ak.schema.contact_operations.v1
ak.schema.contact_operations.v1 · file: schemas/contact-operations.schema.json Closed request/response DTO bundle for the Contact lifecycle: request, respond, reject, scope replacement, tombstone, the portable Contact round evidence bundle, acceptance receipts and the peer Contact carrier, plus the contact-list projection.
* $ · anyOf[15]
Closed request/response DTO bundle for the Contact lifecycle: request, respond, reject, scope replacement, tombstone, the portable Contact round evidence bundle, acceptance receipts and the peer Contact carrier, plus the contact-list projection.
anyOf · anyOf[0] · oneOf[2] · $ref #/$defs/contact_request_request_body
oneOf · oneOf[0] · object
* phase ·
const "prepare"enum:
"prepare"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* idempotency_key ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"* introduction_evidence · oneOf[5] · $ref #/$defs/contact_introduction_evidence
oneOf · oneOf[0] · object
* kind ·
const "locator_ref"enum:
"locator_ref"* principal_locator · object · $ref ./principal-locator.schema.json
Signed online locator returned from a holder-controlled Station locator ref. It asserts an exact AccountId and current first-hop route used for private invite delivery; it is not a Realm membership grant and cannot alter account identity.
* schema ·
const "ak.schema.principal_locator.v1"enum:
"ak.schema.principal_locator.v1"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* service_resolution · oneOf[2] · $ref ./identity-resolution.schema.json#/$defs/service_resolution_carrier
First-hop resolution material for account_id.station_id; it is covered by the locator proofs.
oneOf · oneOf[0] · object
* inline ·
$ref #/$defs/authenticated_service_resolution · $ref #/$defs/authenticated_service_resolutiononeOf · oneOf[1] · object
* resolution_url ·
string (uri) · format=uriBounded canonical HTTPS discovery URL for the public method evidence of the expected service. Fetch success supplies no authority or freshness.
pattern:
^https://[^?#]+$route_assistance · object · $ref ./identity-resolution.schema.json#/$defs/route_assistance
Transport-only bounded discovery hints. They do not authorize routing, extend outer token expiry, or supply current DID state.
* mirror_hints · array<$ref #/$defs/route_mirror_hint>
At most four independently routable mirror hints. Each item carries the mirror did_core_id together with a service_resolution_carrier; bare URLs and bare core ids are not valid items.
items ·
$ref #/$defs/route_mirror_hint · $ref #/$defs/route_mirror_hint* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* locator_ref_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of the private locator ref material. The raw locator token MUST NOT appear in durable Realm events.
display_hint · object
UI-only display hint. It is not identity authority and MUST NOT be used for authorization.
display_name_hint ·
stringavatar_blob_ref ·
string · $ref ./common-ids.schema.json#/$defs/blob_refContent-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern:
^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$* proofs · array<$ref #/$defs/principal_locator_proof>
At minimum contains recipient_service_acceptance. High-assurance deployments SHOULD also require subject_locator_authorization.
items ·
$ref #/$defs/principal_locator_proof · $ref #/$defs/principal_locator_proofoneOf · oneOf[1] · object
* kind ·
const "shared_realm"enum:
"shared_realm"* realm_id ·
string · $ref ./principal-operations.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* requester_member_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* target_member_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "handle_claim"enum:
"handle_claim"* handle ·
string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref ./string-profiles.schema.json#/$defs/canonical_handleCanonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern:
^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$* handle_claim · object · $ref ./handle-claim.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* schema ·
const "ak.schema.handle_claim.v1"enum:
"ak.schema.handle_claim.v1"* claim ·
$ref #/$defs/handle_claim_core · $ref #/$defs/handle_claim_core* status ·
string (enum)enum:
"pending" "verified" "revoked"* as_of ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* verifier_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verified_at ·
$ref #/$defs/nullable_timestamp · $ref #/$defs/nullable_timestamp* revocation · oneOf[2]
oneOf · oneOf[0] ·
$ref #/$defs/handle_claim_revocation · $ref #/$defs/handle_claim_revocationoneOf · oneOf[1] ·
null* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* status_proof · allOf[2]
allOf · allOf[0] · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
$ref #/$defs/digest · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
proof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$allOf · allOf[1] · object
* domain ·
const "ak.handle_claim_status.v1"enum:
"ak.handle_claim_status.v1"* proof_purpose ·
const "status_attestation"enum:
"status_attestation"resolved_by ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$resolved_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[3] · object
* kind ·
const "same_station"enum:
"same_station"oneOf · oneOf[4] · object
* kind ·
const "explicit_address"enum:
"explicit_address"continuity_evidence · object · $ref #/$defs/contact_continuity_evidence
Explicit portable import. The Station validates the checkpoint and bounded tail, binds the exact pair and committed lineage, and derives the predecessor. Ordinary online recontact loads Station durable evidence instead.
* checkpoint · object · $ref #/$defs/bilateral_continuity_checkpoint
* core · object · $ref #/$defs/bilateral_continuity_checkpoint_core
Domain-neutral, root-anchored commitment to one contiguous prefix of a bilateral lineage. Sequence is monotonic; same sequence with a different checkpoint digest is a fork, never a winner election.
allOf · allOf[0] ·
?* context ·
const "ak.contact.round.continuity.v1"enum:
"ak.contact.round.continuity.v1"* participant_ids · array<$ref #/$defs/actor_id>
The two exact ActorIds, sorted by RFC 8785 canonical bytes.
items · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* root_basis · allOf[2]
Portable uncheckpointed root Contact round evidence. It is retained so founder and root identity remain independently derivable after prefix compaction.
allOf · allOf[0] · object · $ref #/$defs/contact_round_evidence_bundle
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestAbsent only for a root Contact round. On recontact it is copied from every signed request fact and request acceptance receipt in this bundle and points to the immediately preceding terminal round. The bundle field is derived convenience, never independent authority.
pattern:
^sha256:[0-9a-f]{64}$* contact_round · oneOf[2] · $ref #/$defs/contact_round
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* request_receipts · array<$ref #/$defs/request_acceptance_receipt>
items ·
…recursion truncated at depth 8; see source schema for full shape
normal_response_receipt · object · $ref #/$defs/normal_response_acceptance_receipt
Source Station attestation issued only after the exact response Event's command unit is committed and its Contact effect atomically installed. Pending admission or proposal acknowledgement is not this receipt.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* contact_round_id ·
…recursion truncated at depth 8; see source schema for full shape
* request_receipt ·
…recursion truncated at depth 8; see source schema for full shape
* response_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer ·
…recursion truncated at depth 8; see source schema for full shape
* outgoing_slot_absence_digest ·
…recursion truncated at depth 8; see source schema for full shape
* accepted_at ·
…recursion truncated at depth 8; see source schema for full shape
* issuer_id ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
glare_concurrency_attestations · array<$ref #/$defs/glare_concurrency_attestation>
items ·
…recursion truncated at depth 8; see source schema for full shape
* current_proofs · array<$ref #/$defs/contact_current_proof>
items ·
…recursion truncated at depth 8; see source schema for full shape
continuity_checkpoint · object · $ref #/$defs/bilateral_continuity_checkpoint
Latest mutually signed compacted prefix for this lineage. Its presence changes the chain terminator from the root round to covered_through_contact_round_id; it never changes the root basis or participant authority pair.
* core ·
…recursion truncated at depth 8; see source schema for full shape
* checkpoint_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signatures ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
?* covered_through_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestThe exact terminal contact_round_id at the compacted-prefix boundary. The oldest remaining tail edge points here; bundle content digests are accumulated only in prefix_accumulator_root.
pattern:
^sha256:[0-9a-f]{64}$* prefix_accumulator_root ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* covered_prefix_count ·
integer* sequence ·
integerprevious_checkpoint_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* checkpoint_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH(ak.bilateral-continuity.checkpoint.v1, canonical core).
pattern:
^sha256:[0-9a-f]{64}$* signatures · array<$ref #/$defs/bilateral_continuity_checkpoint_signature>
Exactly one signature by each registered participant authority key over the checkpoint core.
items · object · $ref #/$defs/bilateral_continuity_checkpoint_signature
* signer_id · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* uncompressed_tail_entries · array<$ref #/$defs/contact_round_evidence_bundle>
Immediate predecessor first; at least the latest terminal round remains explicit, and the final edge must terminate exactly at checkpoint.core.covered_through_contact_round_id.
items · object · $ref #/$defs/contact_round_evidence_bundle
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestAbsent only for a root Contact round. On recontact it is copied from every signed request fact and request acceptance receipt in this bundle and points to the immediately preceding terminal round. The bundle field is derived convenience, never independent authority.
pattern:
^sha256:[0-9a-f]{64}$* contact_round · oneOf[2] · $ref #/$defs/contact_round
oneOf · oneOf[0] · object
* kind ·
const "normal"enum:
"normal"* sorted_pair_member_ids · array<$ref #/$defs/actor_id>
Exactly two distinct full ActorIds, strictly ascending by their RFC 8785 JCS UTF-8 unsigned bytes. Validation rejects noncanonical order without sorting the received array.
items ·
…recursion truncated at depth 8; see source schema for full shape
* request_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* request_acceptance_receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[1] · object
* kind ·
const "glare"enum:
"glare"* sorted_pair_member_ids · array<$ref #/$defs/actor_id>
Exactly two distinct full ActorIds, strictly ascending by their RFC 8785 JCS UTF-8 unsigned bytes. Validation rejects noncanonical order without sorting the received array.
items ·
…recursion truncated at depth 8; see source schema for full shape
* requests · array<object>
Exactly two distinct request_event_ref values, strictly ascending by the complete typed EventId wire string UTF-8 unsigned bytes. Receipt digest is not a sort key or tiebreaker. Duplicate refs are invalid even with different digests. Receivers reject unsorted input without normalization. The signed request Event author ActorId of requests[0], not the Station receipt issuer_id, is the root-round founder.
items ·
…recursion truncated at depth 8; see source schema for full shape
* request_receipts · array<$ref #/$defs/request_acceptance_receipt>
items · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* holder ·
…recursion truncated at depth 8; see source schema for full shape
* peer ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
…recursion truncated at depth 8; see source schema for full shape
slot_predecessor ·
…recursion truncated at depth 8; see source schema for full shape
previous_terminal_contact_round_id ·
…recursion truncated at depth 8; see source schema for full shape
* request_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
…recursion truncated at depth 8; see source schema for full shape
* accepted_at ·
…recursion truncated at depth 8; see source schema for full shape
* issuer_id ·
…recursion truncated at depth 8; see source schema for full shape
* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
normal_response_receipt · object · $ref #/$defs/normal_response_acceptance_receipt
Source Station attestation issued only after the exact response Event's command unit is committed and its Contact effect atomically installed. Pending admission or proposal acknowledgement is not this receipt.
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* holder ·
…recursion truncated at depth 8; see source schema for full shape
* peer ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
…recursion truncated at depth 8; see source schema for full shape
slot_predecessor ·
…recursion truncated at depth 8; see source schema for full shape
previous_terminal_contact_round_id ·
…recursion truncated at depth 8; see source schema for full shape
* request_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* producer_signer ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
…recursion truncated at depth 8; see source schema for full shape
* accepted_at ·
…recursion truncated at depth 8; see source schema for full shape
* issuer_id ·
…recursion truncated at depth 8; see source schema for full shape
* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
* response_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted response Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel response_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
* delegated_actor_did ·
…recursion truncated at depth 8; see source schema for full shape
* outgoing_slot_absence_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH('ak.contact.no_outgoing_slot.v1', outgoing_slot_absence_transcript) over the exact closed transcript defined by identity/contact-and-direct-conversation.md section 2.
pattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$glare_concurrency_attestations · array<$ref #/$defs/glare_concurrency_attestation>
items · object · $ref #/$defs/glare_concurrency_attestation
Source-service-signed evidence for the subject_id -> peer_id direction that both request receipts were accepted while neither request slot had yet been consumed. A glare bundle requires the two opposite directions; issuer_id is the signing service and is never used as the participant discriminator.
* subject_id · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer_id · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* request_receipt_digests · array<$ref ./principal-operations.schema.json#/$defs/digest>
items ·
…recursion truncated at depth 8; see source schema for full shape
* observed_commit_event_ids · array<$ref #/$defs/event_id>
items ·
…recursion truncated at depth 8; see source schema for full shape
* complete_through ·
integer* unconsumed_slot_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* observed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
* current_proofs · array<$ref #/$defs/contact_current_proof>
items · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
…recursion truncated at depth 8; see source schema for full shape
* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
continuity_checkpoint · object · $ref #/$defs/bilateral_continuity_checkpoint
Latest mutually signed compacted prefix for this lineage. Its presence changes the chain terminator from the root round to covered_through_contact_round_id; it never changes the root basis or participant authority pair.
* core · object · $ref #/$defs/bilateral_continuity_checkpoint_core
Domain-neutral, root-anchored commitment to one contiguous prefix of a bilateral lineage. Sequence is monotonic; same sequence with a different checkpoint digest is a fork, never a winner election.
allOf · allOf[0] ·
?* context ·
const "ak.contact.round.continuity.v1"enum:
"ak.contact.round.continuity.v1"* participant_ids · array<$ref #/$defs/actor_id>
The two exact ActorIds, sorted by RFC 8785 canonical bytes.
items ·
…recursion truncated at depth 8; see source schema for full shape
* root_basis · allOf[2]
Portable uncheckpointed root Contact round evidence. It is retained so founder and root identity remain independently derivable after prefix compaction.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* covered_through_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestThe exact terminal contact_round_id at the compacted-prefix boundary. The oldest remaining tail edge points here; bundle content digests are accumulated only in prefix_accumulator_root.
pattern:
^sha256:[0-9a-f]{64}$* prefix_accumulator_root ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* covered_prefix_count ·
integer* sequence ·
integerprevious_checkpoint_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* checkpoint_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH(ak.bilateral-continuity.checkpoint.v1, canonical core).
pattern:
^sha256:[0-9a-f]{64}$* signatures · array<$ref #/$defs/bilateral_continuity_checkpoint_signature>
Exactly one signature by each registered participant authority key over the checkpoint core.
items · object · $ref #/$defs/bilateral_continuity_checkpoint_signature
* signer_id ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
message ·
stringoneOf · oneOf[1] · object
* phase ·
const "commit"enum:
"commit"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* idempotency_key ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* signed_event · allOf[2]
allOf · allOf[0] · object · $ref ./principal-operations.schema.json#/$defs/signed_event
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.contact.requested"enum:
"ak.contact.requested"anyOf · anyOf[1] · allOf[2] · $ref #/$defs/contact_request_outcome
allOf · allOf[0] · oneOf[11] · $ref #/$defs/contact_operation_outcome
oneOf · oneOf[0] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "request"enum:
"request"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[1] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "response"enum:
"response"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[2] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "reject"enum:
"reject"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[3] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "scope_update"enum:
"scope_update"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[4] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "tombstone"enum:
"tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[5] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "request"enum:
"request"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* request_acceptance_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[6] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "response"enum:
"response"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* normal_response_acceptance_receipt · object · $ref #/$defs/normal_response_acceptance_receipt
Source Station attestation issued only after the exact response Event's command unit is committed and its Contact effect atomically installed. Pending admission or proposal acknowledgement is not this receipt.
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
* delegated_actor_did ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* response_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted response Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel response_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* outgoing_slot_absence_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH('ak.contact.no_outgoing_slot.v1', outgoing_slot_absence_transcript) over the exact closed transcript defined by identity/contact-and-direct-conversation.md section 2.
pattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[7] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "reject"enum:
"reject"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reject_acceptance_receipt · object · $ref #/$defs/reject_acceptance_receipt
Source Station attestation of the committed Contact rejection Event, which is a successful terminal domain command. A RealmCommit-rejected command or pending Event cannot produce this receipt.
allOf · allOf[0] ·
?* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
* delegated_actor_did ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* reject_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted reject Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel reject_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[8] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "scope_update"enum:
"scope_update"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[9] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "tombstone"enum:
"tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[10] · object
* status ·
const "failed"enum:
"failed"* result_kind ·
string (enum)enum:
"request" "response" "reject" "scope_update" "tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reason ·
string (enum)enum:
"contact_idempotency_conflict" "contact_round_conflict" "contact_lineage_conflict" "contact_terminal" "contact_scope_stale"allOf · allOf[1] · object
* result_kind ·
const "request"enum:
"request"anyOf · anyOf[2] · oneOf[2] · $ref #/$defs/contact_respond_request_body
oneOf · oneOf[0] · object
* phase ·
const "prepare"enum:
"prepare"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* idempotency_key ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* request_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* action ·
const "accept"enum:
"accept"* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"oneOf · oneOf[1] · object
* phase ·
const "commit"enum:
"commit"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* idempotency_key ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* signed_event · allOf[2]
allOf · allOf[0] · object · $ref ./principal-operations.schema.json#/$defs/signed_event
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.contact.accepted"enum:
"ak.contact.accepted"anyOf · anyOf[3] · allOf[2] · $ref #/$defs/contact_respond_outcome
allOf · allOf[0] · oneOf[11] · $ref #/$defs/contact_operation_outcome
oneOf · oneOf[0] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "request"enum:
"request"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[1] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "response"enum:
"response"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[2] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "reject"enum:
"reject"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[3] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "scope_update"enum:
"scope_update"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[4] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "tombstone"enum:
"tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[5] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "request"enum:
"request"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* request_acceptance_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[6] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "response"enum:
"response"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* normal_response_acceptance_receipt · object · $ref #/$defs/normal_response_acceptance_receipt
Source Station attestation issued only after the exact response Event's command unit is committed and its Contact effect atomically installed. Pending admission or proposal acknowledgement is not this receipt.
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
* delegated_actor_did ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* response_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted response Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel response_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* outgoing_slot_absence_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH('ak.contact.no_outgoing_slot.v1', outgoing_slot_absence_transcript) over the exact closed transcript defined by identity/contact-and-direct-conversation.md section 2.
pattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[7] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "reject"enum:
"reject"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reject_acceptance_receipt · object · $ref #/$defs/reject_acceptance_receipt
Source Station attestation of the committed Contact rejection Event, which is a successful terminal domain command. A RealmCommit-rejected command or pending Event cannot produce this receipt.
allOf · allOf[0] ·
?* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
* delegated_actor_did ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* reject_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted reject Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel reject_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[8] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "scope_update"enum:
"scope_update"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[9] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "tombstone"enum:
"tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[10] · object
* status ·
const "failed"enum:
"failed"* result_kind ·
string (enum)enum:
"request" "response" "reject" "scope_update" "tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reason ·
string (enum)enum:
"contact_idempotency_conflict" "contact_round_conflict" "contact_lineage_conflict" "contact_terminal" "contact_scope_stale"allOf · allOf[1] · object
* result_kind ·
const "response"enum:
"response"anyOf · anyOf[4] · oneOf[2] · $ref #/$defs/contact_reject_request_body
oneOf · oneOf[0] · object
* phase ·
const "prepare"enum:
"prepare"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* idempotency_key ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* request_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* action ·
const "reject"enum:
"reject"oneOf · oneOf[1] · object
* phase ·
const "commit"enum:
"commit"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* idempotency_key ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* signed_event · allOf[2]
allOf · allOf[0] · object · $ref ./principal-operations.schema.json#/$defs/signed_event
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.contact.rejected"enum:
"ak.contact.rejected"anyOf · anyOf[5] · allOf[2] · $ref #/$defs/contact_reject_outcome
allOf · allOf[0] · oneOf[11] · $ref #/$defs/contact_operation_outcome
oneOf · oneOf[0] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "request"enum:
"request"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[1] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "response"enum:
"response"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[2] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "reject"enum:
"reject"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[3] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "scope_update"enum:
"scope_update"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[4] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "tombstone"enum:
"tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[5] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "request"enum:
"request"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* request_acceptance_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[6] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "response"enum:
"response"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* normal_response_acceptance_receipt · object · $ref #/$defs/normal_response_acceptance_receipt
Source Station attestation issued only after the exact response Event's command unit is committed and its Contact effect atomically installed. Pending admission or proposal acknowledgement is not this receipt.
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
* delegated_actor_did ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* response_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted response Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel response_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* outgoing_slot_absence_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH('ak.contact.no_outgoing_slot.v1', outgoing_slot_absence_transcript) over the exact closed transcript defined by identity/contact-and-direct-conversation.md section 2.
pattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[7] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "reject"enum:
"reject"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reject_acceptance_receipt · object · $ref #/$defs/reject_acceptance_receipt
Source Station attestation of the committed Contact rejection Event, which is a successful terminal domain command. A RealmCommit-rejected command or pending Event cannot produce this receipt.
allOf · allOf[0] ·
?* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
* delegated_actor_did ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* reject_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted reject Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel reject_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[8] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "scope_update"enum:
"scope_update"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[9] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "tombstone"enum:
"tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[10] · object
* status ·
const "failed"enum:
"failed"* result_kind ·
string (enum)enum:
"request" "response" "reject" "scope_update" "tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reason ·
string (enum)enum:
"contact_idempotency_conflict" "contact_round_conflict" "contact_lineage_conflict" "contact_terminal" "contact_scope_stale"allOf · allOf[1] · object
* result_kind ·
const "reject"enum:
"reject"anyOf · anyOf[6] · object · $ref #/$defs/contact_list
* contacts · array<$ref #/$defs/contact_list_row>
items · object · $ref #/$defs/contact_list_row
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* state ·
string (enum) · $ref #/$defs/contact_stateenum:
"pending_outgoing" "pending_incoming" "accepted" "rejected" "expired" "tombstoned"request_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$request_message ·
stringThe exact verified request Event message, present only for pending_incoming and only when that Event carries message.
response_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$tombstone_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$next_prepare_input · object · $ref #/$defs/contact_next_prepare_input
Closed successor cursor for the holder's own issuer-local Contact lineage, carried only by the ak.self.contact.read.list.v1 projection. The container name carries the tense: version is the version the NEXT Event carries, that is current head version plus one, hence the minimum of 2; predecessor_event_ref is the current lineage head Event ID, that is the predecessor the next Event must name, and never the predecessor of the current head. The three field names are byte-identical to the prepare-phase fields of ak.self.contact.command.scope_update.v1 and ak.self.contact.command.tombstone.v1 and MUST be copied verbatim; a client MUST NOT rename, recompute or derive them, and MUST NOT assemble a successor from request_event_ref, response_event_ref or tombstone_event_ref, which are projection summaries and not authoritative lineage heads. Presence is fixed by contact_state: an accepted row MUST carry it, and a pending_outgoing, pending_incoming, rejected, expired or tombstoned row MUST NOT, because the first two have no contact round or lineage yet and the last three are terminal. Absence is the sole encoding of 'no successor is authorable now'; no extra error code or contact_state value expresses it. A stale cursor is refused by prepare with contact_lineage_conflict or contact_scope_stale; the client MUST re-read this operation and retry with the fresh values, and MUST NOT guess a head or retry the same triple.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* version ·
integer* predecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"* granted_by_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"* bidirectional_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"effective_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
Optional shorthand. When present, MUST equal bidirectional_scopes.
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"continuity_evidence · object · $ref #/$defs/contact_continuity_evidence
Explicit export only: present when include_continuity=true and a committed portable checkpoint exists. Ordinary list responses omit it. Online recontact uses Station durable evidence.
* checkpoint · object · $ref #/$defs/bilateral_continuity_checkpoint
* core · object · $ref #/$defs/bilateral_continuity_checkpoint_core
Domain-neutral, root-anchored commitment to one contiguous prefix of a bilateral lineage. Sequence is monotonic; same sequence with a different checkpoint digest is a fork, never a winner election.
allOf · allOf[0] ·
?* context ·
const "ak.contact.round.continuity.v1"enum:
"ak.contact.round.continuity.v1"* participant_ids · array<$ref #/$defs/actor_id>
The two exact ActorIds, sorted by RFC 8785 canonical bytes.
items · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* root_basis · allOf[2]
Portable uncheckpointed root Contact round evidence. It is retained so founder and root identity remain independently derivable after prefix compaction.
allOf · allOf[0] · object · $ref #/$defs/contact_round_evidence_bundle
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* contact_round_id ·
…recursion truncated at depth 8; see source schema for full shape
previous_terminal_contact_round_id ·
…recursion truncated at depth 8; see source schema for full shape
* contact_round ·
…recursion truncated at depth 8; see source schema for full shape
* request_receipts ·
…recursion truncated at depth 8; see source schema for full shape
normal_response_receipt ·
…recursion truncated at depth 8; see source schema for full shape
glare_concurrency_attestations ·
…recursion truncated at depth 8; see source schema for full shape
* current_proofs ·
…recursion truncated at depth 8; see source schema for full shape
continuity_checkpoint ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
?* covered_through_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestThe exact terminal contact_round_id at the compacted-prefix boundary. The oldest remaining tail edge points here; bundle content digests are accumulated only in prefix_accumulator_root.
pattern:
^sha256:[0-9a-f]{64}$* prefix_accumulator_root ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* covered_prefix_count ·
integer* sequence ·
integerprevious_checkpoint_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* checkpoint_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH(ak.bilateral-continuity.checkpoint.v1, canonical core).
pattern:
^sha256:[0-9a-f]{64}$* signatures · array<$ref #/$defs/bilateral_continuity_checkpoint_signature>
Exactly one signature by each registered participant authority key over the checkpoint core.
items · object · $ref #/$defs/bilateral_continuity_checkpoint_signature
* signer_id · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
* uncompressed_tail_entries · array<$ref #/$defs/contact_round_evidence_bundle>
Immediate predecessor first; at least the latest terminal round remains explicit, and the final edge must terminate exactly at checkpoint.core.covered_through_contact_round_id.
items · object · $ref #/$defs/contact_round_evidence_bundle
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestAbsent only for a root Contact round. On recontact it is copied from every signed request fact and request acceptance receipt in this bundle and points to the immediately preceding terminal round. The bundle field is derived convenience, never independent authority.
pattern:
^sha256:[0-9a-f]{64}$* contact_round · oneOf[2] · $ref #/$defs/contact_round
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* sorted_pair_member_ids ·
…recursion truncated at depth 8; see source schema for full shape
* request_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* request_acceptance_receipt_digest ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* sorted_pair_member_ids ·
…recursion truncated at depth 8; see source schema for full shape
* requests ·
…recursion truncated at depth 8; see source schema for full shape
* request_receipts · array<$ref #/$defs/request_acceptance_receipt>
items · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core ·
…recursion truncated at depth 8; see source schema for full shape
* receipt_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
normal_response_receipt · object · $ref #/$defs/normal_response_acceptance_receipt
Source Station attestation issued only after the exact response Event's command unit is committed and its Contact effect atomically installed. Pending admission or proposal acknowledgement is not this receipt.
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core ·
…recursion truncated at depth 8; see source schema for full shape
* receipt_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
* response_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted response Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel response_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* outgoing_slot_absence_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH('ak.contact.no_outgoing_slot.v1', outgoing_slot_absence_transcript) over the exact closed transcript defined by identity/contact-and-direct-conversation.md section 2.
pattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
glare_concurrency_attestations · array<$ref #/$defs/glare_concurrency_attestation>
items · object · $ref #/$defs/glare_concurrency_attestation
Source-service-signed evidence for the subject_id -> peer_id direction that both request receipts were accepted while neither request slot had yet been consumed. A glare bundle requires the two opposite directions; issuer_id is the signing service and is never used as the participant discriminator.
* subject_id ·
…recursion truncated at depth 8; see source schema for full shape
* issuer_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer_id ·
…recursion truncated at depth 8; see source schema for full shape
* request_receipt_digests ·
…recursion truncated at depth 8; see source schema for full shape
* observed_commit_event_ids ·
…recursion truncated at depth 8; see source schema for full shape
* complete_through ·
…recursion truncated at depth 8; see source schema for full shape
* unconsumed_slot_checkpoint ·
…recursion truncated at depth 8; see source schema for full shape
* observed_at ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
* current_proofs · array<$ref #/$defs/contact_current_proof>
items · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
…recursion truncated at depth 8; see source schema for full shape
* issuer_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer ·
…recursion truncated at depth 8; see source schema for full shape
* head_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* terminal ·
…recursion truncated at depth 8; see source schema for full shape
* accepted_commit_event_ids ·
…recursion truncated at depth 8; see source schema for full shape
* complete_through ·
…recursion truncated at depth 8; see source schema for full shape
* fresh_until ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
continuity_checkpoint · object · $ref #/$defs/bilateral_continuity_checkpoint
Latest mutually signed compacted prefix for this lineage. Its presence changes the chain terminator from the root round to covered_through_contact_round_id; it never changes the root basis or participant authority pair.
* core · object · $ref #/$defs/bilateral_continuity_checkpoint_core
Domain-neutral, root-anchored commitment to one contiguous prefix of a bilateral lineage. Sequence is monotonic; same sequence with a different checkpoint digest is a fork, never a winner election.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* context ·
…recursion truncated at depth 8; see source schema for full shape
* participant_ids ·
…recursion truncated at depth 8; see source schema for full shape
* root_basis ·
…recursion truncated at depth 8; see source schema for full shape
* covered_through_contact_round_id ·
…recursion truncated at depth 8; see source schema for full shape
* prefix_accumulator_root ·
…recursion truncated at depth 8; see source schema for full shape
* covered_prefix_count ·
…recursion truncated at depth 8; see source schema for full shape
* sequence ·
…recursion truncated at depth 8; see source schema for full shape
previous_checkpoint_digest ·
…recursion truncated at depth 8; see source schema for full shape
* checkpoint_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH(ak.bilateral-continuity.checkpoint.v1, canonical core).
pattern:
^sha256:[0-9a-f]{64}$* signatures · array<$ref #/$defs/bilateral_continuity_checkpoint_signature>
Exactly one signature by each registered participant authority key over the checkpoint core.
items ·
…recursion truncated at depth 8; see source schema for full shape
direct_conversation · object · $ref #/$defs/direct_conversation_summary
Contact-list projection of an already materialized stable Direct Conversation. Coordinates and binding identity are immutable; state only says whether the same conversation is currently sendable. Creation progress is exposed only by direct_conversation_resolve_outcome; there is no durable creation operation, draft or reservation.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* main_strand_id ·
string · $ref #/$defs/strand_idpattern:
^ak:strand:[A-Za-z0-9_-]{44}$* binding_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* state ·
string (enum)enum:
"found" "suspended"contact_agents · array<$ref #/$defs/contact_agent_projection>
items · object · $ref #/$defs/contact_agent_projection
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$display_name ·
stringagent_slug ·
string (arkret-agent-slug) · format=arkret-agent-slug · $ref string-profiles.schema.json#/$defs/agent_slugCanonical controller-scoped Agent Agent selector slug. Maximum 64 Unicode code points in prepared form.
pattern:
^[^\s:@/#?\\]+$avatar_blob_ref ·
string · $ref #/$defs/blob_refContent-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern:
^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$direct_conversation · object · $ref #/$defs/direct_conversation_summary
Contact-list projection of an already materialized stable Direct Conversation. Coordinates and binding identity are immutable; state only says whether the same conversation is currently sendable. Creation progress is exposed only by direct_conversation_resolve_outcome; there is no durable creation operation, draft or reservation.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* main_strand_id ·
string · $ref #/$defs/strand_idpattern:
^ak:strand:[A-Za-z0-9_-]{44}$* binding_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* state ·
string (enum)enum:
"found" "suspended"peer_endpoint · object · $ref #/$defs/contact_peer_endpoint
Exact selector mechanically derived from the verified peer producer of the selected accepted Contact round. Not current Device or MLS authority. Omit when no verified source exists.
* contact_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$next_cursor ·
string · $ref #/$defs/cursorpattern:
^ak:cursor:[A-Za-z0-9_-]+$* has_more ·
booleananyOf · anyOf[7] · oneOf[2] · $ref #/$defs/contact_tombstone_request_body
oneOf · oneOf[0] · object
* phase ·
const "prepare"enum:
"prepare"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* idempotency_key ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* version ·
integer* predecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* block_peer ·
booleanHolder-private commit side effect. true adds the peer to invite receive policy denied_subjects; false only tombstones the Contact lineage. This field is reservation-bound and is not copied into the public Contact Event payload.
oneOf · oneOf[1] · object
* phase ·
const "commit"enum:
"commit"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* idempotency_key ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* signed_event · allOf[2]
allOf · allOf[0] · object · $ref ./principal-operations.schema.json#/$defs/signed_event
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.contact.tombstone"enum:
"ak.contact.tombstone"anyOf · anyOf[8] · allOf[2] · $ref #/$defs/contact_tombstone
allOf · allOf[0] · oneOf[11] · $ref #/$defs/contact_operation_outcome
oneOf · oneOf[0] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "request"enum:
"request"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[1] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "response"enum:
"response"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[2] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "reject"enum:
"reject"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[3] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "scope_update"enum:
"scope_update"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[4] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "tombstone"enum:
"tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[5] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "request"enum:
"request"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* request_acceptance_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[6] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "response"enum:
"response"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* normal_response_acceptance_receipt · object · $ref #/$defs/normal_response_acceptance_receipt
Source Station attestation issued only after the exact response Event's command unit is committed and its Contact effect atomically installed. Pending admission or proposal acknowledgement is not this receipt.
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
* delegated_actor_did ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* response_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted response Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel response_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* outgoing_slot_absence_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH('ak.contact.no_outgoing_slot.v1', outgoing_slot_absence_transcript) over the exact closed transcript defined by identity/contact-and-direct-conversation.md section 2.
pattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[7] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "reject"enum:
"reject"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reject_acceptance_receipt · object · $ref #/$defs/reject_acceptance_receipt
Source Station attestation of the committed Contact rejection Event, which is a successful terminal domain command. A RealmCommit-rejected command or pending Event cannot produce this receipt.
allOf · allOf[0] ·
?* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
* delegated_actor_did ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* reject_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted reject Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel reject_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[8] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "scope_update"enum:
"scope_update"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[9] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "tombstone"enum:
"tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[10] · object
* status ·
const "failed"enum:
"failed"* result_kind ·
string (enum)enum:
"request" "response" "reject" "scope_update" "tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reason ·
string (enum)enum:
"contact_idempotency_conflict" "contact_round_conflict" "contact_lineage_conflict" "contact_terminal" "contact_scope_stale"allOf · allOf[1] · object
* result_kind ·
const "tombstone"enum:
"tombstone"anyOf · anyOf[9] · oneOf[2] · $ref #/$defs/contact_scope_update_request_body
oneOf · oneOf[0] · object
* phase ·
const "prepare"enum:
"prepare"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* idempotency_key ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* version ·
integer* predecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"oneOf · oneOf[1] · object
* phase ·
const "commit"enum:
"commit"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* idempotency_key ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* signed_event · allOf[2]
allOf · allOf[0] · object · $ref ./principal-operations.schema.json#/$defs/signed_event
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.contact.scope.update"enum:
"ak.contact.scope.update"anyOf · anyOf[10] · allOf[2] · $ref #/$defs/contact_scope_update_outcome
allOf · allOf[0] · oneOf[11] · $ref #/$defs/contact_operation_outcome
oneOf · oneOf[0] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "request"enum:
"request"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[1] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "response"enum:
"response"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[2] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "reject"enum:
"reject"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[3] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "scope_update"enum:
"scope_update"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[4] · object
* status ·
const "prepared"enum:
"prepared"* result_kind ·
const "tombstone"enum:
"tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reservation_handle ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* event_draft · object · $ref ./principal-operations.schema.json#/$defs/prepared_event_draft
Service-built canonical producer Event digest-payload bytes with producer_proof and reducer-managed fields absent. The client MUST decode these exact bytes under the suite carried by event_digest, add only the required producer proof, and return the resulting signed Event. Event id and kind are derived views, never parallel wire inputs.
* unsigned_event_bytes ·
$ref #/$defs/base64url · $ref #/$defs/base64url* event_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestSHA-256 digest of unsigned_event_bytes under the fixed current-v1 Event identity suite. The value MUST use the sha256 prefix; no Realm state selects or changes it.
pattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[5] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "request"enum:
"request"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* request_acceptance_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[6] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "response"enum:
"response"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* normal_response_acceptance_receipt · object · $ref #/$defs/normal_response_acceptance_receipt
Source Station attestation issued only after the exact response Event's command unit is committed and its Contact effect atomically installed. Pending admission or proposal acknowledgement is not this receipt.
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
* delegated_actor_did ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* response_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted response Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel response_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* outgoing_slot_absence_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH('ak.contact.no_outgoing_slot.v1', outgoing_slot_absence_transcript) over the exact closed transcript defined by identity/contact-and-direct-conversation.md section 2.
pattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[7] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "reject"enum:
"reject"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reject_acceptance_receipt · object · $ref #/$defs/reject_acceptance_receipt
Source Station attestation of the committed Contact rejection Event, which is a successful terminal domain command. A RealmCommit-rejected command or pending Event cannot produce this receipt.
allOf · allOf[0] ·
?* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* public_key_b64u ·
…recursion truncated at depth 8; see source schema for full shape
* delegated_actor_did ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* reject_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted reject Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel reject_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[8] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "scope_update"enum:
"scope_update"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[9] · object
* status ·
const "accepted"enum:
"accepted"* result_kind ·
const "tombstone"enum:
"tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* lineage · object · $ref #/$defs/contact_lineage
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* version ·
integerpredecessor_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* granted_to_peer_scopes · array<$ref #/$defs/contact_scope> · $ref #/$defs/contact_scopes
items ·
string (enum) · $ref #/$defs/contact_scopeenum:
"invite" "direct_message" "voice_call" "video_call" "presence"terminal ·
boolean* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proof · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[10] · object
* status ·
const "failed"enum:
"failed"* result_kind ·
string (enum)enum:
"request" "response" "reject" "scope_update" "tombstone"* operation_id ·
string · $ref ./principal-operations.schema.json#/$defs/operation_idpattern:
^ak:operation:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reason ·
string (enum)enum:
"contact_idempotency_conflict" "contact_round_conflict" "contact_lineage_conflict" "contact_terminal" "contact_scope_stale"allOf · allOf[1] · object
* result_kind ·
const "scope_update"enum:
"scope_update"anyOf · anyOf[11] · object · $ref #/$defs/contact_continuity_checkpoint_request_body
Holder-authorized command to compact the deterministic oldest terminal prefix. The caller never supplies the checkpoint core or boundary.
* idempotency_key ·
string · $ref ./principal-operations.schema.json#/$defs/opaque_id* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$anyOf · anyOf[12] · object · $ref #/$defs/contact_continuity_checkpoint_outcome
allOf · allOf[0] ·
?* status ·
string (enum)enum:
"pending" "committed"* checkpoint_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$continuity_evidence · object · $ref #/$defs/contact_continuity_evidence
* checkpoint · object · $ref #/$defs/bilateral_continuity_checkpoint
* core · object · $ref #/$defs/bilateral_continuity_checkpoint_core
Domain-neutral, root-anchored commitment to one contiguous prefix of a bilateral lineage. Sequence is monotonic; same sequence with a different checkpoint digest is a fork, never a winner election.
allOf · allOf[0] ·
?* context ·
const "ak.contact.round.continuity.v1"enum:
"ak.contact.round.continuity.v1"* participant_ids · array<$ref #/$defs/actor_id>
The two exact ActorIds, sorted by RFC 8785 canonical bytes.
items · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* root_basis · allOf[2]
Portable uncheckpointed root Contact round evidence. It is retained so founder and root identity remain independently derivable after prefix compaction.
allOf · allOf[0] · object · $ref #/$defs/contact_round_evidence_bundle
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestAbsent only for a root Contact round. On recontact it is copied from every signed request fact and request acceptance receipt in this bundle and points to the immediately preceding terminal round. The bundle field is derived convenience, never independent authority.
pattern:
^sha256:[0-9a-f]{64}$* contact_round · oneOf[2] · $ref #/$defs/contact_round
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* sorted_pair_member_ids ·
…recursion truncated at depth 8; see source schema for full shape
* request_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* request_acceptance_receipt_digest ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* sorted_pair_member_ids ·
…recursion truncated at depth 8; see source schema for full shape
* requests ·
…recursion truncated at depth 8; see source schema for full shape
* request_receipts · array<$ref #/$defs/request_acceptance_receipt>
items · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core ·
…recursion truncated at depth 8; see source schema for full shape
* receipt_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
normal_response_receipt · object · $ref #/$defs/normal_response_acceptance_receipt
Source Station attestation issued only after the exact response Event's command unit is committed and its Contact effect atomically installed. Pending admission or proposal acknowledgement is not this receipt.
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core ·
…recursion truncated at depth 8; see source schema for full shape
* receipt_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
* response_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted response Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel response_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* outgoing_slot_absence_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH('ak.contact.no_outgoing_slot.v1', outgoing_slot_absence_transcript) over the exact closed transcript defined by identity/contact-and-direct-conversation.md section 2.
pattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
glare_concurrency_attestations · array<$ref #/$defs/glare_concurrency_attestation>
items · object · $ref #/$defs/glare_concurrency_attestation
Source-service-signed evidence for the subject_id -> peer_id direction that both request receipts were accepted while neither request slot had yet been consumed. A glare bundle requires the two opposite directions; issuer_id is the signing service and is never used as the participant discriminator.
* subject_id ·
…recursion truncated at depth 8; see source schema for full shape
* issuer_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer_id ·
…recursion truncated at depth 8; see source schema for full shape
* request_receipt_digests ·
…recursion truncated at depth 8; see source schema for full shape
* observed_commit_event_ids ·
…recursion truncated at depth 8; see source schema for full shape
* complete_through ·
…recursion truncated at depth 8; see source schema for full shape
* unconsumed_slot_checkpoint ·
…recursion truncated at depth 8; see source schema for full shape
* observed_at ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
* current_proofs · array<$ref #/$defs/contact_current_proof>
items · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
…recursion truncated at depth 8; see source schema for full shape
* issuer_id ·
…recursion truncated at depth 8; see source schema for full shape
* peer ·
…recursion truncated at depth 8; see source schema for full shape
* head_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* terminal ·
…recursion truncated at depth 8; see source schema for full shape
* accepted_commit_event_ids ·
…recursion truncated at depth 8; see source schema for full shape
* complete_through ·
…recursion truncated at depth 8; see source schema for full shape
* fresh_until ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
continuity_checkpoint · object · $ref #/$defs/bilateral_continuity_checkpoint
Latest mutually signed compacted prefix for this lineage. Its presence changes the chain terminator from the root round to covered_through_contact_round_id; it never changes the root basis or participant authority pair.
* core · object · $ref #/$defs/bilateral_continuity_checkpoint_core
Domain-neutral, root-anchored commitment to one contiguous prefix of a bilateral lineage. Sequence is monotonic; same sequence with a different checkpoint digest is a fork, never a winner election.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* context ·
…recursion truncated at depth 8; see source schema for full shape
* participant_ids ·
…recursion truncated at depth 8; see source schema for full shape
* root_basis ·
…recursion truncated at depth 8; see source schema for full shape
* covered_through_contact_round_id ·
…recursion truncated at depth 8; see source schema for full shape
* prefix_accumulator_root ·
…recursion truncated at depth 8; see source schema for full shape
* covered_prefix_count ·
…recursion truncated at depth 8; see source schema for full shape
* sequence ·
…recursion truncated at depth 8; see source schema for full shape
previous_checkpoint_digest ·
…recursion truncated at depth 8; see source schema for full shape
* checkpoint_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH(ak.bilateral-continuity.checkpoint.v1, canonical core).
pattern:
^sha256:[0-9a-f]{64}$* signatures · array<$ref #/$defs/bilateral_continuity_checkpoint_signature>
Exactly one signature by each registered participant authority key over the checkpoint core.
items ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
?* covered_through_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestThe exact terminal contact_round_id at the compacted-prefix boundary. The oldest remaining tail edge points here; bundle content digests are accumulated only in prefix_accumulator_root.
pattern:
^sha256:[0-9a-f]{64}$* prefix_accumulator_root ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* covered_prefix_count ·
integer* sequence ·
integerprevious_checkpoint_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* checkpoint_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH(ak.bilateral-continuity.checkpoint.v1, canonical core).
pattern:
^sha256:[0-9a-f]{64}$* signatures · array<$ref #/$defs/bilateral_continuity_checkpoint_signature>
Exactly one signature by each registered participant authority key over the checkpoint core.
items · object · $ref #/$defs/bilateral_continuity_checkpoint_signature
* signer_id · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* uncompressed_tail_entries · array<$ref #/$defs/contact_round_evidence_bundle>
Immediate predecessor first; at least the latest terminal round remains explicit, and the final edge must terminate exactly at checkpoint.core.covered_through_contact_round_id.
items · object · $ref #/$defs/contact_round_evidence_bundle
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestAbsent only for a root Contact round. On recontact it is copied from every signed request fact and request acceptance receipt in this bundle and points to the immediately preceding terminal round. The bundle field is derived convenience, never independent authority.
pattern:
^sha256:[0-9a-f]{64}$* contact_round · oneOf[2] · $ref #/$defs/contact_round
oneOf · oneOf[0] · object
* kind ·
const "normal"enum:
"normal"* sorted_pair_member_ids · array<$ref #/$defs/actor_id>
Exactly two distinct full ActorIds, strictly ascending by their RFC 8785 JCS UTF-8 unsigned bytes. Validation rejects noncanonical order without sorting the received array.
items · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* request_event_ref ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* request_acceptance_receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[1] · object
* kind ·
const "glare"enum:
"glare"* sorted_pair_member_ids · array<$ref #/$defs/actor_id>
Exactly two distinct full ActorIds, strictly ascending by their RFC 8785 JCS UTF-8 unsigned bytes. Validation rejects noncanonical order without sorting the received array.
items · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* requests · array<object>
Exactly two distinct request_event_ref values, strictly ascending by the complete typed EventId wire string UTF-8 unsigned bytes. Receipt digest is not a sort key or tiebreaker. Duplicate refs are invalid even with different digests. Receivers reject unsorted input without normalization. The signed request Event author ActorId of requests[0], not the Station receipt issuer_id, is the root-round founder.
items · object
* request_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* request_acceptance_receipt_digest ·
…recursion truncated at depth 8; see source schema for full shape
* request_receipts · array<$ref #/$defs/request_acceptance_receipt>
items · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$normal_response_receipt · object · $ref #/$defs/normal_response_acceptance_receipt
Source Station attestation issued only after the exact response Event's command unit is committed and its Contact effect atomically installed. Pending admission or proposal acknowledgement is not this receipt.
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* request_receipt · object · $ref #/$defs/request_acceptance_receipt
Source Station attestation issued only after the exact request Event's command unit is committed and its Contact effect atomically installed. It may seed normal/glare round evidence; a pending admission receipt cannot occupy this type.
* core · object · $ref #/$defs/request_acceptance_receipt_core
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* holder · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* peer · oneOf[2] · $ref #/$defs/contact_peer
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* slot_version ·
integerslot_predecessor ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestPresent exactly when this accepted request starts a recontact after a prior accepted Contact round became terminal. It MUST equal the requester-signed ak.contact.requested payload field and is covered by receipt_digest/signature. It is distinct from slot_predecessor, which is the issuer-local request-slot CAS predecessor and can also follow a rejected proposal.
pattern:
^sha256:[0-9a-f]{64}$* request_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted request Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel request_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* source_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receipt_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* response_event_ref ·
string · $ref #/$defs/event_idComplete identity of the accepted response Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel response_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* producer_signer · oneOf[2] · $ref #/$defs/contact_producer_signer
Exact-Event source-signed producer projection. Closed direct and delegated branches are distinguished by delegated_actor_did presence, with no new wire tag. Enclosing carrier validation MUST select delegated if and only if the original Event is a legal Agent controller-device Event with executed_by; human and Agent runtime use direct. Method/raw32 authenticate the original producer, while delegated_actor_did only locates the independently verified Agent public identity. No reusable authorization, new endpoint or private PCR disclosure is created.
oneOf · oneOf[0] · object · $ref #/$defs/contact_direct_producer_signer
Closed direct producer branch for human-device and Agent-runtime Contact Events. The original Event has no executed_by; its producer method already locates its Actor DID. No delegated_actor_did is permitted.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$oneOf · oneOf[1] · object · $ref #/$defs/contact_delegated_producer_signer
Closed delegated producer branch, required exactly for a legal Agent controller-device Contact Event with executed_by. The receiver verifies the original producer signature and separately validates this complete Agent DID history against exact actor/controller/Station and the create-locked tuple.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* public_key_b64u ·
stringCanonical unpadded base64url of the exact Ed25519 raw32 key independently verified by the source for this confirmed Contact Event.
pattern:
^[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$* delegated_actor_did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* outgoing_slot_absence_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH('ak.contact.no_outgoing_slot.v1', outgoing_slot_absence_transcript) over the exact closed transcript defined by identity/contact-and-direct-conversation.md section 2.
pattern:
^sha256:[0-9a-f]{64}$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$glare_concurrency_attestations · array<$ref #/$defs/glare_concurrency_attestation>
items · object · $ref #/$defs/glare_concurrency_attestation
Source-service-signed evidence for the subject_id -> peer_id direction that both request receipts were accepted while neither request slot had yet been consumed. A glare bundle requires the two opposite directions; issuer_id is the signing service and is never used as the participant discriminator.
* subject_id · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer_id · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* request_receipt_digests · array<$ref ./principal-operations.schema.json#/$defs/digest>
items ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* observed_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integer* unconsumed_slot_checkpoint ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* observed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$* current_proofs · array<$ref #/$defs/contact_current_proof>
items · object · $ref #/$defs/contact_current_proof
Existing source Station attestation of its confirmed directional Contact projection. Authorizing proofs are issued only after the exact source command is committed by the unique confirmed RealmCommit; the peer verifies the independently derived Station's historical service authority and the original holder producer separately, without receiving private PCR history.
* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* peer · oneOf[2] · $ref #/$defs/contact_peer
Signed peer component of the issuer-local lineage key. The directional subject is the other exact member of the bound Contact pair.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* controller_account_id ·
…recursion truncated at depth 8; see source schema for full shape
* head_event_ref ·
string · $ref #/$defs/event_idComplete identity of the actual confirmed current-head Event at proof issuance. It may equal the carrier's original fact or be its authenticated same-direction successor; exact coverage requires the complete verified predecessor chain, never only a larger complete_through. A round-wide terminal uses the separately verified source tombstone and counterpart fence rules. Missing chain material stays non-authorizing pending. A source MUST NOT sign a superseded fact as a fresh head or backdate a proof. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel head_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal ·
booleanSigned current-head classification. true authenticates the round-wide fence from a confirmed ak.contact.tombstone; both directional proofs may reference that same source tombstone without inventing another holder Event. The counterpart verifies the original source proof and retains its own direction's complete_through version. Incomplete local direction material permits a known-terminal fence but no fabricated completeness proof. A historical predecessor in a recontact continuity chain requires true from both directional proofs.
* accepted_commit_event_ids · array<$ref #/$defs/event_id>
items ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* complete_through ·
integerLast completely authenticated version of the direction identified by (contact_round_id, issuer_id, peer): version 1 is either the normal responder's initial accepted Event or a founding request head, which covers both glare sides and the normal requester (identity/contact-and-direct-conversation.md section 3, founding edge); successors use their confirmed payload.version. Never the PCR stream position, request slot_version, RealmCommit height or receiver time. A counterpart terminal acknowledgement retains its local confirmed version, without copying the remote version or incrementing it.
* fresh_until ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$continuity_checkpoint · object · $ref #/$defs/bilateral_continuity_checkpoint
Latest mutually signed compacted prefix for this lineage. Its presence changes the chain terminator from the root round to covered_through_contact_round_id; it never changes the root basis or participant authority pair.
* core · object · $ref #/$defs/bilateral_continuity_checkpoint_core
Domain-neutral, root-anchored commitment to one contiguous prefix of a bilateral lineage. Sequence is monotonic; same sequence with a different checkpoint digest is a fork, never a winner election.
allOf · allOf[0] ·
?* context ·
const "ak.contact.round.continuity.v1"enum:
"ak.contact.round.continuity.v1"* participant_ids · array<$ref #/$defs/actor_id>
The two exact ActorIds, sorted by RFC 8785 canonical bytes.
items · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* root_basis · allOf[2]
Portable uncheckpointed root Contact round evidence. It is retained so founder and root identity remain independently derivable after prefix compaction.
allOf · allOf[0] · object · $ref #/$defs/contact_round_evidence_bundle
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* contact_round_id ·
…recursion truncated at depth 8; see source schema for full shape
previous_terminal_contact_round_id ·
…recursion truncated at depth 8; see source schema for full shape
* contact_round ·
…recursion truncated at depth 8; see source schema for full shape
* request_receipts ·
…recursion truncated at depth 8; see source schema for full shape
normal_response_receipt ·
…recursion truncated at depth 8; see source schema for full shape
glare_concurrency_attestations ·
…recursion truncated at depth 8; see source schema for full shape
* current_proofs ·
…recursion truncated at depth 8; see source schema for full shape
continuity_checkpoint ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
?* covered_through_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestThe exact terminal contact_round_id at the compacted-prefix boundary. The oldest remaining tail edge points here; bundle content digests are accumulated only in prefix_accumulator_root.
pattern:
^sha256:[0-9a-f]{64}$* prefix_accumulator_root ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* covered_prefix_count ·
integer* sequence ·
integerprevious_checkpoint_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* checkpoint_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestH(ak.bilateral-continuity.checkpoint.v1, canonical core).
pattern:
^sha256:[0-9a-f]{64}$* signatures · array<$ref #/$defs/bilateral_continuity_checkpoint_signature>
Exactly one signature by each registered participant authority key over the checkpoint core.
items · object · $ref #/$defs/bilateral_continuity_checkpoint_signature
* signer_id · oneOf[2] · $ref #/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* signature · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
anyOf · anyOf[13] · object · $ref ./direct-conversation-operations.schema.json#/$defs/direct_conversation_resolve_request
Closed query body for ak.self.direct_conversation.read.resolve.v1. Creation is never carried here: a Direct Conversation Realm is created only by the derived founder through the direct_conversation_genesis admission variant of ak.realm.create.
* peer · oneOf[2] · $ref ./contact-operations.schema.json#/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* station_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$anyOf · anyOf[14] · object · $ref ./direct-conversation-operations.schema.json#/$defs/direct_conversation_resolve_outcome
Closed tagged outcome of ak.self.direct_conversation.read.resolve.v1. Evaluation order is fixed: temporarily_unavailable when the current basis or founder cannot be verified; then creation_blocked, creation_required or awaiting_founder while no Realm exists; then suspended for identity, materialization, terminal or gate conflicts; then provisional while no binding endorsement exists; found last. awaiting_founder never transfers authority by timeout, recovery policy, successor designation or permanent-unavailability inference; v1 defines no founder_unrecoverable state.
oneOf · oneOf[0] · object
* state ·
const "creation_required"enum:
"creation_required"* next_founding_input ·
$ref #/$defs/direct_conversation_founding_input · $ref #/$defs/direct_conversation_founding_inputoneOf · oneOf[1] · object
* state ·
const "creation_blocked"enum:
"creation_blocked"* blockers · array<$ref #/$defs/direct_conversation_send_blocker>
items ·
$ref #/$defs/direct_conversation_send_blocker · $ref #/$defs/direct_conversation_send_blockeroneOf · oneOf[2] · object
* state ·
const "awaiting_founder"enum:
"awaiting_founder"retry_after_ms ·
integeroneOf · oneOf[3] · object
* state ·
const "provisional"enum:
"provisional"* coordinates ·
$ref #/$defs/direct_conversation_coordinates · $ref #/$defs/direct_conversation_coordinates* authorization_basis · object · $ref ./event-payload.schema.json#/$defs/direct_conversation_authorization_basis
Canonical authorization basis for creating a Direct Conversation. accepted_contact carries exactly the accepted contact request/accept refs. agent_controller carries exactly two unique accepted Event refs: the controller-authored ak.agent.provision Event, whose payload already binds the Agent, controller, delegation, accountability and selector facts, and the current active ak.agent.key.authorize Event.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* kind ·
string (enum)enum:
"accepted_contact" "agent_controller"* event_refs · array<$ref #/$defs/event_ref>
items ·
$ref #/$defs/event_ref · $ref #/$defs/event_refgroup_state_ref ·
string · $ref ./principal-operations.schema.json#/$defs/event_idComplete Event identity of the unique derived MLS group's exact current winning Genesis/Commit state. Consumers recover the suite and full Event digest from this ID.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$initial_exact_pair_group_state_ref ·
string · $ref ./principal-operations.schema.json#/$defs/event_idImmutable first accepted exact-pair winning state; present once it exists and never replaced by a repair Commit.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* peer_mls_admission ·
string (enum)Authoritative current occupied peer leaf admission state at this read cut; not a write authorization or a client timer.
enum:
"missing" "pending" "durable" "repair_required"oneOf · oneOf[4] · object
* state ·
const "found"enum:
"found"* coordinates ·
$ref #/$defs/direct_conversation_coordinates · $ref #/$defs/direct_conversation_coordinates* group_state_ref ·
string · $ref ./principal-operations.schema.json#/$defs/event_idComplete Event identity of the exact current winning group-state Event.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* send_blockers · array<$ref #/$defs/direct_conversation_send_blocker>
items ·
$ref #/$defs/direct_conversation_send_blocker · $ref #/$defs/direct_conversation_send_blockeroneOf · oneOf[5] · object
* state ·
const "suspended"enum:
"suspended"* coordinates ·
$ref #/$defs/direct_conversation_coordinates · $ref #/$defs/direct_conversation_coordinates* blockers · array<$ref #/$defs/direct_conversation_send_blocker>
items ·
$ref #/$defs/direct_conversation_send_blocker · $ref #/$defs/direct_conversation_send_blockergroup_state_ref ·
string · $ref ./principal-operations.schema.json#/$defs/event_idPresent whenever the unique derived group has an accepted current state.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[6] · object
* state ·
const "temporarily_unavailable"enum:
"temporarily_unavailable"retry_after_ms ·
integerSource
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/contact-operations.schema.json