ak.schema.call_recording_artifact.v1
ak.schema.call_recording_artifact.v1 · file: schemas/call-recording-artifact.schema.json Canonical metadata for a call recording artifact after it has entered the Arkret blob pipeline. It binds the blob, recording start event, MLS exporter recording key context, retention policy and deletion audit surface without introducing a ak:recording or ak:artifact storage key.
* $ · object
Canonical metadata for a call recording artifact after it has entered the Arkret blob pipeline. It binds the blob, recording start event, MLS exporter recording key context, retention policy and deletion audit surface without introducing a ak:recording or ak:artifact storage key.
anyOf · anyOf[0] ·
?anyOf · anyOf[1] · object
* retention ·
?* schema ·
const "ak.schema.call_recording_artifact.v1"enum:
"ak.schema.call_recording_artifact.v1"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* call_id ·
string · $ref #/$defs/call_idpattern:
^ak:call:[A-Za-z0-9_-]{44}$* recording_id ·
string · $ref #/$defs/recording_idpattern:
^[A-Za-z0-9._-]{1,128}$* recording_start_event_id ·
string · $ref #/$defs/event_refpattern:
^ak:event:[A-Za-z0-9_-]{44}$* blob_ref ·
string · $ref #/$defs/blob_refContent-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern:
^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$* size_bytes ·
integer* duration_ms ·
integer* media_type ·
string · $ref #/$defs/media_typepattern:
^[a-z0-9.+-]+/[a-z0-9.+-]+$* encryption · object · $ref #/$defs/recording_encryption
* encryption_algorithm ·
string (enum)enum:
"mls_exporter_aead_xchacha20poly1305" "mls_exporter_aead_aes_256_gcm" "mls_exporter_aead_xchacha20poly1305_stream" "mls_exporter_aead_aes_256_gcm_stream"* exporter_label ·
const "ak.rtc-recording-key/v1"enum:
"ak.rtc-recording-key/v1"* context · object
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* call_id ·
string · $ref #/$defs/call_idpattern:
^ak:call:[A-Za-z0-9_-]{44}$* focus_id ·
stringpattern:
^(?!ak:)* recording_id ·
string · $ref #/$defs/recording_idpattern:
^[A-Za-z0-9._-]{1,128}$* media_service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* recording_start_event_id ·
string · $ref #/$defs/event_refpattern:
^ak:event:[A-Za-z0-9_-]{44}$retention_policy_id ·
string · $ref #/$defs/policy_idpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* retention · object · $ref #/$defs/call_recording_retention
Retention contract for a recording or transcript capture artifact. retention_expires_at is the earliest deletion time; deletion_trigger declares the only accepted purge cause; audit_lock blocks all purge paths until an audit-grade release is accepted; consent_confirmed records the required second client-side capture confirmation.
retention_expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$deletion_trigger ·
string (enum)enum:
"retention_expiry" "manual" "realm_policy" "participant_erasure"audit_lock ·
booleanWhen true the artifact is under audit / legal hold; purge MUST be rejected with legal_hold_active until the lock is released by an audit-grade action.
consent_confirmed ·
booleanRecords that the second client-side confirmation required before recording or transcript capture was obtained.
* produced_by ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* recording_initiator_capability_ref ·
string · $ref #/$defs/grant_refCapability grant reference proving the recording was initiated by an actor holding ak.call.record.
pattern:
^ak:grant:[A-Za-z0-9_-]{44}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$deletion_audit · object · $ref #/$defs/call_recording_deletion_audit
Present only after a delete attempt is scheduled, completed, or blocked. The referenced erasure receipt remains the durable audit proof.
* trigger ·
string (enum)enum:
"retention_expiry" "manual" "realm_policy" "participant_erasure"* outcome ·
string (enum)enum:
"pending" "completed" "blocked_by_legal_hold" "failed"requested_by ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$trigger_event_id ·
string · $ref #/$defs/event_refDurable event that caused this delete attempt, when the trigger is event-backed.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* requested_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$completed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$erasure_receipt_ref ·
string · $ref #/$defs/audit_refak.audit.erasure_receipt event, ak.schema.erasure_receipt.v1 object, or digest proving the deletion outcome.
pattern:
^((?:ak:(event):[A-Za-z0-9_-]{44}|ak:(receipt|policy):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})|(?:sha256|blake3):[0-9a-f]{64})$legal_hold_ref ·
string · $ref #/$defs/audit_refpattern:
^((?:ak:(event):[A-Za-z0-9_-]{44}|ak:(receipt|policy):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})|(?:sha256|blake3):[0-9a-f]{64})$failure_reason_code · oneOf[2]
oneOf · oneOf[0] ·
string (enum)enum:
"media_negotiation_timeout" "permission_denied" "backend_unavailable" "media_source_unavailable" "storage_failed" "policy_revoked" "consent_withdrawn" "integrity_failed"oneOf · oneOf[1] ·
stringpattern:
^x_[a-z0-9_]{1,62}$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/call-recording-artifact.schema.json