ak.schema.extension_manifest.v1
ak.schema.extension_manifest.v1 · file: schemas/extension-manifest.schema.json * $ · object
* manifest_id ·
stringpattern:
^ak\.manifest\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v1$* extension_id ·
stringpattern:
^ak\.extension\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v1$* namespace ·
stringpattern:
^ak\.[a-z0-9_]+(?:\.[a-z0-9_]+)*$* protocol_layer_kind ·
string (enum)enum:
"collaboration_base" "extension"* manifest_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* publisher_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* published_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* dependency_refs · array<$ref #/$defs/registry_content_ref>
items · object · $ref #/$defs/registry_content_ref
* registry_id ·
stringVersioned registry symbol for a dependency, payload schema, or conformance vector.
pattern:
^ak\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v1$* digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$retrieval_url ·
string (uri) · format=uriOptional retrieval hint only. The registry_id plus digest, not this URL, identifies the referenced content.
pattern:
^https://* payload_schema_refs · array<$ref #/$defs/registry_content_ref>
items · object · $ref #/$defs/registry_content_ref
* registry_id ·
stringVersioned registry symbol for a dependency, payload schema, or conformance vector.
pattern:
^ak\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v1$* digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$retrieval_url ·
string (uri) · format=uriOptional retrieval hint only. The registry_id plus digest, not this URL, identifies the referenced content.
pattern:
^https://* reducer_contract_refs · array<$ref #/$defs/reducer_contract_ref>
items · object · $ref #/$defs/reducer_contract_ref
Digest-bound registered reducer contract. Execution, state models and conditional writes come only from that contract; the manifest cannot choose a different synchronization class or state profile.
* reducer_contract_id ·
stringpattern:
^ak\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v1$* digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* required_actions · array<string>
items ·
stringpattern:
^ak\.[a-z0-9_]+(?:\.[a-z0-9_]+)*$* confidentiality_class ·
string (enum)enum:
"plaintext_allowed" "recipient_encrypted" "e2ee_required"* transport_rail_ids · array<string>
items ·
stringpattern:
^ak\.[a-z0-9_]+(?:\.[a-z0-9_]+)*$* recovery_profile_ref · oneOf[2]
oneOf · oneOf[0] ·
stringpattern:
^ak\.profile\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v1$oneOf · oneOf[1] ·
null* federation_profile_ref · oneOf[2]
oneOf · oneOf[0] ·
stringpattern:
^ak\.profile\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v1$oneOf · oneOf[1] ·
null* conformance_vector_refs · array<$ref #/$defs/registry_content_ref>
items · object · $ref #/$defs/registry_content_ref
* registry_id ·
stringVersioned registry symbol for a dependency, payload schema, or conformance vector.
pattern:
^ak\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v1$* digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$retrieval_url ·
string (uri) · format=uriOptional retrieval hint only. The registry_id plus digest, not this URL, identifies the referenced content.
pattern:
^https://* resource_limits · object
max_canonical_bytes ·
integermax_item_count ·
integermax_depth ·
integermax_operation_count_per_minute ·
integer* proofs · array<$ref ./event-envelope.schema.json#/$defs/proof>
items · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampdomain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
stringproof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/extension-manifest.schema.json