ak.schema.detached_object_signature.v1
ak.schema.detached_object_signature.v1 · file: schemas/detached-object-signature.schema.json Closed Ed25519 detached signature over one registered object-family transcript. The verifier removes the registered signature member or members from the closed host object, computes signed_digest as sha256:lowercase_hex(SHA-256(RFC8785_JCS(unsigned_projection))), then verifies sig over UTF8(context + LF) || RFC8785_JCS({context,signature_algorithm,verification_method,signed_digest,created_at}). context is intentionally bound both by the prefix and as an envelope member. This is not an Event producer proof.
* $ · object
Closed Ed25519 detached signature over one registered object-family transcript. The verifier removes the registered signature member or members from the closed host object, computes signed_digest as sha256:lowercase_hex(SHA-256(RFC8785_JCS(unsigned_projection))), then verifies sig over UTF8(context + LF) || RFC8785_JCS({context,signature_algorithm,verification_method,signed_digest,created_at}). context is intentionally bound both by the prefix and as an envelope member. This is not an Event producer proof.
* context ·
string (enum)enum:
"ak.realm_commit_signature.v1" "ak.realm_authority_handoff_old_signature.v1" "ak.realm_authority_handoff_new_acceptance_signature.v1" "ak.realm_authority_current_assertion_signature.v1" "ak.realm_snapshot_signature.v1" "ak.mls_welcome_delivery_signature.v1"* signature_algorithm ·
const "Ed25519"enum:
"Ed25519"* verification_method ·
string · $ref ./event-envelope.schema.json#/$defs/proof/properties/verification_methodDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signed_digest ·
stringSHA-256 of the RFC8785 JCS bytes of the complete registered unsigned host projection. A verifier MUST recompute this value from the host object before signature verification.
pattern:
^sha256:[0-9a-f]{64}$* created_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* sig ·
stringUnpadded Base64URL encoding of an Ed25519 signature.
pattern:
^[A-Za-z0-9_-]{86}$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/detached-object-signature.schema.json