ak.schema.keys_operations.v1
ak.schema.keys_operations.v1 · file: schemas/keys-operations.schema.json Closed request and response DTOs for ak.keys.{upload,query,claim}, the Station-to-Station device directory read and ak.keys.backups.{put,list,delete}. Individual OpenAPI components reference the $defs entries in this bundle.
* $ · oneOf[15]
Closed request and response DTOs for ak.keys.{upload,query,claim}, the Station-to-Station device directory read and ak.keys.backups.{put,list,delete}. Individual OpenAPI components reference the $defs entries in this bundle.
oneOf · oneOf[0] · object · $ref #/$defs/keys_upload_request_body
* device_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* device_signature · object · $ref #/$defs/signature
* kid ·
string · $ref #/$defs/non_empty_stringsignature_algorithm ·
string (enum)enum:
"Ed25519"* sig ·
string · $ref #/$defs/base64urlpattern:
^[A-Za-z0-9_-]+$one_time_keys ·
object · $ref #/$defs/algorithm_key_recordsfallback_keys ·
object · $ref #/$defs/algorithm_key_recordsoneOf · oneOf[1] · object · $ref #/$defs/keys_upload_outcome
* one_time_key_counts ·
object · $ref #/$defs/algorithm_countsfallback_keys ·
object · $ref #/$defs/algorithm_key_recordsoneOf · oneOf[2] · object · $ref #/$defs/keys_query_request_body
* device_keys · array<object> · $ref #/$defs/query_account_device_selectors
Explicit account/device selectors sorted by unsigned UTF-8 bytes of RFC 8785 JCS(account_id). Neither AccountId component may be inferred from the target service, caller session or another entry. Duplicate AccountIds MUST be rejected; use one entry containing all selected device_ids for that account. At most 16 accounts and 32 devices per account bound the local read and its cross-Station fan-out alike; an over-limit request fails whole and is never truncated.
items · object
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* device_ids · array<$ref #/$defs/device_id>
items ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$timeout_ms ·
integeroneOf · oneOf[3] · object · $ref #/$defs/keys_query_outcome
* device_keys · array<object> · $ref #/$defs/query_account_device_entries
One device-key result group per exact AccountId on the self surface. The returning Station MUST have matched each verified attestation's account_id and device_id against this account_id and its enclosing device_id key before projecting the row. Entries MUST be sorted by RFC 8785 JCS AccountId bytes with no duplicate account identity.
items · object
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* device_keys ·
object · $ref #/$defs/query_device_keysfailures · array<$ref #/$defs/query_failure>
items · object · $ref #/$defs/query_failure
Closed non-enumerating failure row for the device directory read surfaces. device_result_unavailable covers absent, invisible, unrelated, revoked, fenced and policy-denied targets with one indistinguishable value. device_directory_unavailable states only that the requester's own Station could not obtain or verify a current attested projection this time; it never depends on target state and MUST NOT be rendered as an omitted row or an empty device set.
account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_iddevice_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reason_code ·
string (enum)enum:
"device_result_unavailable" "device_directory_unavailable"retry_after_ms ·
integerOnly meaningful with device_directory_unavailable; a target-private failure MUST NOT carry it.
device_generations · array<object> · $ref #/$defs/account_device_generation_entries
Current device-generation fence for each exact AccountId. Entries MUST be sorted by RFC 8785 JCS AccountId bytes with no duplicate account identity.
items · object
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* generation_state · object · $ref #/$defs/device_generation_state
Reducer-managed identity-root generation fence for the principal device directory.
* current_device_generation_ref ·
integer · $ref ./recovery-session.schema.json#/$defs/pcr_generation_refPCR-local monotonic generation; it is not and MUST NOT be derived from a DID versionId.
oneOf · oneOf[4] · object · $ref #/$defs/peer_keys_query_request_body
Station-to-Station device directory and published prekey-bundle read. It is the only registered carrier for a cross-Station keys/query target: the client asks its own Station, which authenticates itself with its own RFC 9421 service signature and never forwards a client SessionGrant, DPoP or any local bearer. Single authority, single hop, read only. Cross-Station single-use material stays with the MLS KeyPackage claim contract.
* request_id ·
string · $ref ./account-operations.schema.json#/$defs/request_idStable typed id the requesting Station mints for this fetch. The destination uses it only for correlation and rate limiting and keeps no durable ledger.
pattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* requester_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* purpose ·
string (enum) · $ref #/$defs/peer_keys_query_purposeDeclared use of the requested directory rows. The destination authorizes each purpose independently and MUST NOT clear the broadest one once.
enum:
"e2ee_message_encryption" "mls_group_admission" "call_media"* relationship_basis · oneOf[2] · $ref #/$defs/peer_keys_relationship_basis
Closed relationship the requester asserts. The destination re-derives it from its own accepted state; a caller assertion never authorizes by itself. The contact branch deliberately carries no realm_id: a legitimate Contact needs no shared Realm.
oneOf · oneOf[0] · object
* kind ·
const "realm_membership"enum:
"realm_membership"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "contact"enum:
"contact"* device_keys · array<object> · $ref #/$defs/query_account_device_selectors
Explicit account/device selectors sorted by unsigned UTF-8 bytes of RFC 8785 JCS(account_id). Neither AccountId component may be inferred from the target service, caller session or another entry. Duplicate AccountIds MUST be rejected; use one entry containing all selected device_ids for that account. At most 16 accounts and 32 devices per account bound the local read and its cross-Station fan-out alike; an over-limit request fails whole and is never truncated.
items · object
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* device_ids · array<$ref #/$defs/device_id>
items ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$oneOf · oneOf[5] · object · $ref #/$defs/peer_keys_query_outcome
Verbatim origin-signed rows plus the closed non-enumerating failure shape. The destination does not add a response signature layer: every row carries the origin's own device_projection_attestation and signer_evidence_ref, and the requesting Station MUST verify them before projecting the restricted client-facing query_device_record.
* request_id ·
string · $ref ./account-operations.schema.json#/$defs/request_idEchoed byte-for-byte from the request.
pattern:
^ak:request:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* requester_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* device_keys · array<object> · $ref #/$defs/peer_query_account_device_entries
One device-key result group per exact AccountId on the Station-to-Station surface. Each signed device projection MUST match this account_id and its enclosing device_id key. Entries MUST be sorted by RFC 8785 JCS AccountId bytes with no duplicate account identity.
items · object
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* device_keys ·
object · $ref #/$defs/peer_query_device_keysdevice_generations · array<object> · $ref #/$defs/account_device_generation_entries
Current device-generation fence for each exact AccountId. Entries MUST be sorted by RFC 8785 JCS AccountId bytes with no duplicate account identity.
items · object
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* generation_state · object · $ref #/$defs/device_generation_state
Reducer-managed identity-root generation fence for the principal device directory.
* current_device_generation_ref ·
integer · $ref ./recovery-session.schema.json#/$defs/pcr_generation_refPCR-local monotonic generation; it is not and MUST NOT be derived from a DID versionId.
failures · array<$ref #/$defs/query_failure>
items · object · $ref #/$defs/query_failure
Closed non-enumerating failure row for the device directory read surfaces. device_result_unavailable covers absent, invisible, unrelated, revoked, fenced and policy-denied targets with one indistinguishable value. device_directory_unavailable states only that the requester's own Station could not obtain or verify a current attested projection this time; it never depends on target state and MUST NOT be rendered as an omitted row or an empty device set.
account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_iddevice_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reason_code ·
string (enum)enum:
"device_result_unavailable" "device_directory_unavailable"retry_after_ms ·
integerOnly meaningful with device_directory_unavailable; a target-private failure MUST NOT carry it.
oneOf · oneOf[6] · object · $ref #/$defs/keys_claim_request_body
* one_time_keys · array<object> · $ref #/$defs/account_device_algorithm_entries
One claim target group per exact AccountId. Entries MUST be sorted by RFC 8785 JCS AccountId bytes with no duplicate account identity.
items · object
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* device_algorithms ·
object · $ref #/$defs/device_algorithm_maponeOf · oneOf[7] · object · $ref #/$defs/keys_claim_outcome
* one_time_keys · array<object> · $ref #/$defs/account_device_key_entries
One entry per exact AccountId. Entries MUST be sorted by unsigned UTF-8 bytes of RFC 8785 JCS(account_id); duplicate AccountIds MUST be rejected even when values differ.
items · object
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* device_keys ·
object · $ref #/$defs/device_key_recordsfailures · array<$ref #/$defs/failure>
items · object · $ref #/$defs/failure
account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_iddevice_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$algorithm ·
string · $ref #/$defs/non_empty_string* reason_code ·
string · $ref #/$defs/non_empty_stringretry_after_ms ·
integeroneOf · oneOf[8] · object · $ref #/$defs/keys_backups_replace_outcome
* status ·
string (enum)enum:
"accepted" "duplicate"* backup_id ·
string · $ref #/$defs/backup_idpattern:
^ak:backup:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* ciphertext_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$oneOf · oneOf[9] · object · $ref #/$defs/keys_backups_list
Bounded Account Station metadata page with the current accepted secret_storage backup-class pointer, independent of list filters. key-management.md section 7.6.1 fixes cursor and unknown-state semantics.
* backups · array<$ref #/$defs/backup_metadata>
items · object · $ref #/$defs/backup_metadata
* backup_id ·
string · $ref #/$defs/backup_idpattern:
^ak:backup:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_iddevice_id ·
string · $ref #/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* backup_kind ·
string (enum) · $ref #/$defs/backup_kindenum:
"secret_storage"* backup_version ·
string · $ref #/$defs/non_empty_string* series_id ·
string · $ref #/$defs/backup_series_idpattern:
^ak:backup_series:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* series_seq ·
integersupersedes_id · oneOf[2]
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
string · $ref #/$defs/backup_idpattern:
^ak:backup:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$supersedes_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$expires_at · oneOf[2]
oneOf · oneOf[0] ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[1] ·
null* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$updated_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* ciphertext_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* encryption · object
Non-secret recipient metadata so the client can categorize a backup (recovery_public_key vs passphrase_kdf vs secret_storage_key) without downloading the ciphertext. The aead/kdf material is withheld from the list summary.
* recipient_method ·
string (enum)enum:
"passphrase_kdf" "recovery_public_key" "secret_storage_key"recipient_key_ref ·
stringretention ·
object* active_series · object · $ref #/$defs/backup_active_series_state
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* authority_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* secret_storage · oneOf[2] · $ref #/$defs/backup_active_series_pointer
oneOf · oneOf[0] · object
* state ·
const "absent"enum:
"absent"oneOf · oneOf[1] · object
* state ·
const "active"enum:
"active"* active_series_id ·
string · $ref #/$defs/backup_series_idpattern:
^ak:backup_series:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* series_pointer_version ·
integernext_cursor ·
string · $ref #/$defs/cursorpattern:
^ak:cursor:[A-Za-z0-9_-]+$* has_more ·
booleanoneOf · oneOf[10] · object · $ref #/$defs/keys_backups_issue_delete_challenge_request_body
Request body for ak.self.keys.backups.command.issue_delete_challenge.v1. While an issued challenge for the same (account_id, backup_id, request_id) is still valid, the service MUST return the same challenge; a different request_id mints a new challenge.
* request_id ·
string · $ref #/$defs/request_idpattern:
^[A-Za-z0-9_-]+$oneOf · oneOf[11] · object · $ref #/$defs/keys_backups_delete_challenge
Server-issued, durable, single-use delete challenge (TTL <= 300s). Every field is materialized by the service; the client echoes challenge_id in the DELETE body and every proof signs the canonical delete-intent transcript of key-management.md section 7.8.1, which embeds these exact values. Replay, expiry, path mismatch, or audience/service mismatch MUST fail closed.
* challenge_id ·
string · $ref #/$defs/base64urlServer-issued unique id of this challenge; echoed verbatim in the DELETE request body.
pattern:
^[A-Za-z0-9_-]+$* challenge ·
string · $ref #/$defs/base64urlServer-issued CSPRNG challenge bytes (base64url, no padding).
pattern:
^[A-Za-z0-9_-]+$* nonce ·
string · $ref #/$defs/base64urlServer-issued CSPRNG nonce bytes (base64url, no padding); distinct from challenge so the transcript binds two independent freshness values.
pattern:
^[A-Za-z0-9_-]+$* operation ·
const "ak.self.keys.backups.resource.delete.v1"enum:
"ak.self.keys.backups.resource.delete.v1"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* backup_id ·
string · $ref #/$defs/backup_idpattern:
^ak:backup:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* audience ·
string · $ref #/$defs/non_empty_stringThe service base origin this challenge is valid against; MUST match the origin the DELETE request is sent to.
* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* request_id ·
string · $ref #/$defs/request_idEcho of the issuance request_id this challenge was minted for.
pattern:
^[A-Za-z0-9_-]+$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[12] · object · $ref #/$defs/keys_backups_delete_request_body
Request body for ak.self.keys.backups.resource.delete.v1. The service verifies the referenced challenge against the current caller/path/service, verifies the high-risk proof over the canonical delete-intent transcript, and consumes the challenge in the same transaction as the successful delete. A byte-identical network retry returns the stored terminal outcome without re-admitting the consumed challenge; the same request_id with a different canonical digest is a duplicate conflict.
* request_id ·
string · $ref #/$defs/request_idpattern:
^[A-Za-z0-9_-]+$* challenge_id ·
string · $ref #/$defs/base64urlExact echo of the server-issued challenge_id being consumed.
pattern:
^[A-Za-z0-9_-]+$* proof · oneOf[3] · $ref #/$defs/keys_backups_delete_proof
Shared authority proof family for service operations that key-management.md designates as high-risk material destruction or equivalent (first consumer: active-series key backup tail deletion, key-management.md section 7.8). Exactly one closed branch: recovery_unlock, device_quorum, or trusted_recovery_service, discriminated by `kind`. Every branch reuses the common detached-JWS leaf (event-envelope.schema.json#/$defs/proof) over the operation's single canonical delete-intent transcript; branches never restate the leaf fields. An ordinary current-device session proof is deliberately NOT a branch of this family — operations that accept it for low-risk paths must say so in their own normative text. This is one wire leaf with per-consumer domain separation: the transcript context is owned by the consuming operation, never by the leaf, so x-arkret-proof-contexts below enumerates every registered consumer context and proof-context-registry.json carries the matching consumer_operation on each row.
oneOf · oneOf[0] ·
$ref #/$defs/recovery_unlock_proof · $ref #/$defs/recovery_unlock_proofoneOf · oneOf[1] ·
$ref #/$defs/device_quorum_proof · $ref #/$defs/device_quorum_proofoneOf · oneOf[2] ·
$ref #/$defs/trusted_recovery_service_proof · $ref #/$defs/trusted_recovery_service_proofreason ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/audit_reason_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$oneOf · oneOf[13] · object · $ref #/$defs/keys_backups_issue_unlock_challenge_request_body
Request body for ak.self.keys.backups.command.issue_unlock_challenge.v1. While an issued challenge for the same (account_id, backup_id, request_id) is still valid, the service MUST return the same challenge; a different request_id mints a new challenge.
* request_id ·
string · $ref #/$defs/request_idpattern:
^[A-Za-z0-9_-]+$oneOf · oneOf[14] · object · $ref #/$defs/keys_backups_unlock_challenge
Shared-durable single-use current-device unlock challenge, TTL <= 300 seconds, scoped to authenticated account/device, exact backup/series/ciphertext, origin and service. All values are server materialized. Recovery-session unlock reuses its session challenge and MUST NOT call this operation.
* challenge_id ·
string · $ref #/$defs/base64urlServer-issued single-use challenge identifier.
pattern:
^[A-Za-z0-9_-]+$* challenge ·
string · $ref #/$defs/base64urlServer-issued CSPRNG challenge bytes (base64url, no padding).
pattern:
^[A-Za-z0-9_-]+$* nonce ·
string · $ref #/$defs/base64urlServer-issued CSPRNG nonce bytes (base64url, no padding); distinct from challenge so the transcript binds two independent freshness values.
pattern:
^[A-Za-z0-9_-]+$* operation ·
const "ak.self.keys.backups.command.unlock.v1"enum:
"ak.self.keys.backups.command.unlock.v1"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* backup_id ·
string · $ref #/$defs/backup_idpattern:
^ak:backup:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* audience ·
string · $ref #/$defs/non_empty_stringExact authenticated unlock service origin.
* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* request_id ·
string · $ref #/$defs/request_idEcho of the issuance request_id this challenge was minted for.
pattern:
^[A-Za-z0-9_-]+$* issued_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* requesting_device_id ·
string · $ref ./account-operations.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* series_id ·
string · $ref ./agent-operations.schema.json#/$defs/backup_series_idpattern:
^ak:backup_series:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* ciphertext_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/keys-operations.schema.json