at depth 8; see source schema for full shape
* realm_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* bundle_issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* current_assertion · $ref #/$defs/current_assertion · $ref #/$defs/current_assertion
historical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.realm_authority_handoff_new_acceptance_signature.v1"
enum: "ak.realm_authority_handoff_new_acceptance_signature.v1"
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id · string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_id
Content-addressed identity of an authority-signed typed Realm snapshot.
pattern: ^ak:realm_snapshot:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Station tenure this snapshot is bound to. A consumer MUST refuse a snapshot whose generation is not the Realm's current governing Station tenure.
* visible_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
All and only the caller-visible stream heads at the same durable cut as current_state_entries and retention_and_history_floor; hidden Circle/Sidecar streams are not enumerated.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* current_state_entries · array<$ref ./typed-current-result.schema.json>
Inline closed typed current results for the caller-visible streams at the same durable cut as visible_stream_heads. An empty array is not a placeholder for an unregistered chunk fetch and proves nothing about hidden streams.
items · oneOf[85] · $ref ./typed-current-result.schema.json
Closed domain result selected without protocol typed current result IDs. Every result names the last authority commit that affected the typed target.
oneOf · oneOf[0] · $ref #/$defs/agent_interaction_result · $ref #/$defs/agent_interaction_result
oneOf · oneOf[1] · $ref #/$defs/realm_authority_root_result · $ref #/$defs/realm_authority_root_result
oneOf · oneOf[2] · $ref #/$defs/realm_profile_result · $ref #/$defs/realm_profile_result
oneOf · oneOf[3] · $ref #/$defs/member_state_result · $ref #/$defs/member_state_result
oneOf · oneOf[4] · $ref #/$defs/strand_result · $ref #/$defs/strand_result
oneOf · oneOf[5] · $ref #/$defs/space_result · $ref #/$defs/space_result
oneOf · oneOf[6] · $ref #/$defs/message_reactions_result · $ref #/$defs/message_reactions_result
oneOf · oneOf[7] · $ref #/$defs/relation_result · $ref #/$defs/relation_result
oneOf · oneOf[8] · $ref #/$defs/mls_group_result · $ref #/$defs/mls_group_result
oneOf · oneOf[9] · $ref #/$defs/agent_key_result · $ref #/$defs/agent_key_result
oneOf · oneOf[10] · $ref #/$defs/agent_status_result · $ref #/$defs/agent_status_result
oneOf · oneOf[11] · $ref #/$defs/realm_genesis_result · $ref #/$defs/realm_genesis_result
oneOf · oneOf[12] · $ref #/$defs/realm_history_access_result · $ref #/$defs/realm_history_access_result
oneOf · oneOf[13] · $ref #/$defs/identity_resolution_result · $ref #/$defs/identity_resolution_result
oneOf · oneOf[14] · $ref #/$defs/identity_accountability_result · $ref #/$defs/identity_accountability_result
oneOf · oneOf[15] · $ref #/$defs/capability_grant_result · $ref #/$defs/capability_grant_result
oneOf · oneOf[16] · $ref #/$defs/call_state_result · $ref #/$defs/call_state_result
oneOf · oneOf[17] · $ref #/$defs/call_focus_result · $ref #/$defs/call_focus_result
oneOf · oneOf[18] · $ref #/$defs/call_recording_state_result · $ref #/$defs/call_recording_state_result
oneOf · oneOf[19] · $ref #/$defs/call_recording_artifact_result · $ref #/$defs/call_recording_artifact_result
oneOf · oneOf[20] · $ref #/$defs/call_transcript_state_result · $ref #/$defs/call_transcript_state_result
oneOf · oneOf[21] · $ref #/$defs/call_transcript_artifact_result · $ref #/$defs/call_transcript_artifact_result
oneOf · oneOf[22] · $ref #/$defs/call_moderation_result · $ref #/$defs/call_moderation_result
oneOf · oneOf[23] · $ref #/$defs/call_roster_result · $ref #/$defs/call_roster_result
oneOf · oneOf[24] · $ref #/$defs/call_mute_override_result · $ref #/$defs/call_mute_override_result
oneOf · oneOf[25] · $ref #/$defs/realm_schema_result · $ref #/$defs/realm_schema_result
oneOf · oneOf[26] · $ref #/$defs/realm_link_result · $ref #/$defs/realm_link_result
oneOf · oneOf[27] · $ref #/$defs/realm_join_rule_result · $ref #/$defs/realm_join_rule_result
oneOf · oneOf[28] · $ref #/$defs/realm_discovery_result · $ref #/$defs/realm_discovery_result
oneOf · oneOf[29] · $ref #/$defs/realm_alias_result · $ref #/$defs/realm_alias_result
oneOf · oneOf[30] · $ref #/$defs/realm_policy_bundle_result · $ref #/$defs/realm_policy_bundle_result
oneOf · oneOf[31] · $ref #/$defs/realm_asset_privacy_policy_result · $ref #/$defs/realm_asset_privacy_policy_result
oneOf · oneOf[32] · $ref #/$defs/realm_plaintext_visible_services_result · $ref #/$defs/realm_plaintext_visible_services_result
oneOf · oneOf[33] · $ref #/$defs/realm_media_service_result · $ref #/$defs/realm_media_service_result
oneOf · oneOf[34] · $ref #/$defs/realm_read_receipt_policy_result · $ref #/$defs/realm_read_receipt_policy_result
oneOf · oneOf[35] · $ref #/$defs/realm_preview_policy_result · $ref #/$defs/realm_preview_policy_result
oneOf · oneOf[36] · $ref #/$defs/mimi_room_binding_result · $ref #/$defs/mimi_room_binding_result
oneOf · oneOf[37] · $ref #/$defs/moderation_franking_proof_result · $ref #/$defs/moderation_franking_proof_result
oneOf · oneOf[38] · $ref #/$defs/realm_tombstone_result · $ref #/$defs/realm_tombstone_result
oneOf · oneOf[39] · $ref #/$defs/realm_destroy_result · $ref #/$defs/realm_destroy_result
oneOf · oneOf[40] · $ref #/$defs/realm_set_default_strand_result · $ref #/$defs/realm_set_default_strand_result
oneOf · oneOf[41] · $ref #/$defs/strand_position_result · $ref #/$defs/strand_position_result
oneOf · oneOf[42] · $ref #/$defs/invite_lifecycle_result · $ref #/$defs/invite_lifecycle_result
oneOf · oneOf[43] · $ref #/$defs/invite_live_target_result · $ref #/$defs/invite_live_target_result
oneOf · oneOf[44] · $ref #/$defs/invite_directed_invitee_result · $ref #/$defs/invite_directed_invitee_result
oneOf · oneOf[45] · $ref #/$defs/pin_result · $ref #/$defs/pin_result
oneOf · oneOf[46] · $ref #/$defs/space_parent_result · $ref #/$defs/space_parent_result
oneOf · oneOf[47] · $ref #/$defs/space_child_scope_policy_result · $ref #/$defs/space_child_scope_policy_result
oneOf · oneOf[48] · $ref #/$defs/agent_provisioning_result · $ref #/$defs/agent_provisioning_result
oneOf · oneOf[49] · $ref #/$defs/agent_pcr_genesis_declaration_result · $ref #/$defs/agent_pcr_genesis_declaration_result
oneOf · oneOf[50] · $ref #/$defs/agent_selector_claim_result · $ref #/$defs/agent_selector_claim_result
oneOf · oneOf[51] · $ref #/$defs/consent_result · $ref #/$defs/consent_result
oneOf · oneOf[52] · $ref #/$defs/moderation_state_result · $ref #/$defs/moderation_state_result
oneOf · oneOf[53] · $ref #/$defs/object_redaction_result · $ref #/$defs/object_redaction_result
oneOf · oneOf[54] · $ref #/$defs/organization_moderation_policy_result · $ref #/$defs/organization_moderation_policy_result
oneOf · oneOf[55] · $ref #/$defs/view_result · $ref #/$defs/view_result
oneOf · oneOf[56] · $ref #/$defs/policy_result · $ref #/$defs/policy_result
oneOf · oneOf[57] · $ref #/$defs/device_authorization_result · $ref #/$defs/device_authorization_result
oneOf · oneOf[58] · $ref #/$defs/device_generation_result · $ref #/$defs/device_generation_result
oneOf · oneOf[59] · $ref #/$defs/device_revocation_proposals_result · $ref #/$defs/device_revocation_proposals_result
oneOf · oneOf[60] · $ref #/$defs/agent_action_approval_result · $ref #/$defs/agent_action_approval_result
oneOf · oneOf[61] · $ref #/$defs/agent_sidecar_exchange_controls_result · $ref #/$defs/agent_sidecar_exchange_controls_result
oneOf · oneOf[62] · $ref #/$defs/applet_discovery_result · $ref #/$defs/applet_discovery_result
oneOf · oneOf[63] · $ref #/$defs/applet_registration_result · $ref #/$defs/applet_registration_result
oneOf · oneOf[64] · $ref #/$defs/key_backup_active_series_result · $ref #/$defs/key_backup_active_series_result
oneOf · oneOf[65] · $ref #/$defs/member_identity_updates_result · $ref #/$defs/member_identity_updates_result
oneOf · oneOf[66] · $ref #/$defs/message_revision_result · $ref #/$defs/message_revision_result
oneOf · oneOf[67] · $ref #/$defs/actor_profile_realm_override_result · $ref #/$defs/actor_profile_realm_override_result
oneOf · oneOf[68] · $ref #/$defs/realm_organization_result · $ref #/$defs/realm_organization_result
oneOf · oneOf[69] · $ref #/$defs/circle_member_state_result · $ref #/$defs/circle_member_state_result
oneOf · oneOf[70] · $ref #/$defs/circle_result · $ref #/$defs/circle_result
oneOf · oneOf[71] · $ref #/$defs/realm_search_policy_result · $ref #/$defs/realm_search_policy_result
oneOf · oneOf[72] · $ref #/$defs/rsvp_result · $ref #/$defs/rsvp_result
oneOf · oneOf[73] · $ref #/$defs/schema_definition_result · $ref #/$defs/schema_definition_result
oneOf · oneOf[74] · $ref #/$defs/sidecar_context_result · $ref #/$defs/sidecar_context_result
oneOf · oneOf[75] · $ref #/$defs/sidecar_result · $ref #/$defs/sidecar_result
oneOf · oneOf[76] · $ref #/$defs/strand_watch_result · $ref #/$defs/strand_watch_result
oneOf · oneOf[77] · $ref #/$defs/calendar_schedule_source_result · $ref #/$defs/calendar_schedule_source_result
oneOf · oneOf[78] · $ref #/$defs/actor_profile_result · $ref #/$defs/actor_profile_result
oneOf · oneOf[79] · $ref #/$defs/direct_conversation_binding_result · $ref #/$defs/direct_conversation_binding_result
oneOf · oneOf[80] · $ref #/$defs/moderation_report_result · $ref #/$defs/moderation_report_result
oneOf · oneOf[81] · $ref #/$defs/morph_result · $ref #/$defs/morph_result
oneOf · oneOf[82] · $ref #/$defs/policy_action_result · $ref #/$defs/policy_action_result
oneOf · oneOf[83] · $ref #/$defs/realm_archive_result · $ref #/$defs/realm_archive_result
oneOf · oneOf[84] · $ref #/$defs/realm_freeze_result · $ref #/$defs/realm_freeze_result
* retention_and_history_floor · object
Caller-authorized per-stream history floors and Realm history policy at the same durable cut as visible_stream_heads and current_state_entries; no floor for a hidden stream may be disclosed.
* history_access · string (enum)
enum: "since_join" "all_history_for_current_members"
* stream_floors · array<object>
items · object
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* oldest_position · integer
* created_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_snapshot_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · …
recursion truncated at depth 8; see source schema for full shape
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · object · $ref ./approval-signature.schema.json
The single approval evidence type of v1 (zh/authz/constraint-schema.md section 9.2). One approver signs one exact target: either a fully authored Event that has not been submitted yet, or the original typed RequestBody of one operation whose evidence carrier is registered in capability-action-registry.json. The object is not an Event, never enters Realm history, and MUST NOT be written into an EventEnvelope, a signed payload or an Event semantic_refs[] entry. It travels in the carrier registered for the approved action. It proves that an approver approved that target; it proves nothing about the initiator's own authority.
* input · …
recursion truncated at depth 8; see source schema for full shape
* proof · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] · …
recursion truncated at depth 8; see source schema for full shape
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
realm_id · …
recursion truncated at depth 8; see source schema for full shape
* scope_ref · …
recursion truncated at depth 8; see source schema for full shape
* actor_id · …
recursion truncated at depth 8; see source schema for full shape
executed_by · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · …
recursion truncated at depth 8; see source schema for full shape
applet_id · …
recursion truncated at depth 8; see source schema for full shape
external_ref · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
semantic_refs · …
recursion truncated at depth 8; see source schema for full shape
* payload · …
recursion truncated at depth 8; see source schema for full shape
* producer_proof · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
kind · …
recursion truncated at depth 8; see source schema for full shape
* welcomes · array<$ref ./mls-welcome-delivery.schema.json>
items · object · $ref ./mls-welcome-delivery.schema.json
Producer-signed recipient delivery queued atomically with its winning MLS Commit. This is not a shared Realm Event and does not receive an independent RealmCommit.
* welcome_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* effective_scope · …
recursion truncated at depth 8; see source schema for full shape
* commit_event_ref · …
recursion truncated at depth 8; see source schema for full shape
* recipient_actor_id · …
recursion truncated at depth 8; see source schema for full shape
* recipient_endpoint · …
recursion truncated at depth 8; see source schema for full shape
* keypackage_claim_ref · …
recursion truncated at depth 8; see source schema for full shape
* ciphertext_b64 · …
recursion truncated at depth 8; see source schema for full shape
* producer_proof · …
recursion truncated at depth 8; see source schema for full shape
* idempotency_key · string
pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status · string (enum)
enum: "committed" "duplicate"
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status · string (enum)
enum: "rejected" "retryable_unavailable"
* reason_code · string
pattern: ^[a-z][a-z0-9_]{0,63}$
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] · integer
oneOf · oneOf[1] · null
before_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] · integer
oneOf · oneOf[1] · null
* limit · integer
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event_disclosure · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · integer
Smallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* floor_reason · string (enum)
Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum: "stream_start" "membership_join" "history_access_policy"
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · object
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* commit · …
recursion truncated at depth 8; see source schema for full shape
* event_disclosure · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · integer
Smallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* floor_reason · string (enum)
Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum: "stream_start" "membership_join" "history_access_policy"
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* nonce · string
pattern: ^[A-Za-z0-9_-]{43}$
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] · ?
* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* from_generation · integer
* to_generation · integer
* from_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* to_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* final_stream_heads_digest · string · $ref ./event-envelope.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
historical_signer_facts_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
New handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern: ^sha256:[0-9a-f]{64}$
* snapshot_ref · string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_id
Content-addressed identity of an authority-signed typed Realm snapshot.
pattern: ^ak:realm_snapshot:[A-Za-z0-9_-]{44}$
* change_event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* change_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · …
recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id · string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_id
Content-addressed identity of an authority-signed typed Realm snapshot.
pattern: ^ak:realm_snapshot:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Station tenure this snapshot is bound to. A consumer MUST refuse a snapshot whose generation is not the Realm's current governing Station tenure.
* visible_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
All and only the caller-visible stream heads at the same durable cut as current_state_entries and retention_and_history_floor; hidden Circle/Sidecar streams are not enumerated.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* current_state_entries · array<$ref ./typed-current-result.schema.json>
Inline closed typed current results for the caller-visible streams at the same durable cut as visible_stream_heads. An empty array is not a placeholder for an unregistered chunk fetch and proves nothing about hidden streams.
items · oneOf[85] · $ref ./typed-current-result.schema.json
Closed domain result selected without protocol typed current result IDs. Every result names the last authority commit that affected the typed target.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[7] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[8] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[9] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[10] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[11] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[12] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[13] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[14] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[15] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[16] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[17] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[18] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[19] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[20] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[21] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[22] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[23] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[24] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[25] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[26] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[27] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[28] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[29] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[30] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[31] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[32] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[33] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[34] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[35] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[36] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[37] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[38] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[39] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[40] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[41] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[42] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[43] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[44] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[45] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[46] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[47] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[48] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[49] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[50] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[51] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[52] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[53] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[54] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[55] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[56] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[57] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[58] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[59] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[60] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[61] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[62] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[63] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[64] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[65] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[66] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[67] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[68] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[69] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[70] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[71] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[72] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[73] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[74] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[75] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[76] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[77] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[78] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[79] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[80] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[81] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[82] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[83] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[84] · …
recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor · object
Caller-authorized per-stream history floors and Realm history policy at the same durable cut as visible_stream_heads and current_state_entries; no floor for a hidden stream may be disclosed.
* history_access · string (enum)
enum: "since_join" "all_history_for_current_members"
* stream_floors · array<object>
items · …
recursion truncated at depth 8; see source schema for full shape
* created_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_snapshot_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · …
recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* genesis_event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · …
recursion truncated at depth 8; see source schema for full shape
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · …
recursion truncated at depth 8; see source schema for full shape
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
* genesis_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* authority_transitions · array<$ref #/$defs/authority_transition>
items · $ref #/$defs/authority_transition · $ref #/$defs/authority_transition
* current_generation · integer
* current_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* current_route_record · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* service_kind · string
pattern: ^[a-z][a-z0-9_]{0,63}$
* method_history_evidence · $ref #/$defs/method_history_evidence · $ref #/$defs/method_history_evidence
* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did · …
recursion truncated at depth 8; see source schema for full shape
* contexts · …
recursion truncated at depth 8; see source schema for full shape
* controller_dids · …
recursion truncated at depth 8; see source schema for full shape
* also_known_as · …
recursion truncated at depth 8; see source schema for full shape
* verification_methods · …
recursion truncated at depth 8; see source schema for full shape
* authentication · …
recursion truncated at depth 8; see source schema for full shape
* assertion_methods · …
recursion truncated at depth 8; see source schema for full shape
* key_agreements · …
recursion truncated at depth 8; see source schema for full shape
* capability_invocations · …
recursion truncated at depth 8; see source schema for full shape
* capability_delegations · …
recursion truncated at depth 8; see source schema for full shape
* services · …
recursion truncated at depth 8; see source schema for full shape
* metadata · …
recursion truncated at depth 8; see source schema for full shape
* extensions · …
recursion truncated at depth 8; see source schema for full shape
* realm_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* bundle_issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* current_assertion · $ref #/$defs/current_assertion · $ref #/$defs/current_assertion
historical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.realm_snapshot_signature.v1"
enum: "ak.realm_snapshot_signature.v1"
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* genesis_event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · $ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shape
allOf · allOf[6] · $ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shape
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · $ref #/$defs/scope_ref · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · $ref #/$defs/grant_ref · $ref #/$defs/grant_ref
oneOf · oneOf[1] · $ref #/$defs/event_ref · $ref #/$defs/event_ref
oneOf · oneOf[2] · $ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_ref
oneOf · oneOf[3] · $ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_ref
oneOf · oneOf[4] · $ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_ref
oneOf · oneOf[5] · $ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_ref
applet_id · $ref #/$defs/applet_id · $ref #/$defs/applet_id
Optional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref · $ref #/$defs/external_ref · $ref #/$defs/external_ref
Optional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at · $ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestamp
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · $ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref
* payload · object
* producer_proof · $ref #/$defs/event_proof · $ref #/$defs/event_proof
The Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
* genesis_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · ?
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · null
* event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Tenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* committed_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
producer_signer_fact_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
Fixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern: ^sha256:[0-9a-f]{64}$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[7] · $ref #
oneOf · oneOf[0] · oneOf[2] · $ref #/$defs/submit_request
One ordinary producer Event with the approval signatures its two approval layers require for the Event action or for this registered submit operation, or one atomic MLS Commit plus all recipient Welcome deliveries required by that Commit. The ordinary branch is EventAdmissionSubmission itself, not a second declaration of it: the approval evidence a constraint demands has to be carriable on the primary ingress, otherwise no execution could ever satisfy the constraint (zh/authz/constraint-schema.md section 9.2.5).
oneOf · oneOf[0] · object · $ref ./service-operation-dtos.schema.json#/$defs/EventAdmissionSubmission
One exact producer-signed Event submitted to the current governance Station, plus the approval signatures required by a grant, Realm governance or List WIP policy for the Event action or for this registered submit operation. There are no RealmCommit, typed current result, offline-lease or proof-bundle sidecars. approval_signatures is the only sidecar and it is deliberately outside event: the Event bytes and event_id are finished before any approval is signed, so attaching them never changes the Event (zh/authz/constraint-schema.md section 9.2.5).
* event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] · …
recursion truncated at depth 8; see source schema for full shape
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
realm_id · …
recursion truncated at depth 8; see source schema for full shape
* scope_ref · …
recursion truncated at depth 8; see source schema for full shape
* actor_id · …
recursion truncated at depth 8; see source schema for full shape
executed_by · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · …
recursion truncated at depth 8; see source schema for full shape
applet_id · …
recursion truncated at depth 8; see source schema for full shape
external_ref · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
semantic_refs · …
recursion truncated at depth 8; see source schema for full shape
* payload · …
recursion truncated at depth 8; see source schema for full shape
* producer_proof · …
recursion truncated at depth 8; see source schema for full shape
approval_signatures · array<$ref ./approval-signature.schema.json>
One ak.schema.approval_signature.v1 object per approver. An event-target signature binds approval_target.event_id equal to event.event_id. An operation-target signature is allowed only when capability-action-registry.json resolves its action to this exact carrier operation and binds request_canonical_digest to the original typed request with approval_signatures omitted. Every ingress that wraps EventAdmissionSubmission -- ordinary self submit, batch submission, control transactions, facade hand-off -- reuses this one field and MUST NOT define its own DTO. The array is omitted when no approval layer demands evidence; it MUST NOT be present and empty. The governance Station persists the evidence, the verification basis, the nonce consumption and the binding to this submission inside the same atomic acceptance transaction, and the shared Realm Event store keeps the original Event bytes unchanged.
items · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref ./mls-commit-submission.schema.json
Atomic authority submission containing one producer-signed MLS Commit Event and every Welcome required by its Add proposals.
* commit_event · allOf[2]
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* welcomes · array<$ref ./mls-welcome-delivery.schema.json>
items · …
recursion truncated at depth 8; see source schema for full shape
* idempotency_key · string
pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/submit_outcome
oneOf · oneOf[0] · object
* status · string (enum)
enum: "committed" "duplicate"
* commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* authority_ref · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · …
recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* status · string (enum)
enum: "rejected" "retryable_unavailable"
* reason_code · string
pattern: ^[a-z][a-z0-9_]{0,63}$
oneOf · oneOf[2] · object · $ref #/$defs/stream_scan_request
Positional single-stream scan request. Pagination is by stream_position, not by an opaque cursor: within one stream the governance Station's stream_position is a strict +1 total order, so the position IS the continuation token. Exactly one of after_position / before_position MUST be present; the exclusivity is structural (the oneOf below), so a request carrying both or neither is a schema violation and MUST NOT be repaired by picking a default direction. Both bounds are read inside the range this caller is permitted to read, never over the physical stream: null means 'from the oldest position this caller may read' (after_position) or 'from the newest position this caller may read' (before_position). Continuation is the caller's job: take the largest stream_position of this batch for after_position, the smallest for before_position.
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* circle_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* sidecar_id · …
recursion truncated at depth 8; see source schema for full shape
after_position · oneOf[2]
Scan toward newer commits: return commits whose stream_position is strictly greater than this value, ascending. null starts at the oldest position this caller may read, which is position 0 only when that floor is the physical stream start; see stream_scan_outcome.readable_floor.
oneOf · oneOf[0] · integer
oneOf · oneOf[1] · null
before_position · oneOf[2]
Scan toward older commits (history backfill): return commits whose stream_position is strictly smaller than this value, descending. null starts at the newest position this caller may read, which is not necessarily the physical stream head. The scan stops at the caller's readable floor; positions below that floor are unreadable rather than missing and are not a gap (zh/sync/client-sync.md section 12.3.3).
oneOf · oneOf[0] · integer
oneOf · oneOf[1] · null
* limit · integer
oneOf · oneOf[3] · object · $ref #/$defs/stream_scan_outcome
Positional scan result over caller-visible committed Event views. There is no cursor or cross-stream order; continuation uses stream_position from committed_events[].
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · integer
Smallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* floor_reason · string (enum)
Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum: "stream_start" "membership_join" "history_access_policy"
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
oneOf · oneOf[4] · object · $ref #/$defs/peer_stream_scan_outcome
Peer-only authorized original rows and exactly one ordered original Commit-bound producer fact for every digest-bearing Full Human or Applet Service original. Withheld/redacted rows carry no fact. Handoff inventory covers the complete imported digest-bearing original target set, independent of member floors.
* committed_events · array<$ref #/$defs/stream_row>
Contiguous caller-visible committed Event views for the requested stream, ordered by RealmCommit stream_position. Full and withheld rows preserve the same verifiable Commit chain.
items · oneOf[2] · $ref #/$defs/stream_row
Caller-scoped, non-durable read representation pairing one RealmCommit with either the exact producer-signed Event or a minimal withheld marker. It has no independent identity, signature or persistence semantics and is never reducer input.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
readable_floor · object · $ref #/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · integer
Smallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* floor_reason · string (enum)
Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum: "stream_start" "membership_join" "history_access_policy"
* truncated · boolean
True when at least one further commit that this caller is permitted to read exists beyond this page in the requested direction, i.e. the scan stopped on limit. It is a statement about the caller's permitted range, never about the physical stream: a scan that stopped on the newest readable position (after_position) or on readable_floor.oldest_position (before_position) MUST set it false even when the Station holds further commits this caller may not read. History outside the caller's range MUST NOT set it, a page that stopped on the floor MUST NOT be presented as truncation, and truncated MUST NOT be used to conceal a floor. An empty committed_events[] with truncated false means the caller's permitted range is exhausted in that direction, never that the physical stream is empty or absent.
* producer_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] · object · $ref #/$defs/authority_bundle_request
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* nonce · string
pattern: ^[A-Za-z0-9_-]{43}$
oneOf · oneOf[6] · object · $ref #/$defs/handoff_request
allOf · allOf[0] · ?
* handoff · object · $ref ./realm-authority-handoff.schema.json
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id · string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_id
Content-addressed identity of one closed old-to-new Realm authority handoff.
pattern: ^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* from_generation · integer
* to_generation · integer
* from_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* to_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* final_stream_heads_digest · string · $ref ./event-envelope.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
historical_signer_facts_digest · string · $ref ./account-operations.schema.json#/$defs/sha256_digest
New handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern: ^sha256:[0-9a-f]{64}$
* snapshot_ref · string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_id
Content-addressed identity of an authority-signed typed Realm snapshot.
pattern: ^ak:realm_snapshot:[A-Za-z0-9_-]{44}$
* change_event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* change_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* final_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
Private state-transfer manifest whose canonical digest equals handoff.final_stream_heads_digest. It is not included in the public authority bundle.
items · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* snapshot · object · $ref ./realm-state-snapshot.schema.json
Current governing Station-signed closed inline materialization for current bootstrap. visible_stream_heads, current_state_entries and retention_and_history_floor are read from one durable cut and include only requester-visible streams/results; each visible head is followed by its own commit tail. The complete RFC 8785 canonical signed body is at most 8,388,608 bytes. Governance admission preflights the maximal-disclosure projection and rejects a state transition that would exceed this hard Realm capacity; there is no paging or chunk fallback. No separate sections, chunk digests, state root, replay container or independent omission proof exists. Local cached rows invalid under the current closed typed value schema may be rebuilt atomically only from a complete snapshot verified against a fresh authority bundle, with source, revision, head and generation checks preserved; conflicting valid same-revision rows must still reject the entire batch (current-results section 3).
* snapshot_id · string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_id
Content-addressed identity of an authority-signed typed Realm snapshot.
pattern: ^ak:realm_snapshot:[A-Za-z0-9_-]{44}$
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
Station tenure this snapshot is bound to. A consumer MUST refuse a snapshot whose generation is not the Realm's current governing Station tenure.
* visible_stream_heads · array<$ref ./realm-commit.schema.json#/$defs/stream_head>
All and only the caller-visible stream heads at the same durable cut as current_state_entries and retention_and_history_floor; hidden Circle/Sidecar streams are not enumerated.
items · …
recursion truncated at depth 8; see source schema for full shape
* current_state_entries · array<$ref ./typed-current-result.schema.json>
Inline closed typed current results for the caller-visible streams at the same durable cut as visible_stream_heads. An empty array is not a placeholder for an unregistered chunk fetch and proves nothing about hidden streams.
items · …
recursion truncated at depth 8; see source schema for full shape
* retention_and_history_floor · object
Caller-authorized per-stream history floors and Realm history policy at the same durable cut as visible_stream_heads and current_state_entries; no floor for a hidden stream may be disclosed.
* history_access · …
recursion truncated at depth 8; see source schema for full shape
* stream_floors · …
recursion truncated at depth 8; see source schema for full shape
* created_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_snapshot_signature
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
* authority_bundle · object · $ref ./realm-authority-bundle.schema.json
Public genesis-to-current authority certificate chain plus a nonce-bound online assertion. It exposes only the Realm stream and never enumerates Circle or Sidecar streams.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* genesis_event · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] · …
recursion truncated at depth 8; see source schema for full shape
* event_id · …
recursion truncated at depth 8; see source schema for full shape
* kind · …
recursion truncated at depth 8; see source schema for full shape
realm_id · …
recursion truncated at depth 8; see source schema for full shape
* scope_ref · …
recursion truncated at depth 8; see source schema for full shape
* actor_id · …
recursion truncated at depth 8; see source schema for full shape
executed_by · …
recursion truncated at depth 8; see source schema for full shape
authorization_ref · …
recursion truncated at depth 8; see source schema for full shape
applet_id · …
recursion truncated at depth 8; see source schema for full shape
external_ref · …
recursion truncated at depth 8; see source schema for full shape
* created_at · …
recursion truncated at depth 8; see source schema for full shape
semantic_refs · …
recursion truncated at depth 8; see source schema for full shape
* payload · …
recursion truncated at depth 8; see source schema for full shape
* producer_proof · …
recursion truncated at depth 8; see source schema for full shape
* genesis_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref · …
recursion truncated at depth 8; see source schema for full shape
* event_ref · …
recursion truncated at depth 8; see source schema for full shape
* governance_generation · …
recursion truncated at depth 8; see source schema for full shape
* authority_ref · …
recursion truncated at depth 8; see source schema for full shape
* committed_at · …
recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest · …
recursion truncated at depth 8; see source schema for full shape
* signature · …
recursion truncated at depth 8; see source schema for full shape
* authority_transitions · array<$ref #/$defs/authority_transition>
items · …
recursion truncated at depth 8; see source schema for full shape
* current_generation · integer
* current_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* current_route_record · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id · …
recursion truncated at depth 8; see source schema for full shape
* service_kind · …
recursion truncated at depth 8; see source schema for full shape
* method_history_evidence · …
recursion truncated at depth 8; see source schema for full shape
* normalized_did_document · …
recursion truncated at depth 8; see source schema for full shape
* realm_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · …
recursion truncated at depth 8; see source schema for full shape
* commit_id · …
recursion truncated at depth 8; see source schema for full shape
* bundle_issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* current_assertion · $ref #/$defs/current_assertion · $ref #/$defs/current_assertion
historical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · …
recursion truncated at depth 8; see source schema for full shape
* producer_signer_fact · …
recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context · const "ak.realm_commit_signature.v1"
enum: "ak.realm_commit_signature.v1"
* authority_transitions · array<$ref #/$defs/authority_transition>
items · $ref #/$defs/authority_transition · $ref #/$defs/authority_transition
* current_generation · integer
* current_service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* current_route_record · object · $ref ./identity-resolution.schema.json#/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* service_kind · string
pattern: ^[a-z][a-z0-9_]{0,63}$
* method_history_evidence · $ref #/$defs/method_history_evidence · $ref #/$defs/method_history_evidence
* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did · $ref #/$defs/did · $ref #/$defs/did
* contexts · array<oneOf[2]>
items · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · object
* controller_dids · array<$ref #/$defs/did>
items · $ref #/$defs/did · $ref #/$defs/did
* also_known_as · array<string>
items · string
Canonical URI validated by the DID resolver before projection; this array may contain non-network schemes such as acct: and therefore is not a URL field.
pattern: ^[A-Za-z][A-Za-z0-9+.-]*:[^\s]+$
* verification_methods · array<$ref #/$defs/normalized_did_verification_method>
items · $ref #/$defs/normalized_did_verification_method · $ref #/$defs/normalized_did_verification_method
* authentication · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* assertion_methods · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* key_agreements · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* capability_invocations · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* capability_delegations · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* services · array<$ref #/$defs/normalized_did_service>
items · $ref #/$defs/normalized_did_service · $ref #/$defs/normalized_did_service
* metadata · $ref #/$defs/normalized_did_document_metadata · $ref #/$defs/normalized_did_document_metadata
* extensions · array<$ref #/$defs/normalized_did_document_extension>
items · $ref #/$defs/normalized_did_document_extension · $ref #/$defs/normalized_did_document_extension
* realm_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* bundle_issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* current_assertion · $ref #/$defs/current_assertion · $ref #/$defs/current_assertion
historical_signer_facts · array<$ref #/$defs/historical_producer_signer_fact_entry>
Private complete canonical inventory at the frozen authority handoff cut: exact target set equals all imported digest-bearing Full Commit originals, without duplicates, missing or extra entries. Canonical order: JCS UTF-8 stream_ref, numeric stream_position, UTF-8 event_id, UTF-8 commit_id. Authority handoff covers all authorized streams; ordinary peer member floors remain separate. Existing request budget applies: limit_exceeded rejects without partial authority startup. No private PCR bodies. New handoffs require the inventory, including empty array.
items · object · $ref #/$defs/historical_producer_signer_fact_entry
Complete target association derived only after the original governance Commit exists. Fact digest excludes this outer target.
* target · object · $ref #/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* stream_position · integer
* producer_signer_fact · oneOf[2] · $ref #/$defs/historical_producer_signer_fact
oneOf · oneOf[0] · object · $ref #/$defs/human_historical_signer_fact
Minimal immutable original Human device signer source frozen in governance acceptance. Actual signing Account, independent authorization coordinates/revision/PCR tenure and source accepted time. No target CommitId/position, current permission, verified flag or private PCR bytes.
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* actor · object · $ref ./signer-key-operations.schema.json#/$defs/signing_account_actor_id
Complete account ActorId of the exact verified signer, preserving its Station for either an ordinary device or Agent.
* kind · const "account"
enum: "account"
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* verification_method · string (uri) · format=uri
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* key · object · $ref ./signer-key-operations.schema.json#/$defs/query_signing_key
Shared resolved key shape for existing current Agent and historical Agent/Human roles; each enclosing selector/outcome retains its own authority and source rules. Only new ordinary Human historical delivery uses original governance Commit-bound immutable facts. Independent original authorization coordinates/revision/PCR governance generation remain mandatory where the enclosing role requires them; no current fallback or new target source.
* public_key_b64u · string
Canonical unpadded base64url of exactly 32 Ed25519 public-key bytes; this is public material, not reusable current authorization.
pattern: ^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$
* authorization_ref · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · integer
* revision · object
Verified current revision of the authorization stream at resolution. The revision belongs to authorization_ref.stream_ref, is not older than authorization_ref.stream_position, and is never inferred from arrival order, a cursor or a current projection.
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* stream_position · integer
* governance_generation · integer
Verified governance generation of revision.commit_id.
* accepted_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
oneOf · oneOf[1] · object · $ref #/$defs/service_historical_signer_fact
Minimal immutable Applet Service producer source: original key, exact accepted registration epoch and installation authorization coordinates/scope. Frozen at target governance acceptance and bound by original Commit digest; no runtime completion, private Profile/control/history bodies or private signing material. This does not grant access to the source Events.
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* actor · object · $ref ./signer-key-operations.schema.json#/$defs/signing_service_actor_id
* kind · const "service"
enum: "service"
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* verification_method · string (uri) · format=uri
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* key · object · $ref ./signer-key-operations.schema.json#/$defs/service_historical_signing_key
* public_key_b64u · string
Canonical unpadded base64url of exactly 32 Ed25519 public-key bytes; this is public material, not reusable current authorization.
pattern: ^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$
* applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* registration_epoch · string · $ref ./event-payload.schema.json#/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* registration_ref · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · integer
* authorization_ref · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · …
recursion truncated at depth 8; see source schema for full shape
* stream_position · integer
* effective_scope · oneOf[4] · $ref ./event-envelope.schema.json#/$defs/scope_ref
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* circle_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* sidecar_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* accepted_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$

Source