跳转到内容

ak.schema.message.v1

← Schemas

Arkret Message
ak.schema.message.v1 · file: schemas/message.schema.json
* $ · object
oneOf · oneOf[0] · oneOf[2]
oneOf · oneOf[0] · ?
oneOf · oneOf[1] · ?
state · const "active"
enum: "active"
oneOf · oneOf[1] · object
state · const "redacted"
enum: "redacted"
* id · string
For ak.message.create, the reducer derives this value by retyping the creating Event.event_id's full 33-byte / 44-character token from ak:event: to ak:message:. It is not independently producer-chosen.
pattern: ^ak:message:[A-Za-z0-9_-]{44}$
* schema · const "ak.schema.message.v1"
enum: "ak.schema.message.v1"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* strand_id · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
effective_scope · oneOf[2] · $ref #/$defs/effective_scope
Read-only immutable effective scope of this Message, materialized from the accepted Event.scope_ref after the receiver verifies it against the Strand's frozen pre-state (models/circle.md §6.1-§6.2). kind='realm' for Realm-default scope; kind='circle' when the Message's Strand was Circle-scoped at write time. A later Strand scope rebind MUST NOT reinterpret already-written Messages. This field MUST NOT appear in actor-supplied content payload (reason=effective_scope_reducer_managed).
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
content · object · $ref #/$defs/content_block
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
* kind · string · $ref #/$defs/content_kind
pattern: ^(ak\.content\.[a-z0-9_]+(?:\.[a-z0-9_]+)*|[a-z0-9][a-z0-9_.-]*\.[a-z0-9][a-z0-9_.-]*)$
* body · string
format · string (enum)
enum: "plain" "markdown" "prosemirror_json"
formatted_body · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · object
parts · array<$ref #/$defs/content_block>
items · object · $ref #/$defs/content_block
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
* kind · string · $ref #/$defs/content_kind
pattern: ^(ak\.content\.[a-z0-9_]+(?:\.[a-z0-9_]+)*|[a-z0-9][a-z0-9_.-]*\.[a-z0-9][a-z0-9_.-]*)$
* body · string
format · string (enum)
enum: "plain" "markdown" "prosemirror_json"
formatted_body · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · object
parts · array<$ref #/$defs/content_block>
items · object · $ref #/$defs/content_block
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
* kind · string · $ref #/$defs/content_kind
pattern: ^(ak\.content\.[a-z0-9_]+(?:\.[a-z0-9_]+)*|[a-z0-9][a-z0-9_.-]*\.[a-z0-9][a-z0-9_.-]*)$
* body · string
format · string (enum)
enum: "plain" "markdown" "prosemirror_json"
formatted_body · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · object
parts · array<$ref #/$defs/content_block>
items · object · $ref #/$defs/content_block
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
* kind · string · $ref #/$defs/content_kind
pattern: ^(ak\.content\.[a-z0-9_]+(?:\.[a-z0-9_]+)*|[a-z0-9][a-z0-9_.-]*\.[a-z0-9][a-z0-9_.-]*)$
* body · string
format · string (enum)
enum: "plain" "markdown" "prosemirror_json"
formatted_body · oneOf[2]
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
parts · array<$ref #/$defs/content_block>
items · …
recursion truncated at depth 8; see source schema for full shape
mentions · array<$ref #/$defs/mention_node>
Structured direct mention AST nodes for this Content Block. This is the only carrier of a direct mention: authorization, notification routing and audit attribution read mention_node.subject_account_id exclusively, and compare it as a complete AccountId (zh/models/strand-and-message.md §9.4.1-§9.4.2).
items · …
recursion truncated at depth 8; see source schema for full shape
audience_mentions · array<$ref #/$defs/audience_mention_node>
Structured broadcast mention AST nodes for this Content Block (zh/models/strand-and-message.md §9.4.3).
items · …
recursion truncated at depth 8; see source schema for full shape
attachments · array<object>
Profile-defined attachment hints. At most 32; canonical durable attachment relations SHOULD use Relation attached_to.
items · …
recursion truncated at depth 8; see source schema for full shape
reply_context · object
message_ref · …
recursion truncated at depth 8; see source schema for full shape
sender_actor_id · …
recursion truncated at depth 8; see source schema for full shape
excerpt · …
recursion truncated at depth 8; see source schema for full shape
mentions · array<$ref #/$defs/mention_node>
Structured direct mention AST nodes for this Content Block. This is the only carrier of a direct mention: authorization, notification routing and audit attribution read mention_node.subject_account_id exclusively, and compare it as a complete AccountId (zh/models/strand-and-message.md §9.4.1-§9.4.2).
items · object · $ref #/$defs/mention_node
Readable holder/slug or me/slug labels are UI candidate input only: explicit selection binds the complete AccountId and a visible draft token range. Draft routing and ranges are local state, never additional wire fields. Private controller petnames must not enter shared body or metadata; mention_text_original and handle/slug snapshots do not supply current renderer labels.
* kind · const "mention"
enum: "mention"
* subject_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · …
recursion truncated at depth 8; see source schema for full shape
* station_id · …
recursion truncated at depth 8; see source schema for full shape
display_name_at_time · string
handle_at_time · string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref string-profiles.schema.json#/$defs/canonical_handle
Canonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern: ^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$
controller_subject_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · …
recursion truncated at depth 8; see source schema for full shape
* station_id · …
recursion truncated at depth 8; see source schema for full shape
controller_handle_at_time · string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref string-profiles.schema.json#/$defs/canonical_handle
Canonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern: ^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$
agent_slug_at_time · $ref #/$defs/agent_slug · $ref #/$defs/agent_slug
mention_text_original · string
resolved_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
audience_mentions · array<$ref #/$defs/audience_mention_node>
Structured broadcast mention AST nodes for this Content Block (zh/models/strand-and-message.md §9.4.3).
items · object · $ref #/$defs/audience_mention_node
Broadcast mention AST node carried in a Content Block `audience_mentions[]`. It is never expanded into `mention_node` entries in shared history; recipient expansion happens receiver-side under the ak.message.mention.broadcast, audience policy, max_recipients and quota gates in zh/models/strand-and-message.md §9.4.3-§9.4.4.
* kind · const "audience_mention"
enum: "audience_mention"
* audience · string (enum)
Canonical audience selector. @here maps to strand_engaged and is never presence-filtered; presence-filtered audiences require a separate declared profile.
enum: "effective_scope_members" "strand_participants" "strand_watchers" "strand_engaged" "assigned_actors"
mention_text_original · string
resolved_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
attachments · array<object>
Profile-defined attachment hints. At most 32; canonical durable attachment relations SHOULD use Relation attached_to.
items · object
reply_context · object
message_ref · string
pattern: ^ak:(message|event):[A-Za-z0-9_-]{44}$
sender_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
excerpt · string
mentions · array<$ref #/$defs/mention_node>
Structured direct mention AST nodes for this Content Block. This is the only carrier of a direct mention: authorization, notification routing and audit attribution read mention_node.subject_account_id exclusively, and compare it as a complete AccountId (zh/models/strand-and-message.md §9.4.1-§9.4.2).
items · object · $ref #/$defs/mention_node
Readable holder/slug or me/slug labels are UI candidate input only: explicit selection binds the complete AccountId and a visible draft token range. Draft routing and ranges are local state, never additional wire fields. Private controller petnames must not enter shared body or metadata; mention_text_original and handle/slug snapshots do not supply current renderer labels.
* kind · const "mention"
enum: "mention"
* subject_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
display_name_at_time · string
handle_at_time · string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref string-profiles.schema.json#/$defs/canonical_handle
Canonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern: ^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$
controller_subject_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
controller_handle_at_time · string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref string-profiles.schema.json#/$defs/canonical_handle
Canonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern: ^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$
agent_slug_at_time · $ref #/$defs/agent_slug · $ref #/$defs/agent_slug
mention_text_original · string
resolved_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
audience_mentions · array<$ref #/$defs/audience_mention_node>
Structured broadcast mention AST nodes for this Content Block (zh/models/strand-and-message.md §9.4.3).
items · object · $ref #/$defs/audience_mention_node
Broadcast mention AST node carried in a Content Block `audience_mentions[]`. It is never expanded into `mention_node` entries in shared history; recipient expansion happens receiver-side under the ak.message.mention.broadcast, audience policy, max_recipients and quota gates in zh/models/strand-and-message.md §9.4.3-§9.4.4.
* kind · const "audience_mention"
enum: "audience_mention"
* audience · string (enum)
Canonical audience selector. @here maps to strand_engaged and is never presence-filtered; presence-filtered audiences require a separate declared profile.
enum: "effective_scope_members" "strand_participants" "strand_watchers" "strand_engaged" "assigned_actors"
mention_text_original · string
resolved_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
attachments · array<object>
Profile-defined attachment hints. At most 32; canonical durable attachment relations SHOULD use Relation attached_to.
items · object
reply_context · object
message_ref · string
pattern: ^ak:(message|event):[A-Za-z0-9_-]{44}$
sender_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
excerpt · string
mentions · array<$ref #/$defs/mention_node>
Structured direct mention AST nodes for this Content Block. This is the only carrier of a direct mention: authorization, notification routing and audit attribution read mention_node.subject_account_id exclusively, and compare it as a complete AccountId (zh/models/strand-and-message.md §9.4.1-§9.4.2).
items · object · $ref #/$defs/mention_node
Readable holder/slug or me/slug labels are UI candidate input only: explicit selection binds the complete AccountId and a visible draft token range. Draft routing and ranges are local state, never additional wire fields. Private controller petnames must not enter shared body or metadata; mention_text_original and handle/slug snapshots do not supply current renderer labels.
* kind · const "mention"
enum: "mention"
* subject_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
display_name_at_time · string
handle_at_time · string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref string-profiles.schema.json#/$defs/canonical_handle
Canonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern: ^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$
controller_subject_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
controller_handle_at_time · string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref string-profiles.schema.json#/$defs/canonical_handle
Canonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern: ^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$
agent_slug_at_time · $ref #/$defs/agent_slug · $ref #/$defs/agent_slug
mention_text_original · string
resolved_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
audience_mentions · array<$ref #/$defs/audience_mention_node>
Structured broadcast mention AST nodes for this Content Block (zh/models/strand-and-message.md §9.4.3).
items · object · $ref #/$defs/audience_mention_node
Broadcast mention AST node carried in a Content Block `audience_mentions[]`. It is never expanded into `mention_node` entries in shared history; recipient expansion happens receiver-side under the ak.message.mention.broadcast, audience policy, max_recipients and quota gates in zh/models/strand-and-message.md §9.4.3-§9.4.4.
* kind · const "audience_mention"
enum: "audience_mention"
* audience · string (enum)
Canonical audience selector. @here maps to strand_engaged and is never presence-filtered; presence-filtered audiences require a separate declared profile.
enum: "effective_scope_members" "strand_participants" "strand_watchers" "strand_engaged" "assigned_actors"
mention_text_original · string
resolved_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
attachments · array<object>
Profile-defined attachment hints. At most 32; canonical durable attachment relations SHOULD use Relation attached_to.
items · object
reply_context · object
message_ref · string
pattern: ^ak:(message|event):[A-Za-z0-9_-]{44}$
sender_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
excerpt · string
encrypted_content · allOf[2]
Encrypted envelope whose plaintext is the Message ContentBlock.
allOf · allOf[0] · object · $ref ./encrypted-envelope.schema.json
Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.
* version · const "1.0"
enum: "1.0"
* content_type · string
pattern: ^[a-z0-9.+-]+/[a-z0-9.+-]+$
* encryption_context · $ref #/$defs/encryption_context · $ref #/$defs/encryption_context
* ciphertext · string
pattern: ^[A-Za-z0-9_-]+$
allOf · allOf[1] · object
content_type · const "application/vnd.arkret.message+json"
enum: "application/vnd.arkret.message+json"
metadata · object · $ref #/$defs/message_metadata
Extensible user-readable Message metadata. In MLS / E2EE realms this object is encrypted as encrypted_metadata unless the Realm explicitly opts into plaintext metadata.
fields · object · $ref #/$defs/metadata_fields
Profile-defined Message metadata fields. Reducer-owned lifecycle and revision fields are forbidden here to avoid dual sources of truth.
sidecar_exchange_binding · object · $ref ./agent-sidecar-event-exchange-binding.schema.json
Closed typed binding that ties one native-Sidecar-scoped Message event to one source-routed exchange. It is legal only inside encrypted metadata plaintext of an event whose scope_ref.kind is sidecar. It is the only normative way to declare an explicit user-facing response; invalid or absent bindings are non-echo. See zh/models/sidecar.md.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · ?
* schema · const "ak.schema.agent_sidecar_event_exchange_binding.v1"
enum: "ak.schema.agent_sidecar_event_exchange_binding.v1"
* exchange_id · string
Opaque controller-private idempotency identity copied verbatim from the request binding. It is not a Sidecar locator and MUST NOT appear in shared events, plaintext metadata, publish output, push previews, notifications, public telemetry, account-data keys, or any public/shared surface.
pattern: ^[A-Za-z0-9._~=-]{22,128}$
* role · string (enum)
Closed disposition. request: the controller's private request event itself. user_facing_response: an Agent response the controller MAY echo after validation. internal: exchange-scoped Agent collaboration/tool output that MUST NOT be echoed. Consumers MUST fail closed to non-echo on any value not listed here.
enum: "request" "user_facing_response" "internal"
request_event_id · string
Accepted Event id of the private request event of the same exchange. Event id is the only canonical reference form; Message ids MUST NOT be used here.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
completes_exchange · const true
Optional coordinator completion request; legal only with role=user_facing_response. It does not itself make the exchange terminal. A controller device validates the actor against coordinator_assignment_event_id and, on success, authors a durable ak.agent.sidecar.exchange.control Event with action=close.
enum: true
coordinator_assignment_event_id · string
Request Event id for the initial coordinator assignment, or the accepted reassign_coordinator control Event id. Required only when completes_exchange=true.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
request_context · $ref #/$defs/request_context · $ref #/$defs/request_context
encrypted_metadata · allOf[2]
Encrypted envelope whose plaintext is a message_metadata object.
allOf · allOf[0] · object · $ref ./encrypted-envelope.schema.json
Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.
* version · const "1.0"
enum: "1.0"
* content_type · string
pattern: ^[a-z0-9.+-]+/[a-z0-9.+-]+$
* encryption_context · $ref #/$defs/encryption_context · $ref #/$defs/encryption_context
* ciphertext · string
pattern: ^[A-Za-z0-9_-]+$
allOf · allOf[1] · object
content_type · const "application/vnd.arkret.message-metadata+json"
enum: "application/vnd.arkret.message-metadata+json"
* state · string (enum)
Top-level lifecycle state for messages. Messages do not have a separate deleted/tombstone state; retention or moderation removal uses ak.message.redact and state=redacted so the message slot and audit metadata remain stable.
enum: "active" "redacted"
state_changed_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
revision_root_id · string
First revision in this message's edit chain. The first revision MUST have revision_root == id. Maintained by ak.message.revise reducer.
pattern: ^ak:message:[A-Za-z0-9_-]{44}$
edited_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
redaction_ref · string
Required when state=redacted; references the accepted ak.message.redact Event id that produced this state. A cross-object ak.redaction can never be the source: its payload class excludes Message targets, so this reference is single-valued and unambiguous (models/common-fields.md 5.1 Message exemption). MUST be absent for other states.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* created_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* created_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
updated_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
(^x_[a-z][a-z0-9_]{0,63}$) · any

Source