跳转到内容

ak.schema.did_webvh_witness_receipt.v1

← Schemas

Arkret did:webvh Witness Receipt
ak.schema.did_webvh_witness_receipt.v1 · file: schemas/did-webvh-witness-receipt.schema.json

Arkret-layer, cacheable and auditable record that a named did:webvh witness was observed attesting a specific log version. It is deliberately a separate object family from ak.schema.identity_receipt.v1: that one records a role (writer / witness / replica) inside a DID registry consensus group and binds seq + accepted_entry_digest, whereas this one binds a did:webvh method versionId and a witness did:key drawn from parameters.witness. Overloading one object with both meanings would leave half its required fields meaningless on either branch and force verifiers to guess which sense of the word witness applies. This receipt NEVER substitutes for method conformance: a verifier MUST still fetch and verify the standard did-witness.json proofs, the entry hash chain and the controller proof. See zh/identity/identity-did.md.

* $ · object
Arkret-layer, cacheable and auditable record that a named did:webvh witness was observed attesting a specific log version. It is deliberately a separate object family from ak.schema.identity_receipt.v1: that one records a role (writer / witness / replica) inside a DID registry consensus group and binds seq + accepted_entry_digest, whereas this one binds a did:webvh method versionId and a witness did:key drawn from parameters.witness. Overloading one object with both meanings would leave half its required fields meaningless on either branch and force verifiers to guess which sense of the word witness applies. This receipt NEVER substitutes for method conformance: a verifier MUST still fetch and verify the standard did-witness.json proofs, the entry hash chain and the controller proof. See zh/identity/identity-did.md.
* schema · const "ak.schema.did_webvh_witness_receipt.v1"
Closed discriminator. ak.root.identity.receipts.read.list.v1 returns a tagged union of receipt families; this constant is what lets a verifier pick the did:webvh method-witness branch instead of the registry consensus branch without guessing.
enum: "ak.schema.did_webvh_witness_receipt.v1"
* receipt_id · string
pattern: ^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* subject_did · string · $ref ./common-ids.schema.json#/$defs/webvh_did
Canonical bare did:webvh identifier used at method-native registration, document and evidence boundaries. Role admission is enforced separately.
pattern: ^did:webvh:[^\s:/?#]+:[^\s/?#]+$
* version_id · string
The exact did:webvh versionId this attestation covers, verbatim from the log entry. Binding to versionId rather than to a digest of the document is what makes the receipt replayable against did-witness.json, whose proofs are themselves keyed by versionId.
pattern: ^(?!ak:)
log_head_digest · string
Optional digest of the log head the issuer held when observing. Present it when the issuer can commit to the whole log state; it lets a consumer detect a split view that a per-version binding alone would not reveal.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* witness_did · string · $ref ./common-ids.schema.json#/$defs/did_key_did
Canonical bare did:key identifier used at method-native key and witness evidence boundaries. This is a registered method-specific Did subtype, not a business ActorId and not a DID URL.
pattern: ^did:key:z[1-9A-HJ-NP-Za-km-z]+$
* witness_verification_method · string
The specific verification method inside witness_did whose signature appears in did-witness.json for version_id.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* controlling_organization_did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* observed_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
source_url · string (uri) · format=uri
Optional origin the proof was read from (the DID's own did-witness.json or a declared mirror). Recorded so a consumer can tell a first-party read from a mirrored one when adjudicating conflicting receipts.
pattern: ^https://
* issuer_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
trust_domain · string · $ref ./common-ids.schema.json#/$defs/trust_domain
Optional trust domain the receipt is scoped to.
pattern: ^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$
audience · string
Optional audience binding (verifier DID, service DID, or domain). When present, verifiers MUST reject the receipt outside that audience context to prevent cross-protocol reuse.
* expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* created_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* signature · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · $ref #/$defs/digest · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
* created_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$

Source