跳转到内容

ak.schema.encrypted_envelope.v1

← Schemas

Arkret Encrypted Payload Envelope
ak.schema.encrypted_envelope.v1 · file: schemas/encrypted-envelope.schema.json

Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.

* $ · object
Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.
* version · const "1.0"
enum: "1.0"
* content_type · string
pattern: ^[a-z0-9.+-]+/[a-z0-9.+-]+$
* encryption_context · object · $ref #/$defs/encryption_context
RFC 9420 application-message context bound to the accepted group state.
* epoch · integer
* group_state_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
routing_context · object · $ref #/$defs/routing_context
Present only for a registered reaction outer Event kind. The reaction kind and routing_window=floor(unix_ms(outer.created_at)/3600000) are derived inputs to AAD/KDF and never wire fields. All non-reaction kinds forbid routing_context.
* target_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* routing_tag · string
pattern: ^[A-Za-z0-9_-]{43}$
* ciphertext · string
pattern: ^[A-Za-z0-9_-]+$

Source