跳转到内容

ak.schema.capability.v1

← Schemas

Arkret Capability Grant Body
ak.schema.capability.v1 · file: schemas/capability-grant.schema.json
* $ · object
allOf · allOf[0] · ?
allOf · allOf[1] · ?
* id · string
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
* schema · const "ak.schema.capability.v1"
enum: "ak.schema.capability.v1"
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* issuer_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* subject · oneOf[2]
oneOf · oneOf[0] · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
oneOf · oneOf[1] · object
* kind · const "condition"
enum: "condition"
* required_claims · array<object> · $ref ./grant-constraint.schema.json#/properties/required_claims
Conditional claim requirements. resource-selector-grammar.md §3.3 caps this array at 32 entries as a normative DoS guard; the schema enforces maxItems:32 so condition-selector grants cannot smuggle in unbounded claim objects.
items · object
anyOf · anyOf[0] · ?
anyOf · anyOf[1] · ?
* claim_kind · string
issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
trusted_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
subject_matches_actor · boolean
If true, the credential subject did_core_id MUST match the actor did_core_id after each proof's DID is independently validated and projected through its registered method adapter.
example: true
value_constraints · object
Per-field equality / membership constraints on credential claims.
organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
status · string
roles · array<string>
items · string
* actions · array<string>
items · string
Canonical action vocabulary. MUST be of the form ak.<segment>.<segment>... matching capabilities.md §5. Bare names without the ak. prefix are not permitted; consult capabilities.md before introducing new action names. Wildcards within a segment are not permitted in this schema; the resource selector controls scope, not action expansion.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
* resources · array<$ref ./resource-selector.schema.json>
items · object · $ref ./resource-selector.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
* kind · string (enum)
enum: "realm" "space" "circle" "strand" "message" "morph" "object" "relation" "view" "event" "actor" "schema" "policy" "invite" "notification" "read_cursor" "blob" "*"
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
space_id · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
object_kind · string
object_ref · string
Canonical object reference. Acceptable typed-id kinds match the v1 resource selector kind enum (see resource-selector-grammar.md §3.1). Notably MUST NOT include 'actor_profile' (use the 'actor' selector with did pattern), nor non-canonical 'board' / 'list' / 'card' / 'subject' / 'room' kinds — board / list / swimlane / calendar bucket are Space objects and MUST use the 'space' kind together with the 'allowed_space_kinds' constraint to restrict which Space kinds the grant covers.
pattern: ^(?:ak:realm:[A-Za-z0-9_-]{44}|ak:(space|circle|strand|message|morph|relation|view|event|invite):[A-Za-z0-9_-]{44}|ak:(policy|blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})$
strand_id · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
message_id · string
pattern: ^ak:message:[A-Za-z0-9_-]{44}$
morph_id · string
pattern: ^ak:morph:[A-Za-z0-9_-]{44}$
morph_kind · string
relation_kind · string
relation_id · string
pattern: ^ak:relation:[A-Za-z0-9_-]{44}$
view_id · string
pattern: ^ak:view:[A-Za-z0-9_-]{44}$
event_id · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
schema_ref · string
policy_id · string
pattern: ^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
invite_id · string
pattern: ^ak:invite:[A-Za-z0-9_-]{44}$
blob_ref · string
pattern: ^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$
match_scope · string (enum)
Authorization selector breadth. exact matches only the named resource; realm_wide is valid only for the registered resource kinds with an explicit realm_id. Neither current navigation ancestry nor creation ancestry expands authorization. Hierarchy traversal belongs to queries, not grant matching. The normative algorithm is zh/authz/resource-selector-grammar.md section 6.
enum: "exact" "realm_wide"
constraints · array<$ref ./grant-constraint.schema.json>
Constraints applied to this grant. Re-grant control MUST be expressed via constraint_kind='authority_control' and max_authority_depth (see capabilities.md §10). A top-level 'delegable' field is forbidden and MUST be rejected as schema_violation. With no authority_control constraint the grant cannot be re-granted (equivalent to max_authority_depth=0).
items · object · $ref ./grant-constraint.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · ?
allOf · allOf[6] · ?
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
constraint_id · string
Optional stable identifier of this constraint within the grant; used for diagnostics and overrides.
pattern: ^(?!ak:)
* constraint_kind · string (enum)
Constraint family discriminator. v1 collapses what were 15 types into 8 by absorbing narrowly-scoped types into their conceptual parent: edit_window → temporal; container_move → scope_limitation; rate_limiting + resource_limit → quota; approval_workflow + accountability + device_session → claim_based (with constraint_subkind); encryption_requirement + visibility_control → confidentiality (with constraint_subkind). Use the optional 'constraint_subkind' field to indicate the original specialization where evaluation logic differs.
enum: "temporal" "field_access" "kind_restriction" "scope_limitation" "authority_control" "quota" "claim_based" "confidentiality"
* effect · string (enum)
enum: "allow" "deny" "quarantine" "require_review"
evaluation_class · string (enum)
Cacheability/dependency hint for the authorization evaluator. stateless = pure function of (constraint, op, now); grant_local = depends on the grant object only; realm_state = depends on the exact Realm authority revision (membership, policy_version, etc.); external = depends on data outside that authority state (claim revocation status, rate-limit counts, async approval). Each constraint_kind has a canonical evaluation_class declared in constraint-schema.md §2.3; implementations MAY tighten (e.g. grant_local → stateless) but MUST NOT loosen (e.g. external as stateless). Auth evaluators SHOULD use this hint to gate fast-path caching.
enum: "stateless" "grant_local" "realm_state" "external"
constraint_subkind · string (enum)
Optional discriminator within a constraint_kind. Standard values: claim_based.{claim,approval,accountability}; quota.{rate,resource}; confidentiality.{encryption,visibility}; temporal.{window,edit_window,redact_window,session}; authority_control.{applet_authority}. Per constraint-schema.md §2.2, device/session binding is NOT an independent constraint_subkind: it is the claim_based constraint_subkind=claim sub-case expressed via an accepted PCR device issuer. Implementations MAY require constraint_subkind for these families and fail closed on unknown values.
enum: "claim" "approval" "accountability" "rate" "resource" "encryption" "visibility" "window" "edit_window" "redact_window" "session" "applet_authority"
applies_to_actions · array<string>
Optional restriction of a temporal constraint to specific capability actions (e.g. ['ak.message.revise.own', 'ak.message.redact.own']). Action mismatch is neutral in the effect fold: satisfied for effect=allow and not matched for deny/quarantine/require_review.
items · string
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
not_before · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
recurrence · object
Recurrence rule for temporal constraints. Used by constraint-schema.md §3.1.
frequency · string (enum)
enum: "daily" "weekly" "monthly" "custom"
days · array<string (enum)>
items · string (enum)
enum: "mon" "tue" "wed" "thu" "fri" "sat" "sun"
window_start · string
pattern: ^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$
window_end · string
pattern: ^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$
timezone · string
max_duration · string
ISO 8601 duration.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_session_duration · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
inactivity_timeout · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
expires_after · string
ISO 8601 duration; used by approval_workflow constraint instead of expires_after_ms.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_edit_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_redact_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
redact_after_window_allowed · boolean
condition · object
Conditional predicate for field_access and similar constraints. The `kind` value is a registered named condition from constraint-schema.md §4.1; unknown kinds MUST fail closed. Implementations MUST NOT introduce ad hoc string DSL predicates.
* kind · string (enum)
enum: "object_is_owned_by_actor" "actor_is_assignee" "actor_is_responsible" "actor_is_guardian" "actor_is_controller" "object_in_actor_container" "object_is_unencrypted" "object_is_encrypted" "always" "never"
allowed_write_fields · array<string>
items · string
denied_write_fields · array<string>
items · string
allowed_read_fields · array<string>
items · string
denied_read_fields · array<string>
items · string
sensitive_fields · array<string>
items · string
sensitive_handling · string (enum)
enum: "redact" "hash" "omit"
allowed_object_kinds · array<string>
items · string
denied_object_kinds · array<string>
items · string
allowed_morph_kinds · array<string>
items · string
denied_morph_kinds · array<string>
items · string
allowed_space_kinds · array<string>
Allowed Space kinds (e.g. 'board', 'list', or profile-registered kinds like 'swimlane', 'calendar_bucket'). Reducer/profile MUST validate kind value.
items · string
denied_space_kinds · array<string>
items · string
allowed_facets · array<string (enum)>
items · string (enum)
enum: "container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"
denied_facets · array<string (enum)>
items · string (enum)
enum: "container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"
allowed_view_ids · array<string>
items · string
pattern: ^ak:view:[A-Za-z0-9_-]{44}$
allowed_strand_ids · array<string>
items · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
denied_strand_ids · array<string>
items · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
allowed_space_ids · array<string>
items · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
denied_space_ids · array<string>
items · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
allowed_circle_ids · array<$ref ./common-ids.schema.json#/$defs/circle_id>
Limits Circle-scoped capability actions to the listed Circle ids. Used by ak.circle.manage / ak.circle.member.manage style grants; unconstrained Realm-wide Circle management grants are not a normal permission shape.
items · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
allowed_session_ids · array<string>
Limits applet interop-session operations to the listed applet-defined session correlation ids.
items · string
pattern: ^(?!ak:)
allowed_view_kinds · array<string>
items · string
allowed_view_renderers · array<string>
items · string
denied_view_kinds · array<string>
items · string
denied_view_renderers · array<string>
items · string
allowed_relation_kinds · array<string>
items · string
allowed_from_container_refs · array<string>
items · string
pattern: ^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$
allowed_to_container_refs · array<string>
items · string
pattern: ^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$
wip_limit_override · boolean
example: false
allowed_tracks · array<string>
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
denied_tracks · array<string>
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
blob_presign_scope · object
Scope limiter for ak.self.blob.command.presign.v1 grants: allowed purposes plus optional blob/realm restrictions.
* allowed_purposes · array<string (enum)>
items · string (enum)
enum: "media_inline" "thumbnail" "download"
blob_ref_pattern · string
realm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
items · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
allowed_data_labels · array<string>
Data classification labels this grant may read, export, transform, or send to external endpoints.
items · string
pattern: ^[a-z][a-z0-9_]{0,63}$
allowed_endpoints · array<string>
Allowed outbound endpoint origins or deployment-approved endpoint patterns for applet / agent / connector operations.
items · string
max_authority_depth · integer
Maximum remaining authority hops. Bounded by the canonical authority-chain depth ceiling (4) defined in zh/conformance/scalability-constraints.md §3 and zh/authz/capabilities.md §10.2; reducers MUST reject grants declaring a larger value at accept time rather than only truncating during DFS.
authority_path_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
authority_regrant_allowed · boolean
authority_scope · string (enum)
enum: "narrowing_only" "same_scope" "custom"
applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
registration_epoch · string
authority_control(constraint_subkind=applet_authority) binding to the canonical Applet registration epoch.
pattern: ^sha256:[0-9a-f]{64}$
blob_max_bytes · integer
blob_presign_max_ttl_seconds · integer
Maximum TTL, in seconds, that this grant permits for ak.blob.presign. The service must clamp requested max_age_seconds to the smaller of this value and deployment policy.
max_total_blob_bytes · integer
max_artifact_bytes · integer
Maximum artifact size in bytes for applet / agent / export operations.
max_operations · integer
Maximum number of distinct accepted idempotency identities in one UTC epoch-aligned fixed period. Enforcement is a linearizable check-and-reserve at one logical quota authority shared by every node in the enforcing service; per-node duplicated budgets and overshoot are forbidden.
period · string
ISO 8601 duration. For quota constraints, a stricter conditional schema permits only a non-zero fixed-length week/day/hour/minute/second duration; year/month durations are forbidden so every authority derives the same UTC epoch-aligned window id.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
burst · integer
Optional token-bucket capacity at the same logical quota authority, capped by max_operations and refilled at max_operations/period. It never increases the fixed-window total budget.
constraint_scope · string (enum)
Closed v1 quota counting scope. Unknown values are schema violations and MUST fail closed. Quota counters are actor-bound; the enum selects the additional slicing dimension: actor only, actor+space, actor+realm, or actor across all nodes/regions of the enforcing service's global quota domain. global is not an implicit federation-wide counter. Every node in the service domain MUST share one logical linearizable quota authority.
enum: "per_actor" "per_space" "per_realm" "global"
max_resources · integer
resource_kind · string
approval_required · boolean
approval_mode · string (enum)
The only approval mode of v1. The approved write MUST NOT take effect before the approval evidence is verified and accepted in the same transaction (zh/authz/constraint-schema.md section 9.2.7). There is no second mode and no path that first materializes a proposal object and then approves that object.
enum: "before_commit"
approval_actor_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
approval_relation · string (enum)
Responsibility classification of this grant explicit approval_actor_ids roster. It never creates a second dynamic roster or supplies action/scope capability. Missing explicit roster cannot satisfy approval.
enum: "responsible" "controller" "guardian" "realm_admin" "custom"
timeout · string
Positive fixed ISO 8601 duration (week/day/hour/minute/second, no calendar year/month). Each approval vote is valid only when the target covering committed_at <= that vote input.approved_at + timeout, inclusive and with zero tolerance. The same rule applies to Event and operation targets; receiver clocks and first-seen timestamps never anchor it. Omission adds no grant-local age limit.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
approval_threshold · oneOf[2]
Closed executable vote threshold: majority means floor(N/2)+1, unanimous means N, and a positive integer is the exact quorum. N is the distinct eligible approver set at the accepting authority cut. Omission means unanimous. A missing or empty eligible set, or an integer greater than N, cannot satisfy approval. Repeated signatures by one approver count once. Parameterless quorum/custom strings are schema violations.
example: "unanimous"
oneOf · oneOf[0] · string (enum)
enum: "majority" "unanimous"
oneOf · oneOf[1] · integer
accountability_required · boolean
guardian_approval_required · boolean
controller_approval_required · boolean
required_claims · array<object>
Conditional claim requirements. resource-selector-grammar.md §3.3 caps this array at 32 entries as a normative DoS guard; the schema enforces maxItems:32 so condition-selector grants cannot smuggle in unbounded claim objects.
items · object
anyOf · anyOf[0] · ?
anyOf · anyOf[1] · ?
* claim_kind · string
issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
trusted_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
subject_matches_actor · boolean
If true, the credential subject did_core_id MUST match the actor did_core_id after each proof's DID is independently validated and projected through its registered method adapter.
example: true
value_constraints · object
Per-field equality / membership constraints on credential claims.
organization_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
status · string
roles · array<string>
items · string
trusted_claim_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
claim_refresh_required · boolean
claim_max_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
allowed_history_access_values · array<string (enum)>
items · string (enum)
enum: "since_join" "all_history_for_current_members"
redacted_history_allowed · boolean
encryption_required · boolean
min_encryption_level · string (enum)
confidentiality(constraint_subkind=encryption) static floor: the minimum content-encryption mechanism the grant requires. Pure static declaration evaluated as stateless unless cross-checked against the scope's current MLS activation state (see constraint-schema.md section 12).
enum: "none" "mls_rfc9420" "external"
plaintext_fallback_allowed · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant permits plaintext in a scope that has no accepted ak.mls.genesis. After activation the flag cannot restore plaintext; the write MUST be rejected with mls_activation_irreversible. See constraint-schema.md §12.
audit_trail_required · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant requires an audit trail (e.g. active Audit Applet Binding). See constraint-schema.md §12.
key_rotation_period · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_key_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
key_backup_required · boolean
approved_key_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
depends_on_moderation_state · boolean
Cache-invalidation hint: when true, this grant's authorization decisions depend on the moderation_state typed current result (see capabilities.md §18.1) and the grant's cache entry MUST be invalidated when that typed current result changes. Default false: ordinary grants (ak.strand.update / ak.message.create / organization membership grants) do NOT take a cache hit on every moderation decision. v1 capabilities.md §18.1 lists three conditions where MUST be explicitly true (moderator-role grants, condition-selector subjects referencing moderation state, constraints referencing moderation queue / typed current result). Schema-side enforcement of condition (2) is in capability-grant.schema.json via if/then on actions[]; conditions (1) and (3) are reducer-side lint. Cache invalidation hint outside the eight constraint families; it does not participate in allow/deny evaluation and is documented in capabilities.md §6 / constraint-schema.md.
allowed_managed_actor_roles · array<string (enum)>
Ordinary authority_control permits only these accepted roles of the Applet bound by the parent applet_authority constraint; no arbitrary third-party regrant.
items · string (enum)
enum: "bot" "ghost"
(^x_[a-z][a-z0-9_]{0,63}$) · any
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* status · string (enum)
Reducer-derived lifecycle status of this Grant (zh/authz/capabilities.md section 12.1). It is absent from the closed authoring body of ak.capability.grant and is materialised by the registered capability_status derivation, so an author-supplied value MUST be rejected rather than trusted. The two terminal values stay distinct because section 10.4 gives them different authorities: revoke is issuer or root-controller authority, relinquish is the target subject's own signature and MUST NOT require ak.capability.revoke. Collapsing them into revoked_at alone would erase which authority closed the Grant. A terminal value is final -- section 12.1 forbids resurrecting a closed grant_id -- and compaction MUST preserve it.
enum: "active" "revoked" "relinquished"
updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
updated_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
revoked_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
revoked_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* issuer_authority_refs · array<oneOf[3]>
The signed semantic authority lineage this grant was issued under. A root controller's grant anchors on the accepted Realm authority Event; any further grant anchors on grants its issuer already holds. These closed refs intentionally carry no producer-selected current-result revision, authorization-state digest, Station id or commit basis: the governing Station resolves their current typed results at acceptance, fails closed when current authority cannot be proved fresh, and records the accepting RealmCommit as the decision basis. Authorization is recomputed from these refs on every decision, so revoking an ancestor invalidates its descendants without a cascading write. The sole owned_agent ref is an explicit non-regrant exception; it pins ownership membership and continuously bounds the Agent by current controller authority.
items · oneOf[3]
oneOf · oneOf[0] · object
A grant the issuer holds. The issuer MUST be that grant's subject, and the ref MUST be active both at acceptance and evaluation time; its capability, resources and constraints all bound this child. Its current-result revision is an acceptance-time Station input, not a signed wire member.
* kind · const "grant"
enum: "grant"
* grant_id · string · $ref ./common-ids.schema.json#/$defs/grant_id
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
A committed authority root in the same Realm as the grant. It is terminal for cycle checks. The accepting Station verifies the named Event/controller/generation against durable current authority; the ref does not carry a Station-local commit wrapper.
* kind · const "realm_root"
enum: "realm_root"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* authority_event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* authority_generation · integer
Realm authority-root delegation generation at issuance, read from the realm_authority_root typed current result. A ref stays valid only while that value's current authority_generation still equals this one, and the read MUST use the registered inclusion proof at a RealmCommit basis, never an unproven cache. ak.realm.authority.reset is the only kind that advances it, so it is the only act that invalidates a whole delegated generation; ak.realm.owner.transfer preserves it and therefore leaves every child grant valid. This is NOT the governing Station tenure, which is governance_generation on RealmCommit -- a planned Station handoff MUST NOT invalidate any grant.
oneOf · oneOf[2] · object · $ref #/$defs/owned_agent_authority_ref
Explicit terminal owned-Agent execution source, not general regrant or Realm root control. Exact controller and Agent join generations are pinned; current controller authority is reevaluated at each use. See zh/authz/owned-agent-authority.md.
* kind · const "owned_agent"
enum: "owned_agent"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* controller_join_event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* agent_join_event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* authority_depth · integer
Reducer-derived absolute distance from the authority root: a realm_root ref counts 0, so a root controller's grant is 1 and a member's re-grant is 2. Derived from the refs, never author-declared, so it cannot be misreported — which is what makes it safe to answer 'how far did this authority spread' with a single field instead of a recursive join. Taken at issuance and not recomputed on revocation; a later chain may be shorter than the recorded value, which is the conservative direction for a max_authority_depth decision. A dedicated terminal owned_agent source has depth 1 and cannot become a parent grant.
* authority_root_refs · array<oneOf[2]>
Reducer-derived set of committed authority roots this grant ultimately descends from: direct realm_root refs plus the union of every parent grant's roots. Deduplicated on (realm_id, authority_event_ref, authority_generation) and sorted canonically by unsigned-byte order. For an owned_agent source the sole root is that exact owned_agent ref; it never confers Realm root-control authority.
items · oneOf[2]
oneOf · oneOf[0] · object
* kind · const "realm_root"
enum: "realm_root"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* authority_event_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* authority_generation · integer
The delegation generation of the root this grant descends from, carried verbatim from the realm_root ref. Part of the dedup key, because the same root at a different generation is a different authority.
oneOf · oneOf[1] · object · $ref #/$defs/owned_agent_authority_ref
Explicit terminal owned-Agent execution source, not general regrant or Realm root control. Exact controller and Agent join generations are pinned; current controller authority is reevaluated at each use. See zh/authz/owned-agent-authority.md.
* kind · const "owned_agent"
enum: "owned_agent"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* controller_join_event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* agent_join_event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
(^x_[a-z][a-z0-9_]{0,63}$) · any

Source