ak.schema.current_principal_outcome.v1
ak.schema.current_principal_outcome.v1 · file: schemas/identity-resolution.schema.json Canonical did_core_id/did resolution state, owner-published evidence and service-route bootstrap contracts. A did is a standard bare DID and a did_core_id is the stable Arkret business identity projected by a registered DID method adapter.
* $ · oneOf[4]
Canonical did_core_id/did resolution state, owner-published evidence and service-route bootstrap contracts. A did is a standard bare DID and a did_core_id is the stable Arkret business identity projected by a registered DID method adapter.
oneOf · oneOf[0] · object · $ref #/$defs/public_principal_resolution
Complete public resolution response for one account selected by account_id. It is the only unauthenticated resolution surface and it MUST NOT carry principal_control_realm_id, PCR genesis Event, genesis receipt, resolution Events or accepted RealmCommit; those are account-internal audit material served only by the authorized audit operation. A consumer verifies the service route for account_id.station_id, then the attestation proof, then project(did)=account_id.principal_id and the bounded method history; a set of bare unproven fields is not a valid response.
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* resolution_projection · object · $ref #/$defs/resolution_projection
Current accepted value of the singleton resolution typed current result. resolution_event_ref is an opaque head coordinate for staleness comparison; it is not a handle for fetching that Event through any public surface.
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* method_history_evidence · oneOf[3] · $ref #/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · object · $ref #/$defs/webvh_method_history_evidence
Complete did:webvh log, proof and witness material routed by evidence_kind webvh_log to the active did:webvh adapter. log_entries is the gap-free native history from inception through boundary.to_version_id, not a resolver summary or a partial segment. witness_records is the complete did-witness.json record set required by every witness policy active in that interval and is empty only when no entry activates a witness policy. The receiver independently verifies SCID derivation, every versionId/hash-chain link, every controller proof, rotation authorization, all applicable witness thresholds, the exact boundary endpoints and canonical equality of the terminal state with normalized_did_document. Canonical encoded evidence MUST NOT exceed 1 MiB; an over-limit service history is ineligible for retained historical-signer and governance-Station bootstrap and fails closed rather than returning partial evidence.
* evidence_kind ·
const "webvh_log"enum:
"webvh_log"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
string* from_version_id ·
stringpattern:
^(?!ak:)* to_method_history_head ·
string* to_version_id ·
stringpattern:
^(?!ak:)* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
const "ak.did.binding_evidence.v1"enum:
"ak.did.binding_evidence.v1"* method ·
$ref #/$defs/method_token · $ref #/$defs/method_token* document_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of the resolver's verified normalized DID Document projection (did-usage-and-verification.md section 5.1); never the raw response bytes (those use the differently named raw_document_digest).
* method_proofs · array<$ref #/$defs/webvh_log_evidence>
Closed per-method proof rows; empty for proofless methods (did:key, bare did:web). v1 registers exactly one row kind (webvh_log); receiving any unregistered proof kind fails closed. Rows never reuse resolver response order: each row kind registers its own canonical sort and duplicate-rejection rules.
items ·
$ref #/$defs/webvh_log_evidence · $ref #/$defs/webvh_log_evidence* log_entries · array<object>
Exact ordered native did:webvh entry objects from inception through the selected terminal entry. The adapter applies the registered did:webvh parameter-name and proof rules and rejects gaps, duplicates, surplus entries after boundary.to_version_id, or a first entry other than inception.
items ·
object* witness_records · array<object>
Exact native did-witness.json record objects needed by log_entries. Records are keyed uniquely by versionId; missing, duplicate, invalid or surplus records fail closed. The array is empty exactly when the verified log activates no witness policy.
items ·
objectoneOf · oneOf[1] · object · $ref #/$defs/did_web_method_history_evidence
Bounded current DID Document retrieval evidence routed by evidence_kind did_web_document to the active did:web adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
const "did_web_document"enum:
"did_web_document"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
string* from_version_id ·
stringpattern:
^(?!ak:)* to_method_history_head ·
string* to_version_id ·
stringpattern:
^(?!ak:)* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
const "ak.did.binding_evidence.v1"enum:
"ak.did.binding_evidence.v1"* method ·
$ref #/$defs/method_token · $ref #/$defs/method_token* document_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of the resolver's verified normalized DID Document projection (did-usage-and-verification.md section 5.1); never the raw response bytes (those use the differently named raw_document_digest).
* method_proofs · array<$ref #/$defs/webvh_log_evidence>
Closed per-method proof rows; empty for proofless methods (did:key, bare did:web). v1 registers exactly one row kind (webvh_log); receiving any unregistered proof kind fails closed. Rows never reuse resolver response order: each row kind registers its own canonical sort and duplicate-rejection rules.
items ·
$ref #/$defs/webvh_log_evidence · $ref #/$defs/webvh_log_evidenceoneOf · oneOf[2] · object · $ref #/$defs/did_key_method_history_evidence
Bounded deterministic local expansion evidence routed by evidence_kind did_key_expansion to the active did:key adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
const "did_key_expansion"enum:
"did_key_expansion"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
string* from_version_id ·
stringpattern:
^(?!ak:)* to_method_history_head ·
string* to_version_id ·
stringpattern:
^(?!ak:)* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
const "ak.did.binding_evidence.v1"enum:
"ak.did.binding_evidence.v1"* method ·
$ref #/$defs/method_token · $ref #/$defs/method_token* document_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of the resolver's verified normalized DID Document projection (did-usage-and-verification.md section 5.1); never the raw response bytes (those use the differently named raw_document_digest).
* method_proofs · array<$ref #/$defs/webvh_log_evidence>
Closed per-method proof rows; empty for proofless methods (did:key, bare did:web). v1 registers exactly one row kind (webvh_log); receiving any unregistered proof kind fails closed. Rows never reuse resolver response order: each row kind registers its own canonical sort and duplicate-rejection rules.
items ·
$ref #/$defs/webvh_log_evidence · $ref #/$defs/webvh_log_evidence* projection_attestation · object · $ref #/$defs/principal_resolution_projection_attestation
Complete Station-signed projection attestation. The detached proof signs the canonical transcript above; proof.created_at MUST equal attestation.issued_at.
* attestation · object · $ref #/$defs/principal_resolution_projection_attestation_core
Station assertion that resolution_projection is the current accepted value of this account's singleton resolution typed current result. It carries no PCR realm id, Event, receipt or RealmCommit: the public consumer verifies the account pair, the projection and the bounded method history, not the account's internal control stream.
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* resolution_projection · object · $ref #/$defs/resolution_projection
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* method_history_evidence_digest ·
string · $ref #/$defs/sha256_digestLowercase hexadecimal SHA-256 digest.
pattern:
^sha256:[0-9a-f]{64}$* issued_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[1] · object · $ref #/$defs/principal_resolution_audit_evidence
Account-internal resolution audit and recovery evidence for one account selected by account_id. It is served only by the authorized audit operation. PCR genesis, realm and RealmCommit material support account-local audit and recovery; they MUST NOT be compared as external identity, MUST NOT be required to validate an ordinary federated Event, which is verified from its producer proof and the RealmCommit that admitted it, and MUST NOT be republished on any unauthenticated surface.
allOf · allOf[0] ·
?* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* principal_genesis_event · allOf[2] · $ref #/$defs/principal_genesis_event
The accepted identity-control Realm genesis Event. It is resolution history head 0 and commits the initial resolution; its derived Realm id, actor, purpose and initial projection are cross-bound by the principal resolution evidence evaluator.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idexecuted_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idauthorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.realm.create"enum:
"ak.realm.create"* scope_ref · object
* kind ·
const "realm_genesis"enum:
"realm_genesis"* payload · object
* object · object
* purpose ·
string (enum)enum:
"principal_control" "agent_control" "applet_managed_control"* initial_resolution · object · $ref #/$defs/resolution_commitment
Owner-committed current did and method-native history position. For a deterministic method, method_history_head and version_id use the adapter-defined deterministic canonical values; they are never omitted.
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* founding_device_authorize_event · allOf[2] · $ref #/$defs/founding_device_authorize_event
The founding device authorization Event immediately following the PCR realm.create Event.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idexecuted_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idauthorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.device.authorize"enum:
"ak.device.authorize"* genesis_commits · array
The two consecutive RealmCommit objects accepting principal_genesis_event and founding_device_authorize_event in that order.
[0] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[4] · $ref #
Canonical did_core_id/did resolution state, owner-published evidence and service-route bootstrap contracts. A did is a standard bare DID and a did_core_id is the stable Arkret business identity projected by a registered DID method adapter.
oneOf · oneOf[0] · object · $ref #/$defs/public_principal_resolution
Complete public resolution response for one account selected by account_id. It is the only unauthenticated resolution surface and it MUST NOT carry principal_control_realm_id, PCR genesis Event, genesis receipt, resolution Events or accepted RealmCommit; those are account-internal audit material served only by the authorized audit operation. A consumer verifies the service route for account_id.station_id, then the attestation proof, then project(did)=account_id.principal_id and the bounded method history; a set of bare unproven fields is not a valid response.
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* resolution_projection · object · $ref #/$defs/resolution_projection
Current accepted value of the singleton resolution typed current result. resolution_event_ref is an opaque head coordinate for staleness comparison; it is not a handle for fetching that Event through any public surface.
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* method_history_evidence · oneOf[3] · $ref #/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · object · $ref #/$defs/webvh_method_history_evidence
Complete did:webvh log, proof and witness material routed by evidence_kind webvh_log to the active did:webvh adapter. log_entries is the gap-free native history from inception through boundary.to_version_id, not a resolver summary or a partial segment. witness_records is the complete did-witness.json record set required by every witness policy active in that interval and is empty only when no entry activates a witness policy. The receiver independently verifies SCID derivation, every versionId/hash-chain link, every controller proof, rotation authorization, all applicable witness thresholds, the exact boundary endpoints and canonical equality of the terminal state with normalized_did_document. Canonical encoded evidence MUST NOT exceed 1 MiB; an over-limit service history is ineligible for retained historical-signer and governance-Station bootstrap and fails closed rather than returning partial evidence.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
* log_entries ·
…recursion truncated at depth 8; see source schema for full shape
* witness_records ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/did_web_method_history_evidence
Bounded current DID Document retrieval evidence routed by evidence_kind did_web_document to the active did:web adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/did_key_method_history_evidence
Bounded deterministic local expansion evidence routed by evidence_kind did_key_expansion to the active did:key adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
* projection_attestation · object · $ref #/$defs/principal_resolution_projection_attestation
Complete Station-signed projection attestation. The detached proof signs the canonical transcript above; proof.created_at MUST equal attestation.issued_at.
* attestation · object · $ref #/$defs/principal_resolution_projection_attestation_core
Station assertion that resolution_projection is the current accepted value of this account's singleton resolution typed current result. It carries no PCR realm id, Event, receipt or RealmCommit: the public consumer verifies the account pair, the projection and the bounded method history, not the account's internal control stream.
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
* resolution_projection ·
…recursion truncated at depth 8; see source schema for full shape
* method_history_evidence_digest ·
…recursion truncated at depth 8; see source schema for full shape
* issued_at ·
…recursion truncated at depth 8; see source schema for full shape
* expires_at ·
…recursion truncated at depth 8; see source schema for full shape
* proof · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/principal_resolution_audit_evidence
Account-internal resolution audit and recovery evidence for one account selected by account_id. It is served only by the authorized audit operation. PCR genesis, realm and RealmCommit material support account-local audit and recovery; they MUST NOT be compared as external identity, MUST NOT be required to validate an ordinary federated Event, which is verified from its producer proof and the RealmCommit that admitted it, and MUST NOT be republished on any unauthenticated surface.
allOf · allOf[0] ·
?* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* principal_genesis_event · allOf[2] · $ref #/$defs/principal_genesis_event
The accepted identity-control Realm genesis Event. It is resolution history head 0 and commits the initial resolution; its derived Realm id, actor, purpose and initial projection are cross-bound by the principal resolution evidence evaluator.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* founding_device_authorize_event · allOf[2] · $ref #/$defs/founding_device_authorize_event
The founding device authorization Event immediately following the PCR realm.create Event.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* genesis_commits · array
The two consecutive RealmCommit objects accepting principal_genesis_event and founding_device_authorize_event in that order.
[0] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* authority_ref ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
…recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
[1] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* authority_ref ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
…recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
* current_resolution_event · oneOf[2] · $ref #/$defs/current_resolution_event
oneOf · oneOf[0] · allOf[2] · $ref #/$defs/principal_genesis_event
The accepted identity-control Realm genesis Event. It is resolution history head 0 and commits the initial resolution; its derived Realm id, actor, purpose and initial projection are cross-bound by the principal resolution evidence evaluator.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · allOf[2] · $ref #/$defs/resolution_update_event
One accepted post-genesis resolution successor Event. Its exact resolution-typed current result expected_revision precondition and predecessor fields are mandatory under Event dispatch.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* predecessor_resolution_events · array<$ref #/$defs/resolution_update_event>
Post-genesis resolution update Events preceding current_resolution_event, ordered from the current event's immediate predecessor toward older events and contiguous with no gaps. The genesis Event is carried separately and MUST NOT be repeated here. The segment ends at whichever comes first: request history_depth items, the exclusive request after_resolution_event_ref ancestor, or head 0. A server MAY return a shorter contiguous segment than requested when a response bound applies, MUST NOT return more items than history_depth, and MUST NOT skip an intermediate Event.
items · allOf[2] · $ref #/$defs/resolution_update_event
One accepted post-genesis resolution successor Event. Its exact resolution-typed current result expected_revision precondition and predecessor fields are mandatory under Event dispatch.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* accepted_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* history_complete ·
booleanTrue exactly when the disclosed segment reaches its requested stop condition: head 0, or the exclusive after_resolution_event_ref ancestor. False means disclosure was truncated and next_audit_cursor is present. Omitted history is unknown rather than absent.
next_audit_cursor ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$method_history_evidence · oneOf[3] · $ref #/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · object · $ref #/$defs/webvh_method_history_evidence
Complete did:webvh log, proof and witness material routed by evidence_kind webvh_log to the active did:webvh adapter. log_entries is the gap-free native history from inception through boundary.to_version_id, not a resolver summary or a partial segment. witness_records is the complete did-witness.json record set required by every witness policy active in that interval and is empty only when no entry activates a witness policy. The receiver independently verifies SCID derivation, every versionId/hash-chain link, every controller proof, rotation authorization, all applicable witness thresholds, the exact boundary endpoints and canonical equality of the terminal state with normalized_did_document. Canonical encoded evidence MUST NOT exceed 1 MiB; an over-limit service history is ineligible for retained historical-signer and governance-Station bootstrap and fails closed rather than returning partial evidence.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
* log_entries ·
…recursion truncated at depth 8; see source schema for full shape
* witness_records ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/did_web_method_history_evidence
Bounded current DID Document retrieval evidence routed by evidence_kind did_web_document to the active did:web adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/did_key_method_history_evidence
Bounded deterministic local expansion evidence routed by evidence_kind did_key_expansion to the active did:key adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* service_kind ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$* method_history_evidence · oneOf[3] · $ref #/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · object · $ref #/$defs/webvh_method_history_evidence
Complete did:webvh log, proof and witness material routed by evidence_kind webvh_log to the active did:webvh adapter. log_entries is the gap-free native history from inception through boundary.to_version_id, not a resolver summary or a partial segment. witness_records is the complete did-witness.json record set required by every witness policy active in that interval and is empty only when no entry activates a witness policy. The receiver independently verifies SCID derivation, every versionId/hash-chain link, every controller proof, rotation authorization, all applicable witness thresholds, the exact boundary endpoints and canonical equality of the terminal state with normalized_did_document. Canonical encoded evidence MUST NOT exceed 1 MiB; an over-limit service history is ineligible for retained historical-signer and governance-Station bootstrap and fails closed rather than returning partial evidence.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
* log_entries ·
…recursion truncated at depth 8; see source schema for full shape
* witness_records ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/did_web_method_history_evidence
Bounded current DID Document retrieval evidence routed by evidence_kind did_web_document to the active did:web adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/did_key_method_history_evidence
Bounded deterministic local expansion evidence routed by evidence_kind did_key_expansion to the active did:key adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did ·
$ref #/$defs/did · $ref #/$defs/did* contexts · array<oneOf[2]>
items ·
…recursion truncated at depth 8; see source schema for full shape
* controller_dids · array<$ref #/$defs/did>
items ·
…recursion truncated at depth 8; see source schema for full shape
* also_known_as · array<string>
items ·
…recursion truncated at depth 8; see source schema for full shape
* verification_methods · array<$ref #/$defs/normalized_did_verification_method>
items ·
…recursion truncated at depth 8; see source schema for full shape
* authentication ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* assertion_methods ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* key_agreements ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* capability_invocations ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* capability_delegations ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* services · array<$ref #/$defs/normalized_did_service>
items ·
…recursion truncated at depth 8; see source schema for full shape
* metadata ·
$ref #/$defs/normalized_did_document_metadata · $ref #/$defs/normalized_did_document_metadata* extensions · array<$ref #/$defs/normalized_did_document_extension>
items ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object · $ref #/$defs/current_principal_outcome
* request_id ·
string · $ref ./account-operations.schema.json#/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* resolution_projection · object · $ref #/$defs/resolution_projection
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$allOf · allOf[1] · object
context ·
const "ak.realm_commit_signature.v1"enum:
"ak.realm_commit_signature.v1"[1] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[4] · $ref #
Canonical did_core_id/did resolution state, owner-published evidence and service-route bootstrap contracts. A did is a standard bare DID and a did_core_id is the stable Arkret business identity projected by a registered DID method adapter.
oneOf · oneOf[0] · object · $ref #/$defs/public_principal_resolution
Complete public resolution response for one account selected by account_id. It is the only unauthenticated resolution surface and it MUST NOT carry principal_control_realm_id, PCR genesis Event, genesis receipt, resolution Events or accepted RealmCommit; those are account-internal audit material served only by the authorized audit operation. A consumer verifies the service route for account_id.station_id, then the attestation proof, then project(did)=account_id.principal_id and the bounded method history; a set of bare unproven fields is not a valid response.
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* resolution_projection · object · $ref #/$defs/resolution_projection
Current accepted value of the singleton resolution typed current result. resolution_event_ref is an opaque head coordinate for staleness comparison; it is not a handle for fetching that Event through any public surface.
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* method_history_evidence · oneOf[3] · $ref #/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · object · $ref #/$defs/webvh_method_history_evidence
Complete did:webvh log, proof and witness material routed by evidence_kind webvh_log to the active did:webvh adapter. log_entries is the gap-free native history from inception through boundary.to_version_id, not a resolver summary or a partial segment. witness_records is the complete did-witness.json record set required by every witness policy active in that interval and is empty only when no entry activates a witness policy. The receiver independently verifies SCID derivation, every versionId/hash-chain link, every controller proof, rotation authorization, all applicable witness thresholds, the exact boundary endpoints and canonical equality of the terminal state with normalized_did_document. Canonical encoded evidence MUST NOT exceed 1 MiB; an over-limit service history is ineligible for retained historical-signer and governance-Station bootstrap and fails closed rather than returning partial evidence.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
* log_entries ·
…recursion truncated at depth 8; see source schema for full shape
* witness_records ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/did_web_method_history_evidence
Bounded current DID Document retrieval evidence routed by evidence_kind did_web_document to the active did:web adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/did_key_method_history_evidence
Bounded deterministic local expansion evidence routed by evidence_kind did_key_expansion to the active did:key adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
* projection_attestation · object · $ref #/$defs/principal_resolution_projection_attestation
Complete Station-signed projection attestation. The detached proof signs the canonical transcript above; proof.created_at MUST equal attestation.issued_at.
* attestation · object · $ref #/$defs/principal_resolution_projection_attestation_core
Station assertion that resolution_projection is the current accepted value of this account's singleton resolution typed current result. It carries no PCR realm id, Event, receipt or RealmCommit: the public consumer verifies the account pair, the projection and the bounded method history, not the account's internal control stream.
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
* resolution_projection ·
…recursion truncated at depth 8; see source schema for full shape
* method_history_evidence_digest ·
…recursion truncated at depth 8; see source schema for full shape
* issued_at ·
…recursion truncated at depth 8; see source schema for full shape
* expires_at ·
…recursion truncated at depth 8; see source schema for full shape
* proof · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
* jws ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/principal_resolution_audit_evidence
Account-internal resolution audit and recovery evidence for one account selected by account_id. It is served only by the authorized audit operation. PCR genesis, realm and RealmCommit material support account-local audit and recovery; they MUST NOT be compared as external identity, MUST NOT be required to validate an ordinary federated Event, which is verified from its producer proof and the RealmCommit that admitted it, and MUST NOT be republished on any unauthenticated surface.
allOf · allOf[0] ·
?* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* principal_genesis_event · allOf[2] · $ref #/$defs/principal_genesis_event
The accepted identity-control Realm genesis Event. It is resolution history head 0 and commits the initial resolution; its derived Realm id, actor, purpose and initial projection are cross-bound by the principal resolution evidence evaluator.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* founding_device_authorize_event · allOf[2] · $ref #/$defs/founding_device_authorize_event
The founding device authorization Event immediately following the PCR realm.create Event.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* genesis_commits · array
The two consecutive RealmCommit objects accepting principal_genesis_event and founding_device_authorize_event in that order.
[0] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* authority_ref ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
…recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
[1] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
* commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* stream_ref ·
…recursion truncated at depth 8; see source schema for full shape
* stream_position ·
…recursion truncated at depth 8; see source schema for full shape
* previous_commit_ref ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* governance_generation ·
…recursion truncated at depth 8; see source schema for full shape
* authority_ref ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
…recursion truncated at depth 8; see source schema for full shape
producer_signer_fact_digest ·
…recursion truncated at depth 8; see source schema for full shape
* signature ·
…recursion truncated at depth 8; see source schema for full shape
* current_resolution_event · oneOf[2] · $ref #/$defs/current_resolution_event
oneOf · oneOf[0] · allOf[2] · $ref #/$defs/principal_genesis_event
The accepted identity-control Realm genesis Event. It is resolution history head 0 and commits the initial resolution; its derived Realm id, actor, purpose and initial projection are cross-bound by the principal resolution evidence evaluator.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · allOf[2] · $ref #/$defs/resolution_update_event
One accepted post-genesis resolution successor Event. Its exact resolution-typed current result expected_revision precondition and predecessor fields are mandatory under Event dispatch.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* predecessor_resolution_events · array<$ref #/$defs/resolution_update_event>
Post-genesis resolution update Events preceding current_resolution_event, ordered from the current event's immediate predecessor toward older events and contiguous with no gaps. The genesis Event is carried separately and MUST NOT be repeated here. The segment ends at whichever comes first: request history_depth items, the exclusive request after_resolution_event_ref ancestor, or head 0. A server MAY return a shorter contiguous segment than requested when a response bound applies, MUST NOT return more items than history_depth, and MUST NOT skip an intermediate Event.
items · allOf[2] · $ref #/$defs/resolution_update_event
One accepted post-genesis resolution successor Event. Its exact resolution-typed current result expected_revision precondition and predecessor fields are mandatory under Event dispatch.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* accepted_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* history_complete ·
booleanTrue exactly when the disclosed segment reaches its requested stop condition: head 0, or the exclusive after_resolution_event_ref ancestor. False means disclosure was truncated and next_audit_cursor is present. Omitted history is unknown rather than absent.
next_audit_cursor ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$method_history_evidence · oneOf[3] · $ref #/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · object · $ref #/$defs/webvh_method_history_evidence
Complete did:webvh log, proof and witness material routed by evidence_kind webvh_log to the active did:webvh adapter. log_entries is the gap-free native history from inception through boundary.to_version_id, not a resolver summary or a partial segment. witness_records is the complete did-witness.json record set required by every witness policy active in that interval and is empty only when no entry activates a witness policy. The receiver independently verifies SCID derivation, every versionId/hash-chain link, every controller proof, rotation authorization, all applicable witness thresholds, the exact boundary endpoints and canonical equality of the terminal state with normalized_did_document. Canonical encoded evidence MUST NOT exceed 1 MiB; an over-limit service history is ineligible for retained historical-signer and governance-Station bootstrap and fails closed rather than returning partial evidence.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
* log_entries ·
…recursion truncated at depth 8; see source schema for full shape
* witness_records ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/did_web_method_history_evidence
Bounded current DID Document retrieval evidence routed by evidence_kind did_web_document to the active did:web adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/did_key_method_history_evidence
Bounded deterministic local expansion evidence routed by evidence_kind did_key_expansion to the active did:key adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* service_kind ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$* method_history_evidence · oneOf[3] · $ref #/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · object · $ref #/$defs/webvh_method_history_evidence
Complete did:webvh log, proof and witness material routed by evidence_kind webvh_log to the active did:webvh adapter. log_entries is the gap-free native history from inception through boundary.to_version_id, not a resolver summary or a partial segment. witness_records is the complete did-witness.json record set required by every witness policy active in that interval and is empty only when no entry activates a witness policy. The receiver independently verifies SCID derivation, every versionId/hash-chain link, every controller proof, rotation authorization, all applicable witness thresholds, the exact boundary endpoints and canonical equality of the terminal state with normalized_did_document. Canonical encoded evidence MUST NOT exceed 1 MiB; an over-limit service history is ineligible for retained historical-signer and governance-Station bootstrap and fails closed rather than returning partial evidence.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
* log_entries ·
…recursion truncated at depth 8; see source schema for full shape
* witness_records ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/did_web_method_history_evidence
Bounded current DID Document retrieval evidence routed by evidence_kind did_web_document to the active did:web adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/did_key_method_history_evidence
Bounded deterministic local expansion evidence routed by evidence_kind did_key_expansion to the active did:key adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
…recursion truncated at depth 8; see source schema for full shape
* boundary ·
…recursion truncated at depth 8; see source schema for full shape
* evidence ·
…recursion truncated at depth 8; see source schema for full shape
* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did ·
$ref #/$defs/did · $ref #/$defs/did* contexts · array<oneOf[2]>
items ·
…recursion truncated at depth 8; see source schema for full shape
* controller_dids · array<$ref #/$defs/did>
items ·
…recursion truncated at depth 8; see source schema for full shape
* also_known_as · array<string>
items ·
…recursion truncated at depth 8; see source schema for full shape
* verification_methods · array<$ref #/$defs/normalized_did_verification_method>
items ·
…recursion truncated at depth 8; see source schema for full shape
* authentication ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* assertion_methods ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* key_agreements ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* capability_invocations ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* capability_delegations ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* services · array<$ref #/$defs/normalized_did_service>
items ·
…recursion truncated at depth 8; see source schema for full shape
* metadata ·
$ref #/$defs/normalized_did_document_metadata · $ref #/$defs/normalized_did_document_metadata* extensions · array<$ref #/$defs/normalized_did_document_extension>
items ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] · object · $ref #/$defs/current_principal_outcome
* request_id ·
string · $ref ./account-operations.schema.json#/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* resolution_projection · object · $ref #/$defs/resolution_projection
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$allOf · allOf[1] · object
context ·
const "ak.realm_commit_signature.v1"enum:
"ak.realm_commit_signature.v1"* current_resolution_event · oneOf[2] · $ref #/$defs/current_resolution_event
oneOf · oneOf[0] · allOf[2] · $ref #/$defs/principal_genesis_event
The accepted identity-control Realm genesis Event. It is resolution history head 0 and commits the initial resolution; its derived Realm id, actor, purpose and initial projection are cross-bound by the principal resolution evidence evaluator.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idexecuted_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idauthorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.realm.create"enum:
"ak.realm.create"* scope_ref · object
* kind ·
const "realm_genesis"enum:
"realm_genesis"* payload · object
* object · object
* purpose ·
string (enum)enum:
"principal_control" "agent_control" "applet_managed_control"* initial_resolution · object · $ref #/$defs/resolution_commitment
Owner-committed current did and method-native history position. For a deterministic method, method_history_head and version_id use the adapter-defined deterministic canonical values; they are never omitted.
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)oneOf · oneOf[1] · allOf[2] · $ref #/$defs/resolution_update_event
One accepted post-genesis resolution successor Event. Its exact resolution-typed current result expected_revision precondition and predecessor fields are mandatory under Event dispatch.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idexecuted_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idauthorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.identity.resolution.update"enum:
"ak.identity.resolution.update"* predecessor_resolution_events · array<$ref #/$defs/resolution_update_event>
Post-genesis resolution update Events preceding current_resolution_event, ordered from the current event's immediate predecessor toward older events and contiguous with no gaps. The genesis Event is carried separately and MUST NOT be repeated here. The segment ends at whichever comes first: request history_depth items, the exclusive request after_resolution_event_ref ancestor, or head 0. A server MAY return a shorter contiguous segment than requested when a response bound applies, MUST NOT return more items than history_depth, and MUST NOT skip an intermediate Event.
items · allOf[2] · $ref #/$defs/resolution_update_event
One accepted post-genesis resolution successor Event. Its exact resolution-typed current result expected_revision precondition and predecessor fields are mandatory under Event dispatch.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idexecuted_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idauthorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refoneOf · oneOf[1] ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[2] ·
$ref #/$defs/did_delegation_ref · $ref #/$defs/did_delegation_refoneOf · oneOf[3] ·
$ref #/$defs/direct_conversation_participant_authority_ref · $ref #/$defs/direct_conversation_participant_authority_refoneOf · oneOf[4] ·
$ref #/$defs/direct_conversation_bootstrap_authority_ref · $ref #/$defs/direct_conversation_bootstrap_authority_refoneOf · oneOf[5] ·
$ref #/$defs/membership_compensation_delegation_ref · $ref #/$defs/membership_compensation_delegation_refapplet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
$ref #/$defs/semantic_ref · $ref #/$defs/semantic_ref* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.identity.resolution.update"enum:
"ak.identity.resolution.update"* accepted_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[4] · $ref #
Canonical did_core_id/did resolution state, owner-published evidence and service-route bootstrap contracts. A did is a standard bare DID and a did_core_id is the stable Arkret business identity projected by a registered DID method adapter.
oneOf · oneOf[0] · object · $ref #/$defs/public_principal_resolution
Complete public resolution response for one account selected by account_id. It is the only unauthenticated resolution surface and it MUST NOT carry principal_control_realm_id, PCR genesis Event, genesis receipt, resolution Events or accepted RealmCommit; those are account-internal audit material served only by the authorized audit operation. A consumer verifies the service route for account_id.station_id, then the attestation proof, then project(did)=account_id.principal_id and the bounded method history; a set of bare unproven fields is not a valid response.
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* resolution_projection · object · $ref #/$defs/resolution_projection
Current accepted value of the singleton resolution typed current result. resolution_event_ref is an opaque head coordinate for staleness comparison; it is not a handle for fetching that Event through any public surface.
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* method_history_evidence · oneOf[3] · $ref #/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · object · $ref #/$defs/webvh_method_history_evidence
Complete did:webvh log, proof and witness material routed by evidence_kind webvh_log to the active did:webvh adapter. log_entries is the gap-free native history from inception through boundary.to_version_id, not a resolver summary or a partial segment. witness_records is the complete did-witness.json record set required by every witness policy active in that interval and is empty only when no entry activates a witness policy. The receiver independently verifies SCID derivation, every versionId/hash-chain link, every controller proof, rotation authorization, all applicable witness thresholds, the exact boundary endpoints and canonical equality of the terminal state with normalized_did_document. Canonical encoded evidence MUST NOT exceed 1 MiB; an over-limit service history is ineligible for retained historical-signer and governance-Station bootstrap and fails closed rather than returning partial evidence.
* evidence_kind ·
const "webvh_log"enum:
"webvh_log"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* from_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* to_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* method ·
…recursion truncated at depth 8; see source schema for full shape
* document_digest ·
…recursion truncated at depth 8; see source schema for full shape
* method_proofs ·
…recursion truncated at depth 8; see source schema for full shape
* log_entries · array<object>
Exact ordered native did:webvh entry objects from inception through the selected terminal entry. The adapter applies the registered did:webvh parameter-name and proof rules and rejects gaps, duplicates, surplus entries after boundary.to_version_id, or a first entry other than inception.
items ·
…recursion truncated at depth 8; see source schema for full shape
* witness_records · array<object>
Exact native did-witness.json record objects needed by log_entries. Records are keyed uniquely by versionId; missing, duplicate, invalid or surplus records fail closed. The array is empty exactly when the verified log activates no witness policy.
items ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/did_web_method_history_evidence
Bounded current DID Document retrieval evidence routed by evidence_kind did_web_document to the active did:web adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
const "did_web_document"enum:
"did_web_document"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* from_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* to_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* method ·
…recursion truncated at depth 8; see source schema for full shape
* document_digest ·
…recursion truncated at depth 8; see source schema for full shape
* method_proofs ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/did_key_method_history_evidence
Bounded deterministic local expansion evidence routed by evidence_kind did_key_expansion to the active did:key adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
const "did_key_expansion"enum:
"did_key_expansion"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* from_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* to_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* method ·
…recursion truncated at depth 8; see source schema for full shape
* document_digest ·
…recursion truncated at depth 8; see source schema for full shape
* method_proofs ·
…recursion truncated at depth 8; see source schema for full shape
* projection_attestation · object · $ref #/$defs/principal_resolution_projection_attestation
Complete Station-signed projection attestation. The detached proof signs the canonical transcript above; proof.created_at MUST equal attestation.issued_at.
* attestation · object · $ref #/$defs/principal_resolution_projection_attestation_core
Station assertion that resolution_projection is the current accepted value of this account's singleton resolution typed current result. It carries no PCR realm id, Event, receipt or RealmCommit: the public consumer verifies the account pair, the projection and the bounded method history, not the account's internal control stream.
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
…recursion truncated at depth 8; see source schema for full shape
* station_id ·
…recursion truncated at depth 8; see source schema for full shape
* resolution_projection · object · $ref #/$defs/resolution_projection
* did ·
…recursion truncated at depth 8; see source schema for full shape
* method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* version_id ·
…recursion truncated at depth 8; see source schema for full shape
* resolution_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* updated_at ·
…recursion truncated at depth 8; see source schema for full shape
* method_history_evidence_digest ·
string · $ref #/$defs/sha256_digestLowercase hexadecimal SHA-256 digest.
pattern:
^sha256:[0-9a-f]{64}$* issued_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[1] · object · $ref #/$defs/principal_resolution_audit_evidence
Account-internal resolution audit and recovery evidence for one account selected by account_id. It is served only by the authorized audit operation. PCR genesis, realm and RealmCommit material support account-local audit and recovery; they MUST NOT be compared as external identity, MUST NOT be required to validate an ordinary federated Event, which is verified from its producer proof and the RealmCommit that admitted it, and MUST NOT be republished on any unauthenticated surface.
allOf · allOf[0] ·
?* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* principal_genesis_event · allOf[2] · $ref #/$defs/principal_genesis_event
The accepted identity-control Realm genesis Event. It is resolution history head 0 and commits the initial resolution; its derived Realm id, actor, purpose and initial projection are cross-bound by the principal resolution evidence evaluator.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.realm.create"enum:
"ak.realm.create"* scope_ref · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* payload · object
* object ·
…recursion truncated at depth 8; see source schema for full shape
* founding_device_authorize_event · allOf[2] · $ref #/$defs/founding_device_authorize_event
The founding device authorization Event immediately following the PCR realm.create Event.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
$ref #/$defs/registered_admission_shape · $ref #/$defs/registered_admission_shapeallOf · allOf[6] ·
$ref #/$defs/registered_execution_shape · $ref #/$defs/registered_execution_shapeallOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?allOf · allOf[15] ·
?allOf · allOf[16] ·
?allOf · allOf[17] ·
?allOf · allOf[18] ·
?allOf · allOf[19] ·
?allOf · allOf[20] ·
?allOf · allOf[21] ·
?allOf · allOf[22] ·
?allOf · allOf[23] ·
?allOf · allOf[24] ·
?allOf · allOf[25] ·
?allOf · allOf[26] ·
?allOf · allOf[27] ·
?allOf · allOf[28] ·
?allOf · allOf[29] ·
?allOf · allOf[30] ·
?allOf · allOf[31] ·
?allOf · allOf[32] ·
?allOf · allOf[33] ·
?allOf · allOf[34] ·
?allOf · allOf[35] ·
?allOf · allOf[36] ·
?allOf · allOf[37] ·
?allOf · allOf[38] ·
?allOf · allOf[39] ·
?allOf · allOf[40] ·
?allOf · allOf[41] ·
?allOf · allOf[42] ·
?allOf · allOf[43] ·
?allOf · allOf[44] ·
?allOf · allOf[45] ·
?allOf · allOf[46] ·
?allOf · allOf[47] ·
?allOf · allOf[48] ·
?allOf · allOf[49] ·
?allOf · allOf[50] ·
?allOf · allOf[51] ·
?allOf · allOf[52] ·
?allOf · allOf[53] ·
?allOf · allOf[54] ·
?allOf · allOf[55] ·
?allOf · allOf[56] ·
?allOf · allOf[57] ·
?allOf · allOf[58] ·
?allOf · allOf[59] ·
?allOf · allOf[60] ·
?allOf · allOf[61] ·
?allOf · allOf[62] ·
?allOf · allOf[63] ·
?allOf · allOf[64] ·
?allOf · allOf[65] ·
?allOf · allOf[66] ·
?allOf · allOf[67] ·
?allOf · allOf[68] ·
?allOf · allOf[69] ·
?allOf · allOf[70] ·
?allOf · allOf[71] ·
?allOf · allOf[72] ·
?allOf · allOf[73] ·
?allOf · allOf[74] ·
?allOf · allOf[75] ·
?allOf · allOf[76] ·
?allOf · allOf[77] ·
?allOf · allOf[78] ·
?allOf · allOf[79] ·
?allOf · allOf[80] ·
?allOf · allOf[81] ·
?allOf · allOf[82] ·
?allOf · allOf[83] ·
?allOf · allOf[84] ·
?allOf · allOf[85] ·
?allOf · allOf[86] ·
?allOf · allOf[87] ·
?allOf · allOf[88] ·
?allOf · allOf[89] ·
?allOf · allOf[90] ·
?allOf · allOf[91] ·
?allOf · allOf[92] ·
?allOf · allOf[93] ·
?allOf · allOf[94] ·
?allOf · allOf[95] ·
?allOf · allOf[96] ·
?allOf · allOf[97] ·
?allOf · allOf[98] ·
?allOf · allOf[99] ·
?allOf · allOf[100] ·
?allOf · allOf[101] ·
?allOf · allOf[102] ·
?allOf · allOf[103] ·
?allOf · allOf[104] ·
?allOf · allOf[105] ·
?allOf · allOf[106] ·
?allOf · allOf[107] ·
?allOf · allOf[108] ·
?allOf · allOf[109] ·
?allOf · allOf[110] ·
?allOf · allOf[111] ·
?allOf · allOf[112] ·
?allOf · allOf[113] ·
?allOf · allOf[114] ·
?allOf · allOf[115] ·
?allOf · allOf[116] ·
?allOf · allOf[117] ·
?allOf · allOf[118] ·
?allOf · allOf[119] ·
?allOf · allOf[120] ·
?allOf · allOf[121] ·
?allOf · allOf[122] ·
?allOf · allOf[123] ·
?allOf · allOf[124] ·
?allOf · allOf[125] ·
?allOf · allOf[126] ·
?allOf · allOf[127] ·
?allOf · allOf[128] ·
?allOf · allOf[129] ·
?allOf · allOf[130] ·
?allOf · allOf[131] ·
?allOf · allOf[132] ·
?allOf · allOf[133] ·
?allOf · allOf[134] ·
?allOf · allOf[135] ·
?allOf · allOf[136] ·
?allOf · allOf[137] ·
?allOf · allOf[138] ·
?allOf · allOf[139] ·
?allOf · allOf[140] ·
?* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* kind ·
stringStandard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* scope_ref ·
$ref #/$defs/scope_ref · $ref #/$defs/scope_refRequired producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
$ref #/$defs/applet_id · $ref #/$defs/applet_idOptional signed Applet provenance. Required by ak.profile.applet_* when the Event is introduced by an Applet, Ghost Actor, bridge, or delegated applet path. Enters canonical event bytes and therefore is covered by proof.event_digest. When present, authorization_ref MUST also be present and resolve to a real active registration/capability grant binding this applet_id, registration_epoch, action and resource per zh/extensions/applet-integration.md sections 4, 8 and 11. Service-actor self-signature proves provenance but is not an authorization substitute. Capability-gated actions require a grant covering action/resource. For subject_only operations the referenced grant binds only the exact active install and cannot replace the subject signature, FSM or independent action authority. Service self-authored Events use ActorId.service; the install grant subject MUST be the same exact ActorId.service as its producer; hosting Station and effective scope are verified separately without coercing a Service into an account variant.
external_ref ·
$ref #/$defs/external_ref · $ref #/$defs/external_refOptional signed external provenance reference for Applet / bridge-originated Events. It is covered by event_digest and MUST NOT be carried only in unsigned when used for loop prevention, audit, or external-message idempotency. Must not contain unauthorized external plaintext.
* created_at ·
$ref #/$defs/canonical_event_timestamp · $ref #/$defs/canonical_event_timestampsemantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
object* producer_proof ·
$ref #/$defs/event_proof · $ref #/$defs/event_proofThe Event's sole portable producer proof. Storage receipts are separate objects and never authorize this Event. producer_proof and unsigned remain outside the canonical Event digest. Exact retries preserve the verified producer proof.
allOf · allOf[1] · object
* kind ·
const "ak.device.authorize"enum:
"ak.device.authorize"* genesis_commits · array
The two consecutive RealmCommit objects accepting principal_genesis_event and founding_device_authorize_event in that order.
[0] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
[1] · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* current_resolution_event · oneOf[2] · $ref #/$defs/current_resolution_event
oneOf · oneOf[0] · allOf[2] · $ref #/$defs/principal_genesis_event
The accepted identity-control Realm genesis Event. It is resolution history head 0 and commits the initial resolution; its derived Realm id, actor, purpose and initial projection are cross-bound by the principal resolution evidence evaluator.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · allOf[2] · $ref #/$defs/resolution_update_event
One accepted post-genesis resolution successor Event. Its exact resolution-typed current result expected_revision precondition and predecessor fields are mandatory under Event dispatch.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* predecessor_resolution_events · array<$ref #/$defs/resolution_update_event>
Post-genesis resolution update Events preceding current_resolution_event, ordered from the current event's immediate predecessor toward older events and contiguous with no gaps. The genesis Event is carried separately and MUST NOT be repeated here. The segment ends at whichever comes first: request history_depth items, the exclusive request after_resolution_event_ref ancestor, or head 0. A server MAY return a shorter contiguous segment than requested when a response bound applies, MUST NOT return more items than history_depth, and MUST NOT skip an intermediate Event.
items · allOf[2] · $ref #/$defs/resolution_update_event
One accepted post-genesis resolution successor Event. Its exact resolution-typed current result expected_revision precondition and predecessor fields are mandatory under Event dispatch.
allOf · allOf[0] · object · $ref ./event-envelope.schema.json
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[4] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[5] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[6] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[7] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[8] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[9] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[10] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[11] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[12] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[13] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[14] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[15] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[16] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[17] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[18] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[19] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[20] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[21] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[22] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[23] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[24] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[25] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[26] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[27] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[28] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[29] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[30] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[31] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[32] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[33] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[34] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[35] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[36] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[37] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[38] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[39] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[40] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[41] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[42] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[43] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[44] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[45] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[46] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[47] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[48] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[49] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[50] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[51] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[52] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[53] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[54] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[55] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[56] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[57] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[58] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[59] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[60] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[61] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[62] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[63] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[64] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[65] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[66] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[67] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[68] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[69] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[70] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[71] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[72] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[73] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[74] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[75] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[76] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[77] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[78] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[79] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[80] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[81] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[82] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[83] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[84] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[85] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[86] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[87] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[88] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[89] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[90] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[91] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[92] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[93] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[94] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[95] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[96] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[97] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[98] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[99] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[100] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[101] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[102] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[103] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[104] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[105] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[106] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[107] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[108] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[109] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[110] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[111] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[112] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[113] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[114] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[115] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[116] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[117] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[118] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[119] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[120] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[121] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[122] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[123] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[124] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[125] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[126] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[127] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[128] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[129] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[130] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[131] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[132] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[133] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[134] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[135] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[136] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[137] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[138] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[139] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[140] ·
…recursion truncated at depth 8; see source schema for full shape
* event_id ·
…recursion truncated at depth 8; see source schema for full shape
* kind ·
…recursion truncated at depth 8; see source schema for full shape
realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* scope_ref ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
executed_by ·
…recursion truncated at depth 8; see source schema for full shape
authorization_ref ·
…recursion truncated at depth 8; see source schema for full shape
applet_id ·
…recursion truncated at depth 8; see source schema for full shape
external_ref ·
…recursion truncated at depth 8; see source schema for full shape
* created_at ·
…recursion truncated at depth 8; see source schema for full shape
semantic_refs ·
…recursion truncated at depth 8; see source schema for full shape
* payload ·
…recursion truncated at depth 8; see source schema for full shape
* producer_proof ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* accepted_commit · object · $ref ./realm-commit.schema.json
The only shared Realm acceptance, ordering, finality and replication record. Every visibility scope has an authority-signed predecessor chain.
allOf · allOf[0] ·
?* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* stream_ref ·
$ref #/$defs/stream_ref · $ref #/$defs/stream_ref* stream_position ·
integer* previous_commit_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
null* event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* governance_generation ·
integerTenure counter of the governing Station that signed this Commit; it advances only on an accepted ak.realm.governance_station.change. It is not the Realm authority-root delegation generation of typed-current-result.schema.json#/$defs/realm_authority_root_value, which advances only on ak.realm.authority.reset.
* authority_ref · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* committed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$producer_signer_fact_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestFixed SHA256 over RFC8785 JCS of the original immutable Human or Applet Service producer fact, excluding the outer target coordinate. Freeze before Commit identity/signature and retain with acceptance; exact replay, replica and handoff preserve this original digest.
pattern:
^sha256:[0-9a-f]{64}$* signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_commit_signature
allOf · allOf[0] · oneOf[4] · $ref #
Canonical did_core_id/did resolution state, owner-published evidence and service-route bootstrap contracts. A did is a standard bare DID and a did_core_id is the stable Arkret business identity projected by a registered DID method adapter.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[3] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* history_complete ·
booleanTrue exactly when the disclosed segment reaches its requested stop condition: head 0, or the exclusive after_resolution_event_ref ancestor. False means disclosure was truncated and next_audit_cursor is present. Omitted history is unknown rather than absent.
next_audit_cursor ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$method_history_evidence · oneOf[3] · $ref #/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · object · $ref #/$defs/webvh_method_history_evidence
Complete did:webvh log, proof and witness material routed by evidence_kind webvh_log to the active did:webvh adapter. log_entries is the gap-free native history from inception through boundary.to_version_id, not a resolver summary or a partial segment. witness_records is the complete did-witness.json record set required by every witness policy active in that interval and is empty only when no entry activates a witness policy. The receiver independently verifies SCID derivation, every versionId/hash-chain link, every controller proof, rotation authorization, all applicable witness thresholds, the exact boundary endpoints and canonical equality of the terminal state with normalized_did_document. Canonical encoded evidence MUST NOT exceed 1 MiB; an over-limit service history is ineligible for retained historical-signer and governance-Station bootstrap and fails closed rather than returning partial evidence.
* evidence_kind ·
const "webvh_log"enum:
"webvh_log"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* from_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* to_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* method ·
…recursion truncated at depth 8; see source schema for full shape
* document_digest ·
…recursion truncated at depth 8; see source schema for full shape
* method_proofs ·
…recursion truncated at depth 8; see source schema for full shape
* log_entries · array<object>
Exact ordered native did:webvh entry objects from inception through the selected terminal entry. The adapter applies the registered did:webvh parameter-name and proof rules and rejects gaps, duplicates, surplus entries after boundary.to_version_id, or a first entry other than inception.
items ·
…recursion truncated at depth 8; see source schema for full shape
* witness_records · array<object>
Exact native did-witness.json record objects needed by log_entries. Records are keyed uniquely by versionId; missing, duplicate, invalid or surplus records fail closed. The array is empty exactly when the verified log activates no witness policy.
items ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/did_web_method_history_evidence
Bounded current DID Document retrieval evidence routed by evidence_kind did_web_document to the active did:web adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
const "did_web_document"enum:
"did_web_document"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* from_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* to_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* method ·
…recursion truncated at depth 8; see source schema for full shape
* document_digest ·
…recursion truncated at depth 8; see source schema for full shape
* method_proofs ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/did_key_method_history_evidence
Bounded deterministic local expansion evidence routed by evidence_kind did_key_expansion to the active did:key adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
const "did_key_expansion"enum:
"did_key_expansion"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* from_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* to_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* method ·
…recursion truncated at depth 8; see source schema for full shape
* document_digest ·
…recursion truncated at depth 8; see source schema for full shape
* method_proofs ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* service_kind ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$* method_history_evidence · oneOf[3] · $ref #/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · object · $ref #/$defs/webvh_method_history_evidence
Complete did:webvh log, proof and witness material routed by evidence_kind webvh_log to the active did:webvh adapter. log_entries is the gap-free native history from inception through boundary.to_version_id, not a resolver summary or a partial segment. witness_records is the complete did-witness.json record set required by every witness policy active in that interval and is empty only when no entry activates a witness policy. The receiver independently verifies SCID derivation, every versionId/hash-chain link, every controller proof, rotation authorization, all applicable witness thresholds, the exact boundary endpoints and canonical equality of the terminal state with normalized_did_document. Canonical encoded evidence MUST NOT exceed 1 MiB; an over-limit service history is ineligible for retained historical-signer and governance-Station bootstrap and fails closed rather than returning partial evidence.
* evidence_kind ·
const "webvh_log"enum:
"webvh_log"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* from_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* to_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* method ·
…recursion truncated at depth 8; see source schema for full shape
* document_digest ·
…recursion truncated at depth 8; see source schema for full shape
* method_proofs ·
…recursion truncated at depth 8; see source schema for full shape
* log_entries · array<object>
Exact ordered native did:webvh entry objects from inception through the selected terminal entry. The adapter applies the registered did:webvh parameter-name and proof rules and rejects gaps, duplicates, surplus entries after boundary.to_version_id, or a first entry other than inception.
items ·
…recursion truncated at depth 8; see source schema for full shape
* witness_records · array<object>
Exact native did-witness.json record objects needed by log_entries. Records are keyed uniquely by versionId; missing, duplicate, invalid or surplus records fail closed. The array is empty exactly when the verified log activates no witness policy.
items ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object · $ref #/$defs/did_web_method_history_evidence
Bounded current DID Document retrieval evidence routed by evidence_kind did_web_document to the active did:web adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
const "did_web_document"enum:
"did_web_document"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* from_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* to_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* method ·
…recursion truncated at depth 8; see source schema for full shape
* document_digest ·
…recursion truncated at depth 8; see source schema for full shape
* method_proofs ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · object · $ref #/$defs/did_key_method_history_evidence
Bounded deterministic local expansion evidence routed by evidence_kind did_key_expansion to the active did:key adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
const "did_key_expansion"enum:
"did_key_expansion"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* from_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_method_history_head ·
…recursion truncated at depth 8; see source schema for full shape
* to_version_id ·
…recursion truncated at depth 8; see source schema for full shape
* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* method ·
…recursion truncated at depth 8; see source schema for full shape
* document_digest ·
…recursion truncated at depth 8; see source schema for full shape
* method_proofs ·
…recursion truncated at depth 8; see source schema for full shape
* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did ·
$ref #/$defs/did · $ref #/$defs/did* contexts · array<oneOf[2]>
items · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* controller_dids · array<$ref #/$defs/did>
items ·
$ref #/$defs/did · $ref #/$defs/did* also_known_as · array<string>
items ·
stringCanonical URI validated by the DID resolver before projection; this array may contain non-network schemes such as acct: and therefore is not a URL field.
pattern:
^[A-Za-z][A-Za-z0-9+.-]*:[^\s]+$* verification_methods · array<$ref #/$defs/normalized_did_verification_method>
items ·
$ref #/$defs/normalized_did_verification_method · $ref #/$defs/normalized_did_verification_method* authentication ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* assertion_methods ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* key_agreements ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* capability_invocations ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* capability_delegations ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* services · array<$ref #/$defs/normalized_did_service>
items ·
$ref #/$defs/normalized_did_service · $ref #/$defs/normalized_did_service* metadata ·
$ref #/$defs/normalized_did_document_metadata · $ref #/$defs/normalized_did_document_metadata* extensions · array<$ref #/$defs/normalized_did_document_extension>
items ·
$ref #/$defs/normalized_did_document_extension · $ref #/$defs/normalized_did_document_extensiononeOf · oneOf[3] · object · $ref #/$defs/current_principal_outcome
* request_id ·
string · $ref ./account-operations.schema.json#/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* resolution_projection · object · $ref #/$defs/resolution_projection
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$allOf · allOf[1] · object
context ·
const "ak.realm_commit_signature.v1"enum:
"ak.realm_commit_signature.v1"* history_complete ·
booleanTrue exactly when the disclosed segment reaches its requested stop condition: head 0, or the exclusive after_resolution_event_ref ancestor. False means disclosure was truncated and next_audit_cursor is present. Omitted history is unknown rather than absent.
next_audit_cursor ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$method_history_evidence · oneOf[3] · $ref #/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · object · $ref #/$defs/webvh_method_history_evidence
Complete did:webvh log, proof and witness material routed by evidence_kind webvh_log to the active did:webvh adapter. log_entries is the gap-free native history from inception through boundary.to_version_id, not a resolver summary or a partial segment. witness_records is the complete did-witness.json record set required by every witness policy active in that interval and is empty only when no entry activates a witness policy. The receiver independently verifies SCID derivation, every versionId/hash-chain link, every controller proof, rotation authorization, all applicable witness thresholds, the exact boundary endpoints and canonical equality of the terminal state with normalized_did_document. Canonical encoded evidence MUST NOT exceed 1 MiB; an over-limit service history is ineligible for retained historical-signer and governance-Station bootstrap and fails closed rather than returning partial evidence.
* evidence_kind ·
const "webvh_log"enum:
"webvh_log"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
string* from_version_id ·
stringpattern:
^(?!ak:)* to_method_history_head ·
string* to_version_id ·
stringpattern:
^(?!ak:)* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
const "ak.did.binding_evidence.v1"enum:
"ak.did.binding_evidence.v1"* method ·
$ref #/$defs/method_token · $ref #/$defs/method_token* document_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of the resolver's verified normalized DID Document projection (did-usage-and-verification.md section 5.1); never the raw response bytes (those use the differently named raw_document_digest).
* method_proofs · array<$ref #/$defs/webvh_log_evidence>
Closed per-method proof rows; empty for proofless methods (did:key, bare did:web). v1 registers exactly one row kind (webvh_log); receiving any unregistered proof kind fails closed. Rows never reuse resolver response order: each row kind registers its own canonical sort and duplicate-rejection rules.
items ·
$ref #/$defs/webvh_log_evidence · $ref #/$defs/webvh_log_evidence* log_entries · array<object>
Exact ordered native did:webvh entry objects from inception through the selected terminal entry. The adapter applies the registered did:webvh parameter-name and proof rules and rejects gaps, duplicates, surplus entries after boundary.to_version_id, or a first entry other than inception.
items ·
object* witness_records · array<object>
Exact native did-witness.json record objects needed by log_entries. Records are keyed uniquely by versionId; missing, duplicate, invalid or surplus records fail closed. The array is empty exactly when the verified log activates no witness policy.
items ·
objectoneOf · oneOf[1] · object · $ref #/$defs/did_web_method_history_evidence
Bounded current DID Document retrieval evidence routed by evidence_kind did_web_document to the active did:web adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
const "did_web_document"enum:
"did_web_document"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
string* from_version_id ·
stringpattern:
^(?!ak:)* to_method_history_head ·
string* to_version_id ·
stringpattern:
^(?!ak:)* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
const "ak.did.binding_evidence.v1"enum:
"ak.did.binding_evidence.v1"* method ·
$ref #/$defs/method_token · $ref #/$defs/method_token* document_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of the resolver's verified normalized DID Document projection (did-usage-and-verification.md section 5.1); never the raw response bytes (those use the differently named raw_document_digest).
* method_proofs · array<$ref #/$defs/webvh_log_evidence>
Closed per-method proof rows; empty for proofless methods (did:key, bare did:web). v1 registers exactly one row kind (webvh_log); receiving any unregistered proof kind fails closed. Rows never reuse resolver response order: each row kind registers its own canonical sort and duplicate-rejection rules.
items ·
$ref #/$defs/webvh_log_evidence · $ref #/$defs/webvh_log_evidenceoneOf · oneOf[2] · object · $ref #/$defs/did_key_method_history_evidence
Bounded deterministic local expansion evidence routed by evidence_kind did_key_expansion to the active did:key adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
const "did_key_expansion"enum:
"did_key_expansion"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
string* from_version_id ·
stringpattern:
^(?!ak:)* to_method_history_head ·
string* to_version_id ·
stringpattern:
^(?!ak:)* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
const "ak.did.binding_evidence.v1"enum:
"ak.did.binding_evidence.v1"* method ·
$ref #/$defs/method_token · $ref #/$defs/method_token* document_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of the resolver's verified normalized DID Document projection (did-usage-and-verification.md section 5.1); never the raw response bytes (those use the differently named raw_document_digest).
* method_proofs · array<$ref #/$defs/webvh_log_evidence>
Closed per-method proof rows; empty for proofless methods (did:key, bare did:web). v1 registers exactly one row kind (webvh_log); receiving any unregistered proof kind fails closed. Rows never reuse resolver response order: each row kind registers its own canonical sort and duplicate-rejection rules.
items ·
$ref #/$defs/webvh_log_evidence · $ref #/$defs/webvh_log_evidenceoneOf · oneOf[2] · object · $ref #/$defs/authenticated_service_resolution
Public method-native service evidence. All route coordinates are derived from the independently verified DID state; this carrier creates no signed address history.
* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* service_kind ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$* method_history_evidence · oneOf[3] · $ref #/$defs/method_history_evidence
Adapter-routed evidence. evidence_kind is the single-source discriminator: the receiver resolves it through did-method-adapter-registry.json method_evidence_kind, which is unique across active adapters, to exactly one active adapter for this versioned schema. The evidence carries no adapter_version; an adapter change requires a new schema/operation version rather than a registry drift under the same wire shape. Unknown evidence kinds fail closed.
oneOf · oneOf[0] · object · $ref #/$defs/webvh_method_history_evidence
Complete did:webvh log, proof and witness material routed by evidence_kind webvh_log to the active did:webvh adapter. log_entries is the gap-free native history from inception through boundary.to_version_id, not a resolver summary or a partial segment. witness_records is the complete did-witness.json record set required by every witness policy active in that interval and is empty only when no entry activates a witness policy. The receiver independently verifies SCID derivation, every versionId/hash-chain link, every controller proof, rotation authorization, all applicable witness thresholds, the exact boundary endpoints and canonical equality of the terminal state with normalized_did_document. Canonical encoded evidence MUST NOT exceed 1 MiB; an over-limit service history is ineligible for retained historical-signer and governance-Station bootstrap and fails closed rather than returning partial evidence.
* evidence_kind ·
const "webvh_log"enum:
"webvh_log"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
string* from_version_id ·
stringpattern:
^(?!ak:)* to_method_history_head ·
string* to_version_id ·
stringpattern:
^(?!ak:)* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
const "ak.did.binding_evidence.v1"enum:
"ak.did.binding_evidence.v1"* method ·
$ref #/$defs/method_token · $ref #/$defs/method_token* document_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of the resolver's verified normalized DID Document projection (did-usage-and-verification.md section 5.1); never the raw response bytes (those use the differently named raw_document_digest).
* method_proofs · array<$ref #/$defs/webvh_log_evidence>
Closed per-method proof rows; empty for proofless methods (did:key, bare did:web). v1 registers exactly one row kind (webvh_log); receiving any unregistered proof kind fails closed. Rows never reuse resolver response order: each row kind registers its own canonical sort and duplicate-rejection rules.
items ·
$ref #/$defs/webvh_log_evidence · $ref #/$defs/webvh_log_evidence* log_entries · array<object>
Exact ordered native did:webvh entry objects from inception through the selected terminal entry. The adapter applies the registered did:webvh parameter-name and proof rules and rejects gaps, duplicates, surplus entries after boundary.to_version_id, or a first entry other than inception.
items ·
object* witness_records · array<object>
Exact native did-witness.json record objects needed by log_entries. Records are keyed uniquely by versionId; missing, duplicate, invalid or surplus records fail closed. The array is empty exactly when the verified log activates no witness policy.
items ·
objectoneOf · oneOf[1] · object · $ref #/$defs/did_web_method_history_evidence
Bounded current DID Document retrieval evidence routed by evidence_kind did_web_document to the active did:web adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
const "did_web_document"enum:
"did_web_document"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
string* from_version_id ·
stringpattern:
^(?!ak:)* to_method_history_head ·
string* to_version_id ·
stringpattern:
^(?!ak:)* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
const "ak.did.binding_evidence.v1"enum:
"ak.did.binding_evidence.v1"* method ·
$ref #/$defs/method_token · $ref #/$defs/method_token* document_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of the resolver's verified normalized DID Document projection (did-usage-and-verification.md section 5.1); never the raw response bytes (those use the differently named raw_document_digest).
* method_proofs · array<$ref #/$defs/webvh_log_evidence>
Closed per-method proof rows; empty for proofless methods (did:key, bare did:web). v1 registers exactly one row kind (webvh_log); receiving any unregistered proof kind fails closed. Rows never reuse resolver response order: each row kind registers its own canonical sort and duplicate-rejection rules.
items ·
$ref #/$defs/webvh_log_evidence · $ref #/$defs/webvh_log_evidenceoneOf · oneOf[2] · object · $ref #/$defs/did_key_method_history_evidence
Bounded deterministic local expansion evidence routed by evidence_kind did_key_expansion to the active did:key adapter. The boundary endpoints MUST be identical synthetic values. Canonical encoded evidence MUST NOT exceed 1 MiB.
* evidence_kind ·
const "did_key_expansion"enum:
"did_key_expansion"* boundary · object · $ref #/$defs/method_evidence_boundary
Inclusive adapter-defined history interval covered by this evidence. For a method without native history the from and to values are identical synthetic values for the one verified state.
* from_method_history_head ·
string* from_version_id ·
stringpattern:
^(?!ak:)* to_method_history_head ·
string* to_version_id ·
stringpattern:
^(?!ak:)* evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
const "ak.did.binding_evidence.v1"enum:
"ak.did.binding_evidence.v1"* method ·
$ref #/$defs/method_token · $ref #/$defs/method_token* document_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of the resolver's verified normalized DID Document projection (did-usage-and-verification.md section 5.1); never the raw response bytes (those use the differently named raw_document_digest).
* method_proofs · array<$ref #/$defs/webvh_log_evidence>
Closed per-method proof rows; empty for proofless methods (did:key, bare did:web). v1 registers exactly one row kind (webvh_log); receiving any unregistered proof kind fails closed. Rows never reuse resolver response order: each row kind registers its own canonical sort and duplicate-rejection rules.
items ·
$ref #/$defs/webvh_log_evidence · $ref #/$defs/webvh_log_evidence* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did ·
$ref #/$defs/did · $ref #/$defs/did* contexts · array<oneOf[2]>
items · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] ·
object* controller_dids · array<$ref #/$defs/did>
items ·
$ref #/$defs/did · $ref #/$defs/did* also_known_as · array<string>
items ·
stringCanonical URI validated by the DID resolver before projection; this array may contain non-network schemes such as acct: and therefore is not a URL field.
pattern:
^[A-Za-z][A-Za-z0-9+.-]*:[^\s]+$* verification_methods · array<$ref #/$defs/normalized_did_verification_method>
items ·
$ref #/$defs/normalized_did_verification_method · $ref #/$defs/normalized_did_verification_method* authentication ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* assertion_methods ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* key_agreements ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* capability_invocations ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* capability_delegations ·
$ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship* services · array<$ref #/$defs/normalized_did_service>
items ·
$ref #/$defs/normalized_did_service · $ref #/$defs/normalized_did_service* metadata ·
$ref #/$defs/normalized_did_document_metadata · $ref #/$defs/normalized_did_document_metadata* extensions · array<$ref #/$defs/normalized_did_document_extension>
items ·
$ref #/$defs/normalized_did_document_extension · $ref #/$defs/normalized_did_document_extensiononeOf · oneOf[3] · object · $ref #/$defs/current_principal_outcome
* request_id ·
string · $ref ./account-operations.schema.json#/$defs/request_idpattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* resolution_projection · object · $ref #/$defs/resolution_projection
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/identity-resolution.schema.json