ak.schema.holder_quarantine.v1
ak.schema.holder_quarantine.v1 · file: schemas/holder-quarantine.schema.json Closed plaintext account-data typed current result value of ak.account.holder_quarantine. The recipient Station is the sole CAS writer; the typed current result is a pending-review pointer inbox and grants no membership, contact, or consent authority. surface_kind is the closed discriminator: invite_delivery entries reference an accepted invite Event and its introduction evidence, consent_request entries reference no Event at all. Contact delivery is not a branch here: a Contact request has its own pending_incoming state and MUST NOT get a second parallel review carrier.
* $ · object
Closed plaintext account-data typed current result value of ak.account.holder_quarantine. The recipient Station is the sole CAS writer; the typed current result is a pending-review pointer inbox and grants no membership, contact, or consent authority. surface_kind is the closed discriminator: invite_delivery entries reference an accepted invite Event and its introduction evidence, consent_request entries reference no Event at all. Contact delivery is not a branch here: a Contact request has its own pending_incoming state and MUST NOT get a second parallel review carrier.
* schema ·
const "ak.schema.holder_quarantine.v1"enum:
"ak.schema.holder_quarantine.v1"* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* quarantine_entries · array<$ref #/$defs/quarantine_entry>
Bounded pending-review entries, oldest first. Expired entries are purged before a write and overflow evicts the oldest entries.
items · object · $ref #/$defs/quarantine_entry
One pending-review quarantined admission. Membership in quarantine_entries is the only state this typed current result expresses: an entry is pending review until the holder reviews it or its TTL discards it, so no status member is carried. The two surface_kind branches are closed and mutually exclusive; a member declared by the other branch is a schema violation.
allOf · allOf[0] ·
?* entry_digest ·
string · $ref #/$defs/digestRecipient-service-local stable deduplication digest for this quarantined delivery.
pattern:
^sha256:[0-9a-f]{64}$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* source_peer_principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* source_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* surface_kind ·
string (enum) · $ref #/$defs/surface_kindClosed discriminator for the admission surface that produced this entry. An unregistered value fails closed.
enum:
"invite_delivery" "consent_request"* consent_scope ·
string (enum)Requested consent scope. The invite_delivery branch pins it to invite; the consent_request branch admits every other registered scope. The enum mirrors zh/identity/consent-model.md section 4.
enum:
"invite" "voice_call" "video_call" "presence" "any"introduction_kind ·
string (enum) · $ref #/$defs/introduction_kindIntroduction evidence kind presented by the requester. invite_delivery branch only; a consent request has no introduction evidence, so any value there would be fabricated.
enum:
"locator_ref" "consent_grant" "shared_realm" "handle_claim" "same_station" "explicit_address"effective_kind ·
string (enum) · $ref #/$defs/introduction_kindEvidence kind after verification downgrade.
enum:
"locator_ref" "consent_grant" "shared_realm" "handle_claim" "same_station" "explicit_address"trust_tier ·
string (enum)enum:
"high" "discovery" "low"invite_event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$request_digest ·
string · $ref #/$defs/digestReplay deduplication digest of the invite delivery request. invite_delivery branch only: ak.self.consent.command.request.v1 declares idempotency_mechanism none and carries no nonce, so its branch deduplicates by live-entry uniqueness instead.
pattern:
^sha256:[0-9a-f]{64}$idempotency_key_digest ·
string · $ref #/$defs/digestDigest of the invite delivery Idempotency-Key. invite_delivery branch only, for the same reason as request_digest.
pattern:
^sha256:[0-9a-f]{64}$* received_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$last_invalidation · object · $ref #/$defs/consent_revoke_invalidation
Optional diagnostic for the latest accepted consent-revoke invalidation. It is holder-private and never disclosed to the requester.
* reason ·
const "consent_revoke"enum:
"consent_revoke"* peer_principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* consent_scope ·
string (enum)enum:
"invite" "any"* revoked_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* removed_entries ·
integerSource
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/holder-quarantine.schema.json