ak.schema.blob_operations.v1
ak.schema.blob_operations.v1 · file: schemas/blob-operations.schema.json Closed request/response DTOs for blob service operations whose wire shape is not the full blob metadata resource.
* $ · anyOf[2]
Closed request/response DTOs for blob service operations whose wire shape is not the full blob metadata resource.
anyOf · anyOf[0] · object · $ref #/$defs/blob_upload_request_body
allOf · allOf[0] ·
?* content ·
string (binary) · format=binaryThe binary blob content part in multipart/form-data. This field is not JCS-canonicalized as JSON; content_digest covers the bytes.
* size_bytes ·
integerrealm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$content_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$media_type ·
string · $ref #/$defs/media_typeThe stored-byte MIME declaration. If the content part also declares a different MIME, reject before storage. Ciphertext uses application/octet-stream.
pattern:
^[a-z0-9.+-]+/[a-z0-9.+-]+$filename ·
string* encryption · oneOf[2] · $ref ./blob.schema.json#/$defs/storage_encryption
Storage-visible encryption classification only; no plaintext MIME, plaintext size, nonce, group or key reference. Private attachment descriptors remain in authenticated Content Blocks.
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] · object
* scheme ·
string (enum)enum:
"ak.blob.whole_file_aead.v1" "ak.blob.stream_aead.v1"anyOf · anyOf[1] · object · $ref #/$defs/blob_upload_outcome
* blob_ref ·
string · $ref #/$defs/blob_refContent-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern:
^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$* size_bytes ·
integermedia_type ·
string · $ref #/$defs/media_typepattern:
^[a-z0-9.+-]+/[a-z0-9.+-]+$upload_receipt · object · $ref #/$defs/upload_receipt
* blob_ref ·
string · $ref #/$defs/blob_refContent-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern:
^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$* size_bytes ·
integer* received_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref #/$defs/signature
* kid ·
string · $ref #/$defs/did_urlDID URL of the concrete issuer verification method. Bare DID is not accepted because the receipt must pin one already accepted service key binding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature_algorithm ·
string (enum)enum:
"Ed25519"* sig ·
stringpattern:
^[A-Za-z0-9_-]+={0,2}$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/blob-operations.schema.json