ak.schema.authz_operations.v1
ak.schema.authz_operations.v1 · file: schemas/authz-operations.schema.json Closed response DTOs for authorization query operations that need operation-specific list envelopes.
* $ · anyOf[1]
Closed response DTOs for authorization query operations that need operation-specific list envelopes.
anyOf · anyOf[0] · object · $ref #/$defs/authz_invite_list
* invites · array<$ref ./invite.schema.json>
items · object · $ref ./invite.schema.json
allOf · allOf[0] ·
?* id ·
stringpattern:
^ak:invite:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.invite.v1"enum:
"ak.schema.invite.v1"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* inviter_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idinvitee_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idintroduction_evidence_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of private invite delivery introduction_evidence. Raw locator tokens and receive-policy state MUST NOT appear in durable Realm events.
third_party_invite ·
$ref #/$defs/third_party_invite · $ref #/$defs/third_party_invitecapability_grant_refs · array<string>
items ·
stringpattern:
^ak:grant:[A-Za-z0-9_-]{44}$* state ·
string (enum)enum:
"pending" "accepted" "rejected" "revoked" "expired" "claimed" "send_failed" "revoked_by_capability_loss" "revoked_by_inviter_left" "invalidated_by_rate_limit"* expires_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampupdated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idupdated_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp(^x_[a-z][a-z0-9_]{0,63}$) ·
anynext_cursor ·
string · $ref #/$defs/cursorpattern:
^ak:cursor:[A-Za-z0-9_-]+$* has_more ·
booleanSource
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/authz-operations.schema.json