ak.schema.key_transparency.v1
ak.schema.key_transparency.v1 · file: schemas/key-transparency.schema.json Canonical Arkret-specific evidence for ak.profile.key_transparency.v1 and high-security/sovereign log-backed witness requirements. This wire object is not an implementation of IETF KEYTRANS and MUST NOT be advertised as such; interop with draft-ietf-keytrans-protocol-05 requires a separately registered adapter/profile.
* $ · object
Canonical Arkret-specific evidence for ak.profile.key_transparency.v1 and high-security/sovereign log-backed witness requirements. This wire object is not an implementation of IETF KEYTRANS and MUST NOT be advertised as such; interop with draft-ietf-keytrans-protocol-05 requires a separately registered adapter/profile.
* schema ·
const "ak.schema.key_transparency.v1"enum:
"ak.schema.key_transparency.v1"* log_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* key_material_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* log_head · object · $ref #/$defs/log_head
* leaf_count ·
integer* tree_root ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* issued_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* inclusion_proof · object · $ref #/$defs/inclusion_proof
* leaf_index ·
integer* leaf_count ·
integer* audit_path · array<$ref #/$defs/digest>
items ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* consistency_proof · object · $ref #/$defs/consistency_proof
* from_leaf_count ·
integer* to_leaf_count ·
integer* audit_path · array<$ref #/$defs/digest>
items ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* witness_signatures · array<$ref #/$defs/witness_signature>
items · object · $ref #/$defs/witness_signature
* witness_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verification_method ·
string · $ref #/$defs/did_urlpattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature ·
stringSource
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/key-transparency.schema.json