ak.schema.mimi_interop.v1
ak.schema.mimi_interop.v1 · file: schemas/mimi-interop.schema.json Provider directory, room binding, and content mapping receipt objects for ak.profile.mimi_interop.v1.
* $ · anyOf[3]
Provider directory, room binding, and content mapping receipt objects for ak.profile.mimi_interop.v1.
anyOf · anyOf[0] · object · $ref #/$defs/provider_directory
* schema ·
const "ak.schema.mimi_interop.v1"enum:
"ak.schema.mimi_interop.v1"* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* service_kind ·
const "mimi_provider_facade"enum:
"mimi_provider_facade"* supported_profiles · array<string>
Sorted unique by UTF-8 byte order; the sorted array is what enters the signed projection.
items ·
string* mimi · object
* protocol_draft ·
const "draft-ietf-mimi-protocol-06"enum:
"draft-ietf-mimi-protocol-06"* content_draft ·
const "draft-ietf-mimi-content-08"enum:
"draft-ietf-mimi-content-08"* room_policy_draft ·
const "draft-ietf-mimi-room-policy-03"enum:
"draft-ietf-mimi-room-policy-03"* identifier_draft ·
const "draft-kohbrok-mimi-identifiers-01"enum:
"draft-kohbrok-mimi-identifiers-01"* base_url ·
string (uri) · format=uripattern:
^https://* provider_id ·
string · $ref #/$defs/mimi_uripattern:
^mimi://[^\s]+$* endpoints · array<$ref #/$defs/provider_directory_endpoint>
Sorted by endpoint_id; endpoint_id unique across rows. Effective URLs derive only via a standard URL parser under the verified HTTPS base_url with same-origin re-check and the section 3 SSRF policy (extensions/mimi-interop.md section 3.1).
items · object · $ref #/$defs/provider_directory_endpoint
* endpoint_id ·
string (enum)The feature this endpoint serves; the id set is the same closed feature enum, and each endpoint_id appears at most once.
enum:
"key_material" "room_update" "notify" "submit_message" "consent" "identifier_query" "report_abuse" "proxy_download"* relative_path ·
stringNormalized relative path: begins with '/', no scheme, authority, query, fragment, whitespace or backslash. Receivers MUST additionally reject '.' / '..' dot segments and percent-encoded '/', '\', '.' or '..' after decoding (extensions/mimi-interop.md section 3.1).
pattern:
^/[^\s?#\\]*$* features · array<string (enum)>
items ·
string (enum)enum:
"key_material" "room_update" "notify" "submit_message" "consent" "identifier_query" "report_abuse" "proxy_download"* mls_cipher_suites · array<string (enum)>
Generated from active canonical_id rows in mls-ciphersuite-registry.json.
items ·
string (enum)enum:
"MLS_128_DHKEMX25519_AES128GCM_SHA256_Ed25519"* content_profiles · array<string (enum)>
items ·
string (enum)enum:
"application/mimi-content" "text/plain;charset=utf-8" "text/markdown;variant=GFM-MIMI" "application/vnd.arkret.content+json"* room_policy_components · array<string>
items ·
string* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind ·
string (enum)Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum:
"detached_jws"* verification_method ·
stringDID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* payload_digest ·
string · $ref #/$defs/digestGeneric non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern:
^(sha256:)?[A-Za-z0-9_+\-/=:.]{32,}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$domain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
stringproof_purpose ·
string (enum)Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum:
"issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$anyOf · anyOf[1] · object · $ref #/$defs/room_binding
MIMI room binding effect payload. In authority-commit/authority-ordered projection state, the typed current result subject is payload.mimi_room_uri for mimi_room_binding.
schema ·
const "ak.schema.mimi_interop.v1"enum:
"ak.schema.mimi_interop.v1"* kind ·
const "ak.mimi.room_binding"enum:
"ak.mimi.room_binding"* payload · object
* profile ·
const "ak.profile.mimi_interop.v1"enum:
"ak.profile.mimi_interop.v1"* mimi_room_uri ·
string · $ref #/$defs/mimi_room_uriCanonical MIMI room URI. It is the mimi_room_binding typed current result subject source, so it is a closed canonical form rather than a free URI: lowercase mimi:// scheme, host[:port] authority with no userinfo, lowercase A-label host, no leading-zero port, at least one non-empty path segment, no dot or dot-dot segment, no trailing slash, no query, no fragment, uppercase percent escapes, and no percent-encoding of unreserved octets (RFC 3986 section 6.2.2.2). A receiver MUST reject a non-canonical value with schema_violation and MUST NOT normalize it first, because two spellings of one room would otherwise each own a first accepted binding and the revoked terminal state could be bypassed by respelling. typed current result subject encoding is the uri subject kind of zh/conformance/encoding.md section 4. The pattern below expresses the structural half of the canonical form; two rules it cannot express portably -- the default port 443 MUST NOT be written explicitly, and a percent escape MUST NOT encode an unreserved octet -- are normative all the same and are closed by ak.vector.encoding.result_selector_uri.v1 plus the SDK typed validator, which every producer and receiver MUST apply in addition to this pattern. See zh/extensions/mimi-interop.md section 4.
pattern:
^mimi://[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)*(?::(?:[1-9][0-9]{0,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?(?:/(?:[A-Za-z0-9\-._~!$&'()*+,;=:@]|%[0-9A-F]{2})+)+$* binding_scope · object
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* strand_id ·
stringpattern:
^ak:strand:[A-Za-z0-9_-]{44}$* hub_provider_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$follower_provider_ids · array<$ref #/$defs/did_core_id>
items ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* local_provider_role ·
string (enum)enum:
"hub" "follower" "observer"mls_group_id ·
string · $ref ./common-ids.schema.json#/$defs/mls_group_idRFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern:
^[A-Za-z0-9_-]{43}$content_profile ·
string (enum)enum:
"application/mimi-content" "text/plain;charset=utf-8" "text/markdown;variant=GFM-MIMI" "application/vnd.arkret.content+json"policy_revision ·
integer* status ·
string (enum)Room binding lifecycle status. Initial status MUST be proposed or accepted; legal transitions are proposed->accepted, proposed->revoked, accepted->migrating, accepted->revoked, migrating->accepted (verified migration proof), migrating->revoked. revoked is the only terminal state; illegal transitions are rejected with mimi_room_binding_status_transition_invalid. Normative state machine: zh/extensions/mimi-interop.md §4.2.
enum:
"proposed" "accepted" "revoked" "migrating"migration_outcome ·
string (enum)Outcome of a migrating->accepted transition: completed (candidate topology in effect) or rolled_back (previous accepted topology restored). MUST be paired with migration_proof and absent on other transitions. Normative: zh/extensions/mimi-interop.md §4.2.
enum:
"completed" "rolled_back"migration_proof · object · $ref ./event-payload.schema.json#/$defs/mimi_room_binding_migration_proof
Commit-backed lineage proof for a migrating->accepted room-binding Event. Each Event ID MUST name an accepted ak.mimi.room_binding Event and each Commit ID MUST be its covering RealmCommit in the same Realm. Admission verifies that the migrating pair is the current typed-result source and the previous_accepted pair was the immediately preceding accepted binding state; see zh/extensions/mimi-interop.md §4.2.
* previous_accepted_event_id ·
$ref #/$defs/event_ref · $ref #/$defs/event_ref* previous_accepted_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* migrating_event_id ·
$ref #/$defs/event_ref · $ref #/$defs/event_ref* migrating_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$anyOf · anyOf[2] · object · $ref #/$defs/content_mapping_receipt
schema ·
const "ak.schema.mimi_interop.v1"enum:
"ak.schema.mimi_interop.v1"* receipt_kind ·
const "content_mapping_receipt"Interop-audit object discriminator. This object is not an Event Envelope and this value is not an event kind.
enum:
"content_mapping_receipt"* profile ·
const "ak.profile.mimi_interop.v1"enum:
"ak.profile.mimi_interop.v1"* mimi_room_uri ·
string · $ref #/$defs/mimi_room_uriCanonical MIMI room URI. It is the mimi_room_binding typed current result subject source, so it is a closed canonical form rather than a free URI: lowercase mimi:// scheme, host[:port] authority with no userinfo, lowercase A-label host, no leading-zero port, at least one non-empty path segment, no dot or dot-dot segment, no trailing slash, no query, no fragment, uppercase percent escapes, and no percent-encoding of unreserved octets (RFC 3986 section 6.2.2.2). A receiver MUST reject a non-canonical value with schema_violation and MUST NOT normalize it first, because two spellings of one room would otherwise each own a first accepted binding and the revoked terminal state could be bypassed by respelling. typed current result subject encoding is the uri subject kind of zh/conformance/encoding.md section 4. The pattern below expresses the structural half of the canonical form; two rules it cannot express portably -- the default port 443 MUST NOT be written explicitly, and a percent escape MUST NOT encode an unreserved octet -- are normative all the same and are closed by ak.vector.encoding.result_selector_uri.v1 plus the SDK typed validator, which every producer and receiver MUST apply in addition to this pattern. See zh/extensions/mimi-interop.md section 4.
pattern:
^mimi://[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)*(?::(?:[1-9][0-9]{0,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?(?:/(?:[A-Za-z0-9\-._~!$&'()*+,;=:@]|%[0-9A-F]{2})+)+$* source_format ·
string (enum)enum:
"application/mimi-content" "text/plain;charset=utf-8" "text/markdown;variant=GFM-MIMI" "application/vnd.arkret.content+json"* target_format ·
string (enum)enum:
"ak.message.create" "ak.message.revise" "ak.message.redact" "ak.reaction.add" "ak.reaction.remove" "ak.relation.create" "application/mimi-content" "application/vnd.arkret.content+json"* original_envelope_digest ·
string · $ref #/$defs/digestpattern:
^(sha256:)?[A-Za-z0-9_+\-/=:.]{32,}$* mapped_operation_id ·
stringpattern:
^(?!ak:)mimi_message_id ·
stringpattern:
^(?!ak:)arkret_event_id ·
stringpattern:
^ak:event:[A-Za-z0-9_-]{44}$accepted_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/mimi-interop.schema.json