ak.schema.erasure_receipt_operations.v1
ak.schema.erasure_receipt_operations.v1 · file: schemas/erasure-receipt-operations.schema.json Typed service-to-service submit, acceptance and retrieval carriers for hard-erasure receipts and their exact retained verification stubs.
* $ · oneOf[4]
Typed service-to-service submit, acceptance and retrieval carriers for hard-erasure receipts and their exact retained verification stubs.
oneOf · oneOf[0] · object · $ref #/$defs/erasure_receipt_package
Self-contained acceptance package. retained_stub is carried exactly once at package level and receipt.retained_stub MUST be absent. The receiver computes H('ak.erasure-receipt.v1', receipt) for addressing and acceptance; retained_stub_digest MUST equal SHA-256(RFC8785_JCS(retained_stub)).
allOf · allOf[0] · object
receipt ·
?* receipt · object · $ref ./erasure-receipt.schema.json
Signed attestation that an issuer completed, partially completed, or blocked a hard-erasure request within a declared storage boundary. It proves the issuer's deletion action and retained verification stub, not disappearance of independent third-party copies.
allOf · allOf[0] ·
?* schema ·
const "ak.schema.erasure_receipt.v1"enum:
"ak.schema.erasure_receipt.v1"* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* trigger · oneOf[2] · $ref ./erasure-verification-stub.schema.json#/$defs/trigger
Exact authoritative fact that created this physical-erasure execution. Account erasure uses the account_status_record branch; other Event-authorized erasure uses the event branch.
oneOf · oneOf[0] · object
* kind ·
const "event"enum:
"event"* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "account_status_record"enum:
"account_status_record"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* subject · oneOf[6] · $ref ./erasure-verification-stub.schema.json#/$defs/subject
oneOf · oneOf[0] ·
$ref #/$defs/principal_subject · $ref #/$defs/principal_subjectoneOf · oneOf[1] ·
$ref #/$defs/realm_subject · $ref #/$defs/realm_subjectoneOf · oneOf[2] ·
$ref #/$defs/event_subject · $ref #/$defs/event_subjectoneOf · oneOf[3] ·
$ref #/$defs/blob_subject · $ref #/$defs/blob_subjectoneOf · oneOf[4] ·
$ref #/$defs/device_subject · $ref #/$defs/device_subjectoneOf · oneOf[5] ·
$ref #/$defs/account_private_state_subject · $ref #/$defs/account_private_state_subject* scope · object · $ref ./erasure-verification-stub.schema.json#/$defs/scope
Boundary in which deletion was attempted. This MUST be narrow enough for an auditor to tell which service/storage class made the claim.
* storage_boundary ·
string (enum)enum:
"canonical_log_minimization" "blob_store" "projection_store" "account_private_store" "search_index" "push_routes" "device_secret_store" "media_derivatives" "service_defined"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$target_refs · array<$ref #/$defs/subject_ref>
items ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_refretention_policy_id ·
$ref #/$defs/policy_id · $ref #/$defs/policy_idservice_scope ·
string* outcome ·
string (enum)enum:
"completed" "partially_completed" "blocked_by_legal_hold"* erased_classes · array<string (enum)>
items ·
string (enum)enum:
"canonical_payload_bytes" "blob_bytes" "projection_rows" "account_private_state" "push_routes" "device_secrets" "search_index_entries" "derived_plaintext" "media_derivatives"* retained_stub_digest ·
string · $ref #/$defs/digestHash of the retained verification stub after erasure: hash(canonical_json(retained_stub)). The stub verifies typed-reference structure, redundant digest consistency, receipt/stub binding, and linkage to retained external proof, RealmCommit, redaction-authorization, and legal-hold evidence. It does not independently verify erased canonical Event bytes.
pattern:
^sha256:[0-9a-f]{64}$retained_stub · object · $ref ./erasure-verification-stub.schema.json
Minimal retained verification stub bound by erasure-receipt.retained_stub_digest. It preserves event graph, proof, authority commit, redaction, legal-hold and receipt linkage evidence without retaining erased plaintext.
allOf · allOf[0] ·
?* stub_schema ·
const "ak.schema.erasure_verification_stub.v1"enum:
"ak.schema.erasure_verification_stub.v1"* subject ·
$ref #/$defs/subject · $ref #/$defs/subject* scope ·
$ref #/$defs/scope · $ref #/$defs/scopeevent_digest ·
string · $ref #/$defs/digestOptional redundant digest for an Event subject; it is permitted only when subject.kind is event and MUST be absent for every other subject kind. Its suite and all 32 digest octets MUST exactly match the suite wire code and digest carried by subject.subject_ref. If omitted, the suite and digest are recovered from the Event ID. This field and the Event ID preserve consistency evidence; neither independently verifies erased canonical Event bytes.
pattern:
^sha256:[0-9a-f]{64}$retained_digests · array<$ref #/$defs/digest>
items ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$commit_inclusion · object
commit_ref ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_refsource_commit_ref ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$redaction_authorization_ref ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_reflegal_hold_ref · oneOf[3]
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
$ref #/$defs/policy_id · $ref #/$defs/policy_idoneOf · oneOf[2] ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* trigger ·
$ref #/$defs/trigger · $ref #/$defs/triggerExact closed trigger copied byte-for-byte from the receipt.
* completed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$legal_hold_ref · oneOf[3]
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
$ref #/$defs/policy_id · $ref #/$defs/policy_idoneOf · oneOf[2] ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* completed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proofs · array<object>
items · object
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature ·
stringfanout_status ·
string (enum)Cross-Station erasure receipt fanout aggregate status tracked by the issuing server (models/realm-and-space.md §2.6.2). 'pending' = peers still within erasure_propagation_window_ms and not all acknowledged; 'complete' = every peer that ever held this Realm's content returned a receipt; 'incomplete' = at least one peer failed to acknowledge within erasure_propagation_window_ms. The issuing server MUST surface 'incomplete' to audit/UI and MUST NOT silently swallow it. Absent on receipts that do not drive fanout tracking.
enum:
"pending" "complete" "incomplete"peer_receipts · array<object>
Per-peer fanout acknowledgement records maintained by the issuing server: one entry per peer Station that ever held this Realm's content. Each entry records that peer's acknowledgement status and time, backing the aggregate fanout_status.
items · object
* peer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* status ·
string (enum)'pending' = awaiting this peer's feedback receipt; 'acknowledged' = peer returned a receipt (regardless of its outcome); 'failed' = peer reported a non-completed feedback outcome (partially_completed / blocked_by_legal_hold); 'timed_out' = no feedback within erasure_propagation_window_ms.
enum:
"pending" "acknowledged" "failed" "timed_out"receipt_id ·
stringThe peer's own feedback receipt id, when received.
pattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$acknowledged_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* retained_stub · object · $ref ./erasure-verification-stub.schema.json
Minimal retained verification stub bound by erasure-receipt.retained_stub_digest. It preserves event graph, proof, authority commit, redaction, legal-hold and receipt linkage evidence without retaining erased plaintext.
allOf · allOf[0] ·
?* stub_schema ·
const "ak.schema.erasure_verification_stub.v1"enum:
"ak.schema.erasure_verification_stub.v1"* subject ·
$ref #/$defs/subject · $ref #/$defs/subject* scope ·
$ref #/$defs/scope · $ref #/$defs/scopeevent_digest ·
string · $ref #/$defs/digestOptional redundant digest for an Event subject; it is permitted only when subject.kind is event and MUST be absent for every other subject kind. Its suite and all 32 digest octets MUST exactly match the suite wire code and digest carried by subject.subject_ref. If omitted, the suite and digest are recovered from the Event ID. This field and the Event ID preserve consistency evidence; neither independently verifies erased canonical Event bytes.
pattern:
^sha256:[0-9a-f]{64}$retained_digests · array<$ref #/$defs/digest>
items ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$commit_inclusion · object
commit_ref ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_refsource_commit_ref ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$redaction_authorization_ref ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_reflegal_hold_ref · oneOf[3]
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
$ref #/$defs/policy_id · $ref #/$defs/policy_idoneOf · oneOf[2] ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* trigger ·
$ref #/$defs/trigger · $ref #/$defs/triggerExact closed trigger copied byte-for-byte from the receipt.
* completed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[1] · object · $ref #/$defs/erasure_receipt_submit_request_body
Canonical body of ak.peer.erasure_receipt.command.submit.v1. Idempotency-Key is a required signed HTTP header and is not duplicated in the body.
* package · object · $ref #/$defs/erasure_receipt_package
Self-contained acceptance package. retained_stub is carried exactly once at package level and receipt.retained_stub MUST be absent. The receiver computes H('ak.erasure-receipt.v1', receipt) for addressing and acceptance; retained_stub_digest MUST equal SHA-256(RFC8785_JCS(retained_stub)).
allOf · allOf[0] · object
receipt ·
?* receipt · object · $ref ./erasure-receipt.schema.json
Signed attestation that an issuer completed, partially completed, or blocked a hard-erasure request within a declared storage boundary. It proves the issuer's deletion action and retained verification stub, not disappearance of independent third-party copies.
allOf · allOf[0] ·
?* schema ·
const "ak.schema.erasure_receipt.v1"enum:
"ak.schema.erasure_receipt.v1"* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* trigger · oneOf[2] · $ref ./erasure-verification-stub.schema.json#/$defs/trigger
Exact authoritative fact that created this physical-erasure execution. Account erasure uses the account_status_record branch; other Event-authorized erasure uses the event branch.
oneOf · oneOf[0] · object
* kind ·
const "event"enum:
"event"* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "account_status_record"enum:
"account_status_record"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* subject · oneOf[6] · $ref ./erasure-verification-stub.schema.json#/$defs/subject
oneOf · oneOf[0] ·
$ref #/$defs/principal_subject · $ref #/$defs/principal_subjectoneOf · oneOf[1] ·
$ref #/$defs/realm_subject · $ref #/$defs/realm_subjectoneOf · oneOf[2] ·
$ref #/$defs/event_subject · $ref #/$defs/event_subjectoneOf · oneOf[3] ·
$ref #/$defs/blob_subject · $ref #/$defs/blob_subjectoneOf · oneOf[4] ·
$ref #/$defs/device_subject · $ref #/$defs/device_subjectoneOf · oneOf[5] ·
$ref #/$defs/account_private_state_subject · $ref #/$defs/account_private_state_subject* scope · object · $ref ./erasure-verification-stub.schema.json#/$defs/scope
Boundary in which deletion was attempted. This MUST be narrow enough for an auditor to tell which service/storage class made the claim.
* storage_boundary ·
string (enum)enum:
"canonical_log_minimization" "blob_store" "projection_store" "account_private_store" "search_index" "push_routes" "device_secret_store" "media_derivatives" "service_defined"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$target_refs · array<$ref #/$defs/subject_ref>
items ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_refretention_policy_id ·
$ref #/$defs/policy_id · $ref #/$defs/policy_idservice_scope ·
string* outcome ·
string (enum)enum:
"completed" "partially_completed" "blocked_by_legal_hold"* erased_classes · array<string (enum)>
items ·
string (enum)enum:
"canonical_payload_bytes" "blob_bytes" "projection_rows" "account_private_state" "push_routes" "device_secrets" "search_index_entries" "derived_plaintext" "media_derivatives"* retained_stub_digest ·
string · $ref #/$defs/digestHash of the retained verification stub after erasure: hash(canonical_json(retained_stub)). The stub verifies typed-reference structure, redundant digest consistency, receipt/stub binding, and linkage to retained external proof, RealmCommit, redaction-authorization, and legal-hold evidence. It does not independently verify erased canonical Event bytes.
pattern:
^sha256:[0-9a-f]{64}$retained_stub · object · $ref ./erasure-verification-stub.schema.json
Minimal retained verification stub bound by erasure-receipt.retained_stub_digest. It preserves event graph, proof, authority commit, redaction, legal-hold and receipt linkage evidence without retaining erased plaintext.
allOf · allOf[0] ·
?* stub_schema ·
const "ak.schema.erasure_verification_stub.v1"enum:
"ak.schema.erasure_verification_stub.v1"* subject ·
$ref #/$defs/subject · $ref #/$defs/subject* scope ·
$ref #/$defs/scope · $ref #/$defs/scopeevent_digest ·
string · $ref #/$defs/digestOptional redundant digest for an Event subject; it is permitted only when subject.kind is event and MUST be absent for every other subject kind. Its suite and all 32 digest octets MUST exactly match the suite wire code and digest carried by subject.subject_ref. If omitted, the suite and digest are recovered from the Event ID. This field and the Event ID preserve consistency evidence; neither independently verifies erased canonical Event bytes.
pattern:
^sha256:[0-9a-f]{64}$retained_digests · array<$ref #/$defs/digest>
items ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$commit_inclusion · object
commit_ref ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_refsource_commit_ref ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$redaction_authorization_ref ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_reflegal_hold_ref · oneOf[3]
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
$ref #/$defs/policy_id · $ref #/$defs/policy_idoneOf · oneOf[2] ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* trigger ·
$ref #/$defs/trigger · $ref #/$defs/triggerExact closed trigger copied byte-for-byte from the receipt.
* completed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$legal_hold_ref · oneOf[3]
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
$ref #/$defs/policy_id · $ref #/$defs/policy_idoneOf · oneOf[2] ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* completed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proofs · array<object>
items · object
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature ·
stringfanout_status ·
string (enum)Cross-Station erasure receipt fanout aggregate status tracked by the issuing server (models/realm-and-space.md §2.6.2). 'pending' = peers still within erasure_propagation_window_ms and not all acknowledged; 'complete' = every peer that ever held this Realm's content returned a receipt; 'incomplete' = at least one peer failed to acknowledge within erasure_propagation_window_ms. The issuing server MUST surface 'incomplete' to audit/UI and MUST NOT silently swallow it. Absent on receipts that do not drive fanout tracking.
enum:
"pending" "complete" "incomplete"peer_receipts · array<object>
Per-peer fanout acknowledgement records maintained by the issuing server: one entry per peer Station that ever held this Realm's content. Each entry records that peer's acknowledgement status and time, backing the aggregate fanout_status.
items · object
* peer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* status ·
string (enum)'pending' = awaiting this peer's feedback receipt; 'acknowledged' = peer returned a receipt (regardless of its outcome); 'failed' = peer reported a non-completed feedback outcome (partially_completed / blocked_by_legal_hold); 'timed_out' = no feedback within erasure_propagation_window_ms.
enum:
"pending" "acknowledged" "failed" "timed_out"receipt_id ·
stringThe peer's own feedback receipt id, when received.
pattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$acknowledged_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* retained_stub · object · $ref ./erasure-verification-stub.schema.json
Minimal retained verification stub bound by erasure-receipt.retained_stub_digest. It preserves event graph, proof, authority commit, redaction, legal-hold and receipt linkage evidence without retaining erased plaintext.
allOf · allOf[0] ·
?* stub_schema ·
const "ak.schema.erasure_verification_stub.v1"enum:
"ak.schema.erasure_verification_stub.v1"* subject ·
$ref #/$defs/subject · $ref #/$defs/subject* scope ·
$ref #/$defs/scope · $ref #/$defs/scopeevent_digest ·
string · $ref #/$defs/digestOptional redundant digest for an Event subject; it is permitted only when subject.kind is event and MUST be absent for every other subject kind. Its suite and all 32 digest octets MUST exactly match the suite wire code and digest carried by subject.subject_ref. If omitted, the suite and digest are recovered from the Event ID. This field and the Event ID preserve consistency evidence; neither independently verifies erased canonical Event bytes.
pattern:
^sha256:[0-9a-f]{64}$retained_digests · array<$ref #/$defs/digest>
items ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$commit_inclusion · object
commit_ref ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_refsource_commit_ref ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$redaction_authorization_ref ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_reflegal_hold_ref · oneOf[3]
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
$ref #/$defs/policy_id · $ref #/$defs/policy_idoneOf · oneOf[2] ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* trigger ·
$ref #/$defs/trigger · $ref #/$defs/triggerExact closed trigger copied byte-for-byte from the receipt.
* completed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[2] · oneOf[2] · $ref #/$defs/erasure_receipt_submit_outcome
oneOf · oneOf[0] · object · $ref #/$defs/erasure_receipt_acceptance
Receiver-signed acceptance. proof signs H('ak.erasure-receipt-acceptance.v1', this object without proof). A duplicate reuses the original accepted_at and byte-identical acceptance object.
* status ·
string (enum)enum:
"accepted" "duplicate"* receipt_id ·
string · $ref #/$defs/receipt_idpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* receipt_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* receiver_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proof · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[1] · object
* status ·
const "rejected"enum:
"rejected"* receipt_id ·
string · $ref #/$defs/receipt_idpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reason_code ·
string (enum)enum:
"erasure_receipt_authority_invalid" "erasure_receipt_proof_invalid" "erasure_receipt_stub_binding_mismatch" "erasure_receipt_stub_digest_mismatch" "duplicate_conflict" "unauthorized"oneOf · oneOf[3] · object · $ref #/$defs/erasure_receipt_resource
Result of ak.peer.erasure_receipt.resource.get.v1. The package is byte-identical in semantic content to the accepted submit package; no later lookup may substitute another retained stub.
* package · object · $ref #/$defs/erasure_receipt_package
Self-contained acceptance package. retained_stub is carried exactly once at package level and receipt.retained_stub MUST be absent. The receiver computes H('ak.erasure-receipt.v1', receipt) for addressing and acceptance; retained_stub_digest MUST equal SHA-256(RFC8785_JCS(retained_stub)).
allOf · allOf[0] · object
receipt ·
?* receipt · object · $ref ./erasure-receipt.schema.json
Signed attestation that an issuer completed, partially completed, or blocked a hard-erasure request within a declared storage boundary. It proves the issuer's deletion action and retained verification stub, not disappearance of independent third-party copies.
allOf · allOf[0] ·
?* schema ·
const "ak.schema.erasure_receipt.v1"enum:
"ak.schema.erasure_receipt.v1"* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* trigger · oneOf[2] · $ref ./erasure-verification-stub.schema.json#/$defs/trigger
Exact authoritative fact that created this physical-erasure execution. Account erasure uses the account_status_record branch; other Event-authorized erasure uses the event branch.
oneOf · oneOf[0] · object
* kind ·
const "event"enum:
"event"* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "account_status_record"enum:
"account_status_record"* account_status_record_id ·
string · $ref ./common-ids.schema.json#/$defs/account_status_record_idAccount Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern:
^ak:account_status_record:[A-Za-z0-9_-]{44}$* issuer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* subject · oneOf[6] · $ref ./erasure-verification-stub.schema.json#/$defs/subject
oneOf · oneOf[0] ·
$ref #/$defs/principal_subject · $ref #/$defs/principal_subjectoneOf · oneOf[1] ·
$ref #/$defs/realm_subject · $ref #/$defs/realm_subjectoneOf · oneOf[2] ·
$ref #/$defs/event_subject · $ref #/$defs/event_subjectoneOf · oneOf[3] ·
$ref #/$defs/blob_subject · $ref #/$defs/blob_subjectoneOf · oneOf[4] ·
$ref #/$defs/device_subject · $ref #/$defs/device_subjectoneOf · oneOf[5] ·
$ref #/$defs/account_private_state_subject · $ref #/$defs/account_private_state_subject* scope · object · $ref ./erasure-verification-stub.schema.json#/$defs/scope
Boundary in which deletion was attempted. This MUST be narrow enough for an auditor to tell which service/storage class made the claim.
* storage_boundary ·
string (enum)enum:
"canonical_log_minimization" "blob_store" "projection_store" "account_private_store" "search_index" "push_routes" "device_secret_store" "media_derivatives" "service_defined"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$target_refs · array<$ref #/$defs/subject_ref>
items ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_refretention_policy_id ·
$ref #/$defs/policy_id · $ref #/$defs/policy_idservice_scope ·
string* outcome ·
string (enum)enum:
"completed" "partially_completed" "blocked_by_legal_hold"* erased_classes · array<string (enum)>
items ·
string (enum)enum:
"canonical_payload_bytes" "blob_bytes" "projection_rows" "account_private_state" "push_routes" "device_secrets" "search_index_entries" "derived_plaintext" "media_derivatives"* retained_stub_digest ·
string · $ref #/$defs/digestHash of the retained verification stub after erasure: hash(canonical_json(retained_stub)). The stub verifies typed-reference structure, redundant digest consistency, receipt/stub binding, and linkage to retained external proof, RealmCommit, redaction-authorization, and legal-hold evidence. It does not independently verify erased canonical Event bytes.
pattern:
^sha256:[0-9a-f]{64}$retained_stub · object · $ref ./erasure-verification-stub.schema.json
Minimal retained verification stub bound by erasure-receipt.retained_stub_digest. It preserves event graph, proof, authority commit, redaction, legal-hold and receipt linkage evidence without retaining erased plaintext.
allOf · allOf[0] ·
?* stub_schema ·
const "ak.schema.erasure_verification_stub.v1"enum:
"ak.schema.erasure_verification_stub.v1"* subject ·
$ref #/$defs/subject · $ref #/$defs/subject* scope ·
$ref #/$defs/scope · $ref #/$defs/scopeevent_digest ·
string · $ref #/$defs/digestOptional redundant digest for an Event subject; it is permitted only when subject.kind is event and MUST be absent for every other subject kind. Its suite and all 32 digest octets MUST exactly match the suite wire code and digest carried by subject.subject_ref. If omitted, the suite and digest are recovered from the Event ID. This field and the Event ID preserve consistency evidence; neither independently verifies erased canonical Event bytes.
pattern:
^sha256:[0-9a-f]{64}$retained_digests · array<$ref #/$defs/digest>
items ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$commit_inclusion · object
commit_ref ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_refsource_commit_ref ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$redaction_authorization_ref ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_reflegal_hold_ref · oneOf[3]
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
$ref #/$defs/policy_id · $ref #/$defs/policy_idoneOf · oneOf[2] ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* trigger ·
$ref #/$defs/trigger · $ref #/$defs/triggerExact closed trigger copied byte-for-byte from the receipt.
* completed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$legal_hold_ref · oneOf[3]
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
$ref #/$defs/policy_id · $ref #/$defs/policy_idoneOf · oneOf[2] ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* completed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* proofs · array<object>
items · object
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* signature ·
stringfanout_status ·
string (enum)Cross-Station erasure receipt fanout aggregate status tracked by the issuing server (models/realm-and-space.md §2.6.2). 'pending' = peers still within erasure_propagation_window_ms and not all acknowledged; 'complete' = every peer that ever held this Realm's content returned a receipt; 'incomplete' = at least one peer failed to acknowledge within erasure_propagation_window_ms. The issuing server MUST surface 'incomplete' to audit/UI and MUST NOT silently swallow it. Absent on receipts that do not drive fanout tracking.
enum:
"pending" "complete" "incomplete"peer_receipts · array<object>
Per-peer fanout acknowledgement records maintained by the issuing server: one entry per peer Station that ever held this Realm's content. Each entry records that peer's acknowledgement status and time, backing the aggregate fanout_status.
items · object
* peer_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* status ·
string (enum)'pending' = awaiting this peer's feedback receipt; 'acknowledged' = peer returned a receipt (regardless of its outcome); 'failed' = peer reported a non-completed feedback outcome (partially_completed / blocked_by_legal_hold); 'timed_out' = no feedback within erasure_propagation_window_ms.
enum:
"pending" "acknowledged" "failed" "timed_out"receipt_id ·
stringThe peer's own feedback receipt id, when received.
pattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$acknowledged_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* retained_stub · object · $ref ./erasure-verification-stub.schema.json
Minimal retained verification stub bound by erasure-receipt.retained_stub_digest. It preserves event graph, proof, authority commit, redaction, legal-hold and receipt linkage evidence without retaining erased plaintext.
allOf · allOf[0] ·
?* stub_schema ·
const "ak.schema.erasure_verification_stub.v1"enum:
"ak.schema.erasure_verification_stub.v1"* subject ·
$ref #/$defs/subject · $ref #/$defs/subject* scope ·
$ref #/$defs/scope · $ref #/$defs/scopeevent_digest ·
string · $ref #/$defs/digestOptional redundant digest for an Event subject; it is permitted only when subject.kind is event and MUST be absent for every other subject kind. Its suite and all 32 digest octets MUST exactly match the suite wire code and digest carried by subject.subject_ref. If omitted, the suite and digest are recovered from the Event ID. This field and the Event ID preserve consistency evidence; neither independently verifies erased canonical Event bytes.
pattern:
^sha256:[0-9a-f]{64}$retained_digests · array<$ref #/$defs/digest>
items ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$commit_inclusion · object
commit_ref ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_refsource_commit_ref ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$redaction_authorization_ref ·
$ref #/$defs/subject_ref · $ref #/$defs/subject_reflegal_hold_ref · oneOf[3]
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
$ref #/$defs/policy_id · $ref #/$defs/policy_idoneOf · oneOf[2] ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* trigger ·
$ref #/$defs/trigger · $ref #/$defs/triggerExact closed trigger copied byte-for-byte from the receipt.
* completed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/erasure-receipt-operations.schema.json