ak.schema.ice_config_response.v1
ak.schema.ice_config_response.v1 · file: schemas/ice-config-response.schema.json Result shape for the WebRTC media service ICE config endpoint. Used by ak.profile.webrtc_media.v1; see crypto-media/webrtc-signaling.md §4.
* $ · object
Result shape for the WebRTC media service ICE config endpoint. Used by ak.profile.webrtc_media.v1; see crypto-media/webrtc-signaling.md §4.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* call_id ·
stringEcho of the request call id. Bound into the signature to prevent cross-call replay.
pattern:
^ak:call:[A-Za-z0-9_-]{44}$* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* device_id ·
stringDevice that may use this ICE configuration. Bound into the signature.
pattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* ice_servers · array<$ref #/$defs/ice_server>
STUN / TURN server entries the client may use during this call.
items · object · $ref #/$defs/ice_server
* urls · oneOf[2]
STUN/TURN server URL(s). Schemes: stun:, stuns:, turn:, turns:.
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
stringusername ·
stringTURN ephemeral credential username. v1: <expiry-unix>:<per-call-pseudonym>. MUST NOT contain principal DID, handle, email, or any cross-call stable identifier.
credential ·
stringTURN ephemeral credential password (HMAC-SHA256 of username with per-tenant turn shared secret in REST-style).
credential_type ·
string (enum)enum:
"password" "oauth"example:
"password"(^x_[a-z][a-z0-9_]{0,63}$) ·
any* ttl_seconds ·
integerValidity window for the issued credentials in seconds. Clients MUST refresh before this expires; servers SHOULD pick a value <= 1 hour for normal calls.
* refresh_lead_seconds ·
integerMinimum lead time before ttl expiry at which the client SHOULD initiate refresh. refresh_lead_seconds MUST be strictly less than ttl_seconds (servers MUST NOT issue refresh_lead_seconds >= ttl_seconds, otherwise the client would judge the credential stale at issuance and storm refresh). Defaults SHOULD be ttl_seconds / 4. The recommended floor (60s) applies only when ttl_seconds is large enough that floor < ttl_seconds still holds; for small ttl (e.g. the 60s minimum) the server MUST shrink refresh_lead_seconds below ttl_seconds (see webrtc-signaling.md §4.2). Required so all clients refresh at consistent cadence and servers can plan secret rotation grace windows.
* issued_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$turn_required ·
booleanWhen true, clients MUST disable host/srflx ICE candidates and only relay through TURN. Used by high-privacy Realms to prevent IP leakage.
example:
falseconstraints · object
Optional server-suggested ICE policy.
udp_allowed ·
booleanexample:
truetcp_allowed ·
booleanexample:
trueipv6_allowed ·
booleanexample:
truenext_retry_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* signature · object · $ref #/$defs/signature
Detached signature by the media service DID over the canonical bytes of this response (excluding `signature`).
* kid ·
stringDID URL of the concrete media-service verification method. Bare DID is not accepted because the response must pin one already accepted service key binding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature_algorithm ·
string (enum)Current-v1 signature algorithm. Reserved algorithms, including ML-DSA-65, are rejected as unsupported until a new negotiated schema/profile activates them while preserving the exact signing input defined in webrtc-signaling.md §4.1.
enum:
"Ed25519"* sig ·
stringbase64url-encoded detached signature over canonical response bytes.
pattern:
^[A-Za-z0-9_-]+={0,2}$(^x_[a-z][a-z0-9_]{0,63}$) ·
anySource
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/ice-config-response.schema.json