ak.schema.direct_conversation_operations.v1
ak.schema.direct_conversation_operations.v1 · file: schemas/direct-conversation-operations.schema.json Closed carriers for the Direct Conversation resolver and single-sided founding. Creation is never carried here: a Direct Conversation Realm is created only by the founder derived from the pair's root Contact round through the direct_conversation_genesis admission variant of ak.realm.create.
* $ · oneOf[4]
Closed carriers for the Direct Conversation resolver and single-sided founding. Creation is never carried here: a Direct Conversation Realm is created only by the founder derived from the pair's root Contact round through the direct_conversation_genesis admission variant of ak.realm.create.
oneOf · oneOf[0] · object · $ref #/$defs/direct_conversation_coordinates
Permanent Direct Conversation coordinates. binding_event_ref appears only from found or suspended onward; it is absent while the pair is still provisional.
* pair_key ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* realm_id ·
string · $ref ./principal-operations.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* main_strand_id ·
string · $ref ./principal-operations.schema.json#/$defs/strand_idpattern:
^ak:strand:[A-Za-z0-9_-]{44}$binding_event_ref ·
string · $ref ./principal-operations.schema.json#/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object · $ref #/$defs/direct_conversation_resolve_outcome
Closed tagged outcome of ak.self.direct_conversation.read.resolve.v1. Evaluation order is fixed: temporarily_unavailable when the current basis or founder cannot be verified; then creation_blocked, creation_required or awaiting_founder while no Realm exists; then suspended for identity, materialization, terminal or gate conflicts; then provisional while no binding endorsement exists; found last. awaiting_founder never transfers authority by timeout, recovery policy, successor designation or permanent-unavailability inference; v1 defines no founder_unrecoverable state.
oneOf · oneOf[0] · object
* state ·
const "creation_required"enum:
"creation_required"* next_founding_input · object · $ref #/$defs/direct_conversation_founding_input
Authoring material for the founding unit the caller is now entitled to author, carried only by the creation_required outcome. The founder reads the current Contact round, continuity chain and binding coordinates from it to author and sign the four Events; it is not an echo container, because DirectConversationFoundingUnitSubmission carries no founding_authority_evidence member and the founder's current Station re-verifies the unit against its own current evidence (zh/identity/contact-and-direct-conversation.md section 9.1.1). This container never carries Event bytes, coordinates or a receipt. Material that the service cannot assemble or verify yields temporarily_unavailable instead of a creation_required outcome without it.
* founding_authority_evidence · oneOf[2] · $ref ./service-operation-dtos.schema.json#/$defs/DirectConversationFoundingAuthorityEvidence
Closed XOR authorization evidence for one Direct Conversation founding unit, matching the two registered ak.realm.create admission variants. The human branch feeds direct_conversation_genesis; the controller_agent branch feeds direct_conversation_agent_genesis. Carrying both, neither, or mixed branch fields rejects the whole unit.
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* contact_round_evidence · object · $ref ./contact-operations.schema.json#/$defs/contact_round_evidence_bundle
Portable evidence for the pair's current Contact round. The verifier re-derives founder from the root Contact round, never from the current round.
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestAbsent only for a root Contact round. On recontact it is copied from every signed request fact and request acceptance receipt in this bundle and points to the immediately preceding terminal round. The bundle field is derived convenience, never independent authority.
pattern:
^sha256:[0-9a-f]{64}$* contact_round ·
$ref #/$defs/contact_round · $ref #/$defs/contact_round* request_receipts · array<$ref #/$defs/request_acceptance_receipt>
items ·
$ref #/$defs/request_acceptance_receipt · $ref #/$defs/request_acceptance_receiptnormal_response_receipt ·
$ref #/$defs/normal_response_acceptance_receipt · $ref #/$defs/normal_response_acceptance_receiptglare_concurrency_attestations · array<$ref #/$defs/glare_concurrency_attestation>
items ·
$ref #/$defs/glare_concurrency_attestation · $ref #/$defs/glare_concurrency_attestation* current_proofs · array<$ref #/$defs/contact_current_proof>
items ·
$ref #/$defs/contact_current_proof · $ref #/$defs/contact_current_proofcontinuity_checkpoint ·
$ref #/$defs/bilateral_continuity_checkpoint · $ref #/$defs/bilateral_continuity_checkpointLatest mutually signed compacted prefix for this lineage. Its presence changes the chain terminator from the root round to covered_through_contact_round_id; it never changes the root basis or participant authority pair.
* contact_round_continuity_chains · array<$ref ./contact-operations.schema.json#/$defs/contact_round_evidence_bundle>
Ordered tombstone/recontact predecessors from the current Contact round back to the pair's unique root Contact round, each linked by previous_terminal_contact_round_id. An empty array means the current round is itself the root. A break, a cycle, multiple roots or two directional proofs yielding different roots reject the unit.
items · object · $ref ./contact-operations.schema.json#/$defs/contact_round_evidence_bundle
allOf · allOf[0] ·
?* contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$previous_terminal_contact_round_id ·
string · $ref ./principal-operations.schema.json#/$defs/digestAbsent only for a root Contact round. On recontact it is copied from every signed request fact and request acceptance receipt in this bundle and points to the immediately preceding terminal round. The bundle field is derived convenience, never independent authority.
pattern:
^sha256:[0-9a-f]{64}$* contact_round ·
$ref #/$defs/contact_round · $ref #/$defs/contact_round* request_receipts · array<$ref #/$defs/request_acceptance_receipt>
items ·
…recursion truncated at depth 8; see source schema for full shape
normal_response_receipt ·
$ref #/$defs/normal_response_acceptance_receipt · $ref #/$defs/normal_response_acceptance_receiptglare_concurrency_attestations · array<$ref #/$defs/glare_concurrency_attestation>
items ·
…recursion truncated at depth 8; see source schema for full shape
* current_proofs · array<$ref #/$defs/contact_current_proof>
items ·
…recursion truncated at depth 8; see source schema for full shape
continuity_checkpoint ·
$ref #/$defs/bilateral_continuity_checkpoint · $ref #/$defs/bilateral_continuity_checkpointLatest mutually signed compacted prefix for this lineage. Its presence changes the chain terminator from the root round to covered_through_contact_round_id; it never changes the root basis or participant authority pair.
oneOf · oneOf[1] · object
* kind ·
const "controller_agent"enum:
"controller_agent"* agent_provision_ref ·
string · $ref ./principal-operations.schema.json#/$defs/event_idComplete identity of the accepted Agent provision Event. Its digest is derived by decoding this suite-tagged full-digest EventId; no parallel agent_provision_digest is carried.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* controller_binding_digest ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[1] · object
* state ·
const "creation_blocked"enum:
"creation_blocked"* blockers · array<$ref #/$defs/direct_conversation_send_blocker>
items ·
string (enum) · $ref #/$defs/direct_conversation_send_blockerClosed machine-readable blocker set surfaced by the Direct Conversation resolver. Every value MUST be server-verifiable from accepted authoritative state. presence_offline and keypackage_empty are visible only to an existing exact-pair participant; every other caller receives the same opaque failure as for a pair that does not exist.
enum:
"session_missing" "presence_offline" "keypackage_empty" "grant_missing" "policy_stale" "contact_scope_stale" "mls_reconcile_required" "agent_runtime_unavailable" "peer_not_joined_mls" "member_count_invalid" "pair_materialization_conflict" "realm_terminal_fault" "governance_station_unavailable" "unsupported_profile"oneOf · oneOf[2] · object
* state ·
const "awaiting_founder"enum:
"awaiting_founder"retry_after_ms ·
integeroneOf · oneOf[3] · object
* state ·
const "provisional"enum:
"provisional"* coordinates · object · $ref #/$defs/direct_conversation_coordinates
Permanent Direct Conversation coordinates. binding_event_ref appears only from found or suspended onward; it is absent while the pair is still provisional.
* pair_key ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* realm_id ·
string · $ref ./principal-operations.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* main_strand_id ·
string · $ref ./principal-operations.schema.json#/$defs/strand_idpattern:
^ak:strand:[A-Za-z0-9_-]{44}$binding_event_ref ·
string · $ref ./principal-operations.schema.json#/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* authorization_basis · object · $ref ./event-payload.schema.json#/$defs/direct_conversation_authorization_basis
Canonical authorization basis for creating a Direct Conversation. accepted_contact carries exactly the accepted contact request/accept refs. agent_controller carries exactly two unique accepted Event refs: the controller-authored ak.agent.provision Event, whose payload already binds the Agent, controller, delegation, accountability and selector facts, and the current active ak.agent.key.authorize Event.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* kind ·
string (enum)enum:
"accepted_contact" "agent_controller"* event_refs · array<$ref #/$defs/event_ref>
items ·
$ref #/$defs/event_ref · $ref #/$defs/event_refgroup_state_ref ·
string · $ref ./principal-operations.schema.json#/$defs/event_idComplete Event identity of the unique derived MLS group's exact current winning Genesis/Commit state. Consumers recover the suite and full Event digest from this ID.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$initial_exact_pair_group_state_ref ·
string · $ref ./principal-operations.schema.json#/$defs/event_idImmutable first accepted exact-pair winning state; present once it exists and never replaced by a repair Commit.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* peer_mls_admission ·
string (enum)Authoritative current occupied peer leaf admission state at this read cut; not a write authorization or a client timer.
enum:
"missing" "pending" "durable" "repair_required"oneOf · oneOf[4] · object
* state ·
const "found"enum:
"found"* coordinates · object · $ref #/$defs/direct_conversation_coordinates
Permanent Direct Conversation coordinates. binding_event_ref appears only from found or suspended onward; it is absent while the pair is still provisional.
* pair_key ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* realm_id ·
string · $ref ./principal-operations.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* main_strand_id ·
string · $ref ./principal-operations.schema.json#/$defs/strand_idpattern:
^ak:strand:[A-Za-z0-9_-]{44}$binding_event_ref ·
string · $ref ./principal-operations.schema.json#/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* group_state_ref ·
string · $ref ./principal-operations.schema.json#/$defs/event_idComplete Event identity of the exact current winning group-state Event.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* send_blockers · array<$ref #/$defs/direct_conversation_send_blocker>
items ·
string (enum) · $ref #/$defs/direct_conversation_send_blockerClosed machine-readable blocker set surfaced by the Direct Conversation resolver. Every value MUST be server-verifiable from accepted authoritative state. presence_offline and keypackage_empty are visible only to an existing exact-pair participant; every other caller receives the same opaque failure as for a pair that does not exist.
enum:
"session_missing" "presence_offline" "keypackage_empty" "grant_missing" "policy_stale" "contact_scope_stale" "mls_reconcile_required" "agent_runtime_unavailable" "peer_not_joined_mls" "member_count_invalid" "pair_materialization_conflict" "realm_terminal_fault" "governance_station_unavailable" "unsupported_profile"oneOf · oneOf[5] · object
* state ·
const "suspended"enum:
"suspended"* coordinates · object · $ref #/$defs/direct_conversation_coordinates
Permanent Direct Conversation coordinates. binding_event_ref appears only from found or suspended onward; it is absent while the pair is still provisional.
* pair_key ·
string · $ref ./principal-operations.schema.json#/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* realm_id ·
string · $ref ./principal-operations.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* main_strand_id ·
string · $ref ./principal-operations.schema.json#/$defs/strand_idpattern:
^ak:strand:[A-Za-z0-9_-]{44}$binding_event_ref ·
string · $ref ./principal-operations.schema.json#/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* blockers · array<$ref #/$defs/direct_conversation_send_blocker>
items ·
string (enum) · $ref #/$defs/direct_conversation_send_blockerClosed machine-readable blocker set surfaced by the Direct Conversation resolver. Every value MUST be server-verifiable from accepted authoritative state. presence_offline and keypackage_empty are visible only to an existing exact-pair participant; every other caller receives the same opaque failure as for a pair that does not exist.
enum:
"session_missing" "presence_offline" "keypackage_empty" "grant_missing" "policy_stale" "contact_scope_stale" "mls_reconcile_required" "agent_runtime_unavailable" "peer_not_joined_mls" "member_count_invalid" "pair_materialization_conflict" "realm_terminal_fault" "governance_station_unavailable" "unsupported_profile"group_state_ref ·
string · $ref ./principal-operations.schema.json#/$defs/event_idPresent whenever the unique derived group has an accepted current state.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[6] · object
* state ·
const "temporarily_unavailable"enum:
"temporarily_unavailable"retry_after_ms ·
integeroneOf · oneOf[2] · object · $ref #/$defs/direct_conversation_resolve_request
Closed query body for ak.self.direct_conversation.read.resolve.v1. Creation is never carried here: a Direct Conversation Realm is created only by the derived founder through the direct_conversation_genesis admission variant of ak.realm.create.
* peer · oneOf[2] · $ref ./contact-operations.schema.json#/$defs/contact_peer
oneOf · oneOf[0] · object
* kind ·
const "human"enum:
"human"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idoneOf · oneOf[1] · object
* kind ·
const "agent"enum:
"agent"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idoneOf · oneOf[3] ·
string (enum) · $ref #/$defs/direct_conversation_send_blockerClosed machine-readable blocker set surfaced by the Direct Conversation resolver. Every value MUST be server-verifiable from accepted authoritative state. presence_offline and keypackage_empty are visible only to an existing exact-pair participant; every other caller receives the same opaque failure as for a pair that does not exist.
enum:
"session_missing" "presence_offline" "keypackage_empty" "grant_missing" "policy_stale" "contact_scope_stale" "mls_reconcile_required" "agent_runtime_unavailable" "peer_not_joined_mls" "member_count_invalid" "pair_materialization_conflict" "realm_terminal_fault" "governance_station_unavailable" "unsupported_profile"Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/direct-conversation-operations.schema.json