ak.schema.key_backup_active_series.v1
ak.schema.key_backup_active_series.v1 · file: schemas/key-backup-active-series.schema.json Signed principal-control record selecting the backup series for one actor and backup kind. Servers verify the accepted record; ordinary clients consume BackupActiveSeriesState from their Account Station instead of replaying PCR history.
* $ · object
Signed principal-control record selecting the backup series for one actor and backup kind. Servers verify the accepted record; ordinary clients consume BackupActiveSeriesState from their Account Station instead of replaying PCR history.
* schema ·
const "ak.schema.key_backup_active_series.v1"enum:
"ak.schema.key_backup_active_series.v1"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* backup_kind ·
string (enum) · $ref #/$defs/backup_kindenum:
"secret_storage"* active_series_id ·
string · $ref #/$defs/backup_series_idpattern:
^ak:backup_series:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* series_pointer_version ·
integerStrictly monotonic per (actor_id, backup_kind). The first record is 1 and every successor is previous+1; receivers reject rollback, gaps and same-version forks.
* previous_series_ids · array<$ref #/$defs/backup_series_id>
Retained old series used only for read-old-data or erasure transition. MUST NOT be treated as a primary recovery source.
items ·
string · $ref #/$defs/backup_series_idpattern:
^ak:backup_series:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* source_commit_ref · object · $ref #/$defs/source_commit_ref
Principal Control Realm source RealmCommit and current identity-root device generation under which active_series_id was selected.
* realm_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* device_generation_ref ·
integer · $ref ./recovery-session.schema.json#/$defs/pcr_generation_refPCR-local monotonic device generation. This is not a DID versionId and MUST equal the accepted current_device_generation_ref at the referenced checkpoint.
* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* auth_data · object
* verification_method ·
string · $ref #/$defs/did_urlpattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature_algorithm ·
string (enum)enum:
"Ed25519"* signature ·
stringbase64url signature over RFC 8785 JCS(record without auth_data.signature). The closed record shape fixes the authenticated projection.
pattern:
^[A-Za-z0-9_-]+$* device_authorize_event_id ·
stringAccepted current-generation ak.device.authorize Event anchoring the device that signed this active-series selection.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$(^x_[a-z][a-z0-9_]{0,63}$) ·
anySource
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/key-backup-active-series.schema.json