ak.schema.device_reanchor.v1
ak.schema.device_reanchor.v1 · file: schemas/device-reanchor.schema.json Canonical closed payload for ak.device.reanchor (ak.schema.device_reanchor.v1).
* $ · object · $ref ./event-payload.schema.json#/$defs/device_reanchor_payload
Closed account-local PCR recovery payload. The account authority is selected by the exact AccountId and one monotonic local device-generation CAS. PCR realm/checkpoint identifiers remain local recovery state and are not an external principal identity selector.
allOf · allOf[0] ·
?* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* recovery_authority_kind ·
string (enum)enum:
"pcr_policy" "did_root"* recovery_policy_id ·
stringpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* recovery_policy_version ·
integer* recovery_session_id ·
stringpattern:
^ak:recovery_session:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* previous_device_generation ·
integer* new_device_generation ·
integerMust be the immediate monotonic successor of previous_device_generation.
did_root_evidence_digest ·
$ref #/$defs/digest · $ref #/$defs/digestRequired only when recovery_authority_kind=did_root; proves the optional factor enabled by the frozen PCR policy.
* replacement_authorize_payload_digest ·
$ref #/$defs/digest · $ref #/$defs/digestcanonical_digest of the replacement ak.device.authorize payload object, using the Realm live digest suite.
Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/device-reanchor.schema.json