ak.schema.high_risk_authority_proof.v1
ak.schema.high_risk_authority_proof.v1 · file: schemas/high-risk-authority-proof.schema.json Shared authority proof family for service operations that key-management.md designates as high-risk material destruction or equivalent (first consumer: active-series key backup tail deletion, key-management.md section 7.8). Exactly one closed branch: recovery_unlock, device_quorum, or trusted_recovery_service, discriminated by `kind`. Every branch reuses the common detached-JWS leaf (event-envelope.schema.json#/$defs/proof) over the operation's single canonical delete-intent transcript; branches never restate the leaf fields. An ordinary current-device session proof is deliberately NOT a branch of this family — operations that accept it for low-risk paths must say so in their own normative text. This is one wire leaf with per-consumer domain separation: the transcript context is owned by the consuming operation, never by the leaf, so x-arkret-proof-contexts below enumerates every registered consumer context and proof-context-registry.json carries the matching consumer_operation on each row.
* $ · oneOf[3]
oneOf · oneOf[0] · object · $ref #/$defs/recovery_unlock_proof
const "recovery_unlock""recovery_unlock"string · $ref #/$defs/recovery_session_id^ak:recovery_session:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* proof · object · $ref #/$defs/detached_proof
string (enum)"detached_jws"string^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$$ref #/$defs/digest · $ref #/$defs/digest$ref #/$defs/timestamp · $ref #/$defs/timestampstringaudience · oneOf[2]
stringoneOf · oneOf[1] · array<string>
stringstring (enum)"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"string^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[1] · object · $ref #/$defs/device_quorum_proof
const "device_quorum""device_quorum"integer* signatures · array<$ref #/$defs/device_quorum_signature>
items · object · $ref #/$defs/device_quorum_signature
string · $ref #/$defs/device_id^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* proof · object · $ref #/$defs/detached_proof
string (enum)"detached_jws"string^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$$ref #/$defs/digest · $ref #/$defs/digest$ref #/$defs/timestamp · $ref #/$defs/timestampstringaudience · oneOf[2]
stringoneOf · oneOf[1] · array<string>
stringstring (enum)"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"string^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[2] · object · $ref #/$defs/trusted_recovery_service_proof
const "trusted_recovery_service""trusted_recovery_service"string · $ref ./common-ids.schema.json#/$defs/did_core_id^ak:did_core:[a-z0-9]+:[^\s/?#]+$string · $ref #/$defs/recovery_session_id^ak:recovery_session:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* proof · object · $ref #/$defs/detached_proof
string (enum)"detached_jws"string^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$$ref #/$defs/digest · $ref #/$defs/digest$ref #/$defs/timestamp · $ref #/$defs/timestampstringaudience · oneOf[2]
stringoneOf · oneOf[1] · array<string>
stringstring (enum)"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"string^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/high-risk-authority-proof.schema.json