跳转到内容

ak.schema.event.v1

← Schemas

Arkret Event Envelope
ak.schema.event.v1 · file: schemas/event-envelope.schema.json

Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.

* $ · object
Closed producer-signed Event. Shared persistent Events become final only when the current Realm governance Station issues a RealmCommit in the derived Realm, Circle, or Sidecar stream.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · allOf[9] · $ref #/$defs/registered_admission_shape
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · ?
allOf · allOf[6] · ?
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[6] · object · $ref #/$defs/registered_execution_shape
* kind · string (enum)
enum: "ak.account_data.set" "ak.agent.action_approve" "ak.agent.action_reject" "ak.agent.action_request" "ak.agent.draft.propose" "ak.agent.interaction.set" "ak.agent.key.authorize" "ak.agent.key.revoke" "ak.agent.provision" "ak.agent.sidecar.exchange.control" "ak.applet.bridge_error" "ak.applet.discovery" "ak.applet.managed_actor.provision" "ak.applet.registration" "ak.audit.accessed" "ak.audit.erasure_receipt" "ak.call.create" "ak.call.recording.start" "ak.call.state" "ak.capability.grant" "ak.capability.relinquish" "ak.capability.revoke" "ak.circle.archive" "ak.circle.create" "ak.circle.history_access" "ak.circle.member.state" "ak.circle.restore" "ak.circle.tombstone" "ak.circle.update" "ak.consent.grant" "ak.consent.revoke" "ak.contact.accepted" "ak.contact.rejected" "ak.contact.requested" "ak.contact.scope.update" "ak.contact.tombstone" "ak.device.authorize" "ak.device.push_route" "ak.device.reanchor" "ak.device.revoke" "ak.direct_conversation.bound" "ak.identity.accountability_grant" "ak.identity.resolution.update" "ak.invite.accept" "ak.invite.cancel" "ak.invite.claim" "ak.invite.create" "ak.invite.revoke" "ak.invite.third_party" "ak.key_backup.active_series" "ak.member.identity.update" "ak.member.state" "ak.message.create" "ak.message.redact" "ak.message.revise" "ak.mimi.room_binding" "ak.mls.commit" "ak.mls.genesis" "ak.moderation.decision" "ak.moderation.decision.lift" "ak.moderation.franking_proof" "ak.morph.archive" "ak.morph.create" "ak.morph.restore" "ak.morph.stage.set" "ak.morph.update" "ak.organization.moderation_policy" "ak.pin.add" "ak.pin.remove" "ak.pin.reorder" "ak.policy.action" "ak.policy.set" "ak.profile.create" "ak.profile.realm_override" "ak.profile.update" "ak.reaction.add" "ak.reaction.remove" "ak.read_cursor.advance" "ak.realm.alias" "ak.realm.archive" "ak.realm.asset_privacy_policy" "ak.realm.authority.reset" "ak.realm.create" "ak.realm.destroy" "ak.realm.discovery" "ak.realm.freeze" "ak.realm.governance_station.change" "ak.realm.history_access" "ak.realm.join_rule" "ak.realm.link" "ak.realm.media_service" "ak.realm.organization" "ak.realm.owner.transfer" "ak.realm.plaintext_visible_services" "ak.realm.policy_bundle" "ak.realm.preview_policy" "ak.realm.profile" "ak.realm.read_receipt_policy" "ak.realm.restore" "ak.realm.schema" "ak.realm.search_policy" "ak.realm.set_default_strand" "ak.realm.tombstone" "ak.realm.unfreeze" "ak.redaction" "ak.relation.create" "ak.relation.tombstone" "ak.relation.update" "ak.rsvp.set" "ak.schema.define" "ak.self.agent.deactivate" "ak.self.agent.pause" "ak.self.agent.resume" "ak.self.moderation.report" "ak.sidecar.context.attach" "ak.sidecar.create" "ak.space.archive" "ak.space.create" "ak.space.parent" "ak.space.restore" "ak.space.tombstone" "ak.space.update" "ak.strand.archive" "ak.strand.create" "ak.strand.move" "ak.strand.reorder" "ak.strand.restore" "ak.strand.stage.set" "ak.strand.tracks.update" "ak.strand.update" "ak.strand.watch.set" "ak.view.create" "ak.view.reconcile" "ak.view.update"
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
allOf · allOf[15] · ?
allOf · allOf[16] · ?
allOf · allOf[17] · ?
allOf · allOf[18] · ?
allOf · allOf[19] · ?
allOf · allOf[20] · ?
allOf · allOf[21] · ?
allOf · allOf[22] · ?
allOf · allOf[23] · ?
allOf · allOf[24] · ?
allOf · allOf[25] · ?
allOf · allOf[26] · ?
allOf · allOf[27] · ?
allOf · allOf[28] · ?
allOf · allOf[29] · ?
allOf · allOf[30] · ?
allOf · allOf[31] · ?
allOf · allOf[32] · ?
allOf · allOf[33] · ?
allOf · allOf[34] · ?
allOf · allOf[35] · ?
allOf · allOf[36] · ?
allOf · allOf[37] · ?
allOf · allOf[38] · ?
allOf · allOf[39] · ?
allOf · allOf[40] · ?
allOf · allOf[41] · ?
allOf · allOf[42] · ?
allOf · allOf[43] · ?
allOf · allOf[44] · ?
allOf · allOf[45] · ?
allOf · allOf[46] · ?
allOf · allOf[47] · ?
allOf · allOf[48] · ?
allOf · allOf[49] · ?
allOf · allOf[50] · ?
allOf · allOf[51] · ?
allOf · allOf[52] · ?
allOf · allOf[53] · ?
allOf · allOf[54] · ?
allOf · allOf[55] · ?
allOf · allOf[56] · ?
allOf · allOf[57] · ?
allOf · allOf[58] · ?
allOf · allOf[59] · ?
allOf · allOf[60] · ?
allOf · allOf[61] · ?
allOf · allOf[62] · ?
allOf · allOf[63] · ?
allOf · allOf[64] · ?
allOf · allOf[65] · ?
allOf · allOf[66] · ?
allOf · allOf[67] · ?
allOf · allOf[68] · ?
allOf · allOf[69] · ?
allOf · allOf[70] · ?
allOf · allOf[71] · ?
allOf · allOf[72] · ?
allOf · allOf[73] · ?
allOf · allOf[74] · ?
allOf · allOf[75] · ?
allOf · allOf[76] · ?
allOf · allOf[77] · ?
allOf · allOf[78] · ?
allOf · allOf[79] · ?
allOf · allOf[80] · ?
allOf · allOf[81] · ?
allOf · allOf[82] · ?
allOf · allOf[83] · ?
allOf · allOf[84] · ?
allOf · allOf[85] · ?
allOf · allOf[86] · ?
allOf · allOf[87] · ?
allOf · allOf[88] · ?
allOf · allOf[89] · ?
allOf · allOf[90] · ?
allOf · allOf[91] · ?
allOf · allOf[92] · ?
allOf · allOf[93] · ?
allOf · allOf[94] · ?
allOf · allOf[95] · ?
allOf · allOf[96] · ?
allOf · allOf[97] · ?
allOf · allOf[98] · ?
allOf · allOf[99] · ?
allOf · allOf[100] · ?
allOf · allOf[101] · ?
allOf · allOf[102] · ?
allOf · allOf[103] · ?
allOf · allOf[104] · ?
allOf · allOf[105] · ?
allOf · allOf[106] · ?
allOf · allOf[107] · ?
allOf · allOf[108] · ?
allOf · allOf[109] · ?
allOf · allOf[110] · ?
allOf · allOf[111] · ?
allOf · allOf[112] · ?
allOf · allOf[113] · ?
allOf · allOf[114] · ?
allOf · allOf[115] · ?
allOf · allOf[116] · ?
allOf · allOf[117] · ?
allOf · allOf[118] · ?
allOf · allOf[119] · ?
allOf · allOf[120] · ?
allOf · allOf[121] · ?
allOf · allOf[122] · ?
allOf · allOf[123] · ?
allOf · allOf[124] · ?
allOf · allOf[125] · ?
allOf · allOf[126] · ?
allOf · allOf[127] · ?
allOf · allOf[128] · ?
allOf · allOf[129] · ?
allOf · allOf[130] · ?
allOf · allOf[131] · ?
allOf · allOf[132] · ?
allOf · allOf[133] · ?
allOf · allOf[134] · ?
allOf · allOf[135] · ?
allOf · allOf[136] · ?
allOf · allOf[137] · ?
allOf · allOf[138] · ?
allOf · allOf[139] · ?
allOf · allOf[140] · ?
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* kind · string
Standard ak.* Event kinds MUST appear in artifacts/registry/event-kind-registry.json. State convergence is defined by the registered pure reducer over kind + payload; producers do not submit typed current result writes.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* scope_ref · oneOf[4] · $ref #/$defs/scope_ref
Required producer-signed security scope. The closed union is ordinary existing realm, circle, or native sidecar scope plus the create-only realm_genesis exception. It enters proof.event_digest and E2EE AAD. Reducers independently derive the exact scope from schema-validated payload and accepted references; missing dependencies, nonexistent scope, realm_id mismatch, omitted sidecar_id, substituting circle for sidecar, or any unequal field is fail closed. Sidecar domain Event kinds remain Extension-owned; recognizing this native security shape does not make Kernel interpret the Sidecar reducer. Exact product targets remain inside recipient-visible ciphertext.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind · const "realm_genesis"
enum: "realm_genesis"
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
authorization_ref · oneOf[6]
Optional. Required when executed_by is present. It identifies an accepted Grant, delegation Event, DID-document delegation, or one of the closed profile-specific authority constants. The current governance Station evaluates the reference against the target stream's committed state.
oneOf · oneOf[0] · string · $ref #/$defs/grant_ref
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string · $ref #/$defs/event_ref
Complete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · string · $ref #/$defs/did_delegation_ref
DID URL of a non-device controller/organization authority entry that designates executed_by for an operation profile. Principal device authorization never uses this DID-document branch: it resolves through accepted PCR evidence. Historical DID authority is resolved at the Event accepted-at basis.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
oneOf · oneOf[3] · const "ak.authority.direct_conversation_participant.v1" · $ref #/$defs/direct_conversation_participant_authority_ref
The daily profile-scoped non-grant authorization source accepted by Event.authorization_ref. It is meaningful solely in ak.profile.direct_conversation_realm.v1 and requires one critical semantic_refs[] role=direct_conversation_binding Event reference. The evaluator rederives the pair's unique immutable binding, exact-two participant membership, Realm/Strand/MLS cross-binding, lifecycle, both directional Contact heads/scopes and action-specific gates without consulting Consent; this constant never authorizes arbitrary Realm or third-party writes.
enum: "ak.authority.direct_conversation_participant.v1"
oneOf · oneOf[4] · const "ak.authority.direct_conversation_bootstrap_participant.v1" · $ref #/$defs/direct_conversation_bootstrap_authority_ref
Pre-binding profile-scoped non-grant authority for a Direct Conversation between accepted founding unit and first legal binding endorsement. It requires one critical founding-unit ref. provisional_history_send authorizes only founder actions in the one scope-derived group; exact_pair_founding_completion applies once that same group holds exact authorized pair leaves. Both retire after the first binding. Neither phase authorizes a second Genesis/group, policy, grant, a third participant, another Strand or ordinary membership writes.
enum: "ak.authority.direct_conversation_bootstrap_participant.v1"
oneOf · oneOf[5] · string · $ref #/$defs/membership_compensation_delegation_ref
Content-addressed accepted-at membership compensation delegation. It is valid only for ak.member.state leave/remove submitted with the matching closed Event submission transport-only membership_compensation_evidence carrier and registered single-use evaluator. This carrier is not an ak:sidecar: Agent Sidecar object and has no participant semantics. The lowercase hex suffix is the sole wire carrier of the delegation digest (encoding.md 4.0.1).
pattern: ^ak:membership_compensation_delegation:sha256:[0-9a-f]{64}$
applet_id · string · $ref #/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
external_ref · object · $ref #/$defs/external_ref
Signed external provenance. Extension profiles define exact field vocabulary; common fields include protocol, network_id, instance_id, user_id, location_id, event_id, external_id, and url. Implementations MUST preserve all fields in canonical bytes and MUST NOT use unsigned.external_ref for security decisions.
schema · string
pattern: ^(ak\.schema\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v[0-9]+|[a-z0-9][a-z0-9_.-]*\.[a-z0-9][a-z0-9_.-]*(?:\.[a-z0-9_.-]+)*\.v[0-9]+)$
protocol · string
pattern: ^[a-z][a-z0-9_.-]{0,63}$
network_id · string
pattern: ^(?!ak:)
instance_id · string
pattern: ^(?!ak:)
user_id · string
pattern: ^(?!ak:)
location_id · string
pattern: ^(?!ak:)
event_id · string
pattern: ^(?!ak:)
external_id · string
pattern: ^(?!ak:)
uri · string (uri) · format=uri
* created_at · string (date-time) · format=date-time · $ref #/$defs/canonical_event_timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
semantic_refs · array<$ref #/$defs/semantic_ref>
Optional semantic refs with role. Omit when there are no semantic references; an explicitly empty array is not canonical. Admission selectors determine any required references. PCR policy recovery has no DID-root anchor reference; its policy/session/replacement-key authority is verified separately.
items · anyOf[2] · $ref #/$defs/semantic_ref
Closed business-reference union. authorized_by names a stable GrantId; all other roles name an immutable Event. Commit continuity is carried only by RealmCommit.previous_commit_ref.
anyOf · anyOf[0] · object
* id · string · $ref #/$defs/grant_ref
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
* role · const "authorized_by"
enum: "authorized_by"
* critical · boolean
anyOf · anyOf[1] · object
* id · string · $ref #/$defs/event_ref
Complete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* role · string (enum)
enum: "attestation" "parent_event" "after" "audit_pair" "recovery_capability" "accountability" "bootstrap_genesis" "disclosure_authorization" "capture_stop" "direct_conversation_binding" "direct_conversation_founding_unit" "direct_conversation_contact_round" "direct_conversation_agent_provision" "applet_managed_actor_provision"
* critical · boolean
* payload · object
* producer_proof · object · $ref #/$defs/event_proof
Producer signature over canonical Event bytes. The current governance Station resolves and validates the signing key at admission; its RealmCommit attests that decision, so no typed current result/RealmCommit signer witness is carried by the Event.
* kind · string (enum)
Detached producer JWS over canonical Event bytes. No Station admission signature is part of the Event proof model.
enum: "detached_jws"
* verification_method · string
DID URL of the Event-signing key. Generic verification extracts the canonical bare DID base under the active method adapter, validates that method history/key, projects the base DID to did_core_id, and compares it byte-for-byte with the principal component of executed_by when present or actor_id otherwise; a did_core_id is never concatenated into a DID URL. For principal device proofs the fragment MUST be the full device_id (`ak:device:<uuidv7>`). Only the admitting governance Station (and a receiver that hosts the producer's own account) resolves the complete actor_id plus device_id through its local device directory or authority_forward producer_device_evidence; every other committed-Event receiver checks this fragment and the projection, then relies on the governance RealmCommit instead of resolving a foreign human device key. The sole exception is an Event whose selected admission variant is registration_anchor: its closed verifier MUST instead resolve the registration-time active update key and controller-proof verification method from that unit's already verified typed principal_registration_anchor, require verification_method to equal that method, and verify the controller proof and update authority against the anchor's own frozen did:webvh history rather than any current resolution; there is no DID-inception Event reference to resolve, and a root did:key controller is not rewritten to the principal actor_id. This exception cannot apply to any other Event. PCR recovery uses the session-frozen replacement device identity key for both Events; did_root is only an optional policy factor, never an alternate Event signer.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* event_digest · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* created_at · string (date-time) · format=date-time · $ref #/$defs/canonical_event_timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for handle-claim proofs. Generic proof consumers ignore it unless their object-family contract makes it required.
enum: "issuer_attestation" "holder_acceptance"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$

Source