跳转到内容

ak.schema.erasure_verification_stub.v1

← Schemas

Arkret Erasure Verification Stub
ak.schema.erasure_verification_stub.v1 · file: schemas/erasure-verification-stub.schema.json

Minimal retained verification stub bound by erasure-receipt.retained_stub_digest. It preserves event graph, proof, authority commit, redaction, legal-hold and receipt linkage evidence without retaining erased plaintext.

* $ · object
Minimal retained verification stub bound by erasure-receipt.retained_stub_digest. It preserves event graph, proof, authority commit, redaction, legal-hold and receipt linkage evidence without retaining erased plaintext.
allOf · allOf[0] · ?
* stub_schema · const "ak.schema.erasure_verification_stub.v1"
enum: "ak.schema.erasure_verification_stub.v1"
* subject · oneOf[6] · $ref #/$defs/subject
oneOf · oneOf[0] · object · $ref #/$defs/principal_subject
* kind · const "principal"
enum: "principal"
* subject_ref · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
oneOf · oneOf[1] · object · $ref #/$defs/realm_subject
* kind · const "realm"
enum: "realm"
* subject_ref · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object · $ref #/$defs/event_subject
* kind · const "event"
enum: "event"
* subject_ref · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[3] · object · $ref #/$defs/blob_subject
* kind · const "blob"
enum: "blob"
* subject_ref · string · $ref ./common-ids.schema.json#/$defs/blob_ref
Content-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern: ^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$
oneOf · oneOf[4] · object · $ref #/$defs/device_subject
* kind · const "device"
enum: "device"
* subject_ref · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[5] · object · $ref #/$defs/account_private_state_subject
* kind · const "account_private_state"
enum: "account_private_state"
* subject_ref · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* scope · object · $ref #/$defs/scope
* storage_boundary · string (enum)
enum: "canonical_log_minimization" "blob_store" "projection_store" "account_private_store" "search_index" "push_routes" "device_secret_store" "media_derivatives" "service_defined"
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
target_refs · array<$ref #/$defs/subject_ref>
items · string · $ref #/$defs/subject_ref
pattern: ^(did:[^\s]+|(?:ak:(realm|event|message|strand|morph|relation|view):[A-Za-z0-9_-]{44}|ak:(blob|device|policy|receipt):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})|ak:blob:(?:sha256|blake3):[0-9a-f]{64}|sha256:[0-9a-f]{64})$
retention_policy_id · string · $ref #/$defs/policy_id
pattern: ^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
service_scope · string
event_digest · string · $ref #/$defs/digest
Optional redundant digest for an Event subject; it is permitted only when subject.kind is event and MUST be absent for every other subject kind. Its suite and all 32 digest octets MUST exactly match the suite wire code and digest carried by subject.subject_ref. If omitted, the suite and digest are recovered from the Event ID. This field and the Event ID preserve consistency evidence; neither independently verifies erased canonical Event bytes.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
retained_digests · array<$ref #/$defs/digest>
items · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
commit_inclusion · object
commit_ref · string · $ref #/$defs/subject_ref
pattern: ^(did:[^\s]+|(?:ak:(realm|event|message|strand|morph|relation|view):[A-Za-z0-9_-]{44}|ak:(blob|device|policy|receipt):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})|ak:blob:(?:sha256|blake3):[0-9a-f]{64}|sha256:[0-9a-f]{64})$
source_commit_ref · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
redaction_authorization_ref · string · $ref #/$defs/subject_ref
pattern: ^(did:[^\s]+|(?:ak:(realm|event|message|strand|morph|relation|view):[A-Za-z0-9_-]{44}|ak:(blob|device|policy|receipt):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})|ak:blob:(?:sha256|blake3):[0-9a-f]{64}|sha256:[0-9a-f]{64})$
legal_hold_ref · oneOf[3]
oneOf · oneOf[0] · null
oneOf · oneOf[1] · string · $ref #/$defs/policy_id
pattern: ^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[2] · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* receipt_id · string
pattern: ^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* trigger · oneOf[2] · $ref #/$defs/trigger
Exact closed trigger copied byte-for-byte from the receipt.
oneOf · oneOf[0] · object
* kind · const "event"
enum: "event"
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "account_status_record"
enum: "account_status_record"
* account_status_record_id · string · $ref ./common-ids.schema.json#/$defs/account_status_record_id
Account Authority issuer-ledger record identity derived from the complete closed unsigned AccountStatusRecord core.
pattern: ^ak:account_status_record:[A-Za-z0-9_-]{44}$
* completed_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$

Source