跳转到内容

ak.schema.mimi_interop.v1

← Schemas

Arkret MIMI Interoperability
ak.schema.mimi_interop.v1 · file: schemas/mimi-interop.schema.json

Provider directory, room binding, and content mapping receipt objects for ak.profile.mimi_interop.v1.

* $ · anyOf[3]
Provider directory, room binding, and content mapping receipt objects for ak.profile.mimi_interop.v1.
anyOf · anyOf[0] · object · $ref #/$defs/provider_directory
* schema · const "ak.schema.mimi_interop.v1"
enum: "ak.schema.mimi_interop.v1"
* service_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* service_kind · const "mimi_provider_facade"
enum: "mimi_provider_facade"
* supported_profiles · array<string>
Sorted unique by UTF-8 byte order; the sorted array is what enters the signed projection.
items · string
* mimi · object
* protocol_draft · const "draft-ietf-mimi-protocol-06"
enum: "draft-ietf-mimi-protocol-06"
* content_draft · const "draft-ietf-mimi-content-08"
enum: "draft-ietf-mimi-content-08"
* room_policy_draft · const "draft-ietf-mimi-room-policy-03"
enum: "draft-ietf-mimi-room-policy-03"
* identifier_draft · const "draft-kohbrok-mimi-identifiers-01"
enum: "draft-kohbrok-mimi-identifiers-01"
* base_url · string (uri) · format=uri
pattern: ^https://
* provider_id · string · $ref #/$defs/mimi_uri
pattern: ^mimi://[^\s]+$
* endpoints · array<$ref #/$defs/provider_directory_endpoint>
Sorted by endpoint_id; endpoint_id unique across rows. Effective URLs derive only via a standard URL parser under the verified HTTPS base_url with same-origin re-check and the section 3 SSRF policy (extensions/mimi-interop.md section 3.1).
items · object · $ref #/$defs/provider_directory_endpoint
* endpoint_id · string (enum)
The feature this endpoint serves; the id set is the same closed feature enum, and each endpoint_id appears at most once.
enum: "key_material" "room_update" "notify" "submit_message" "consent" "identifier_query" "report_abuse" "proxy_download"
* relative_path · string
Normalized relative path: begins with '/', no scheme, authority, query, fragment, whitespace or backslash. Receivers MUST additionally reject '.' / '..' dot segments and percent-encoded '/', '\', '.' or '..' after decoding (extensions/mimi-interop.md section 3.1).
pattern: ^/[^\s?#\\]*$
* features · array<string (enum)>
items · string (enum)
enum: "key_material" "room_update" "notify" "submit_message" "consent" "identifier_query" "report_abuse" "proxy_download"
* mls_cipher_suites · array<string (enum)>
Generated from active canonical_id rows in mls-ciphersuite-registry.json.
items · string (enum)
enum: "MLS_128_DHKEMX25519_AES128GCM_SHA256_Ed25519"
* content_profiles · array<string (enum)>
items · string (enum)
enum: "application/mimi-content" "text/plain;charset=utf-8" "text/markdown;variant=GFM-MIMI" "application/vnd.arkret.content+json"
* room_policy_components · array<string>
items · string
* proof · object · $ref ./event-envelope.schema.json#/$defs/proof
Generic detached-JWS proof shape reused by non-Event schemas (snapshot signature, snapshot witness attestations, identity receipts, handle claims, etc.). MUST NOT be used as the shape of Event Envelope `producer_proof` — Event proofs reference $defs/event_proof and bind canonical Event bytes via `event_digest`. Non-Event signed objects MUST define an object-family signing-context constant and include it in the canonical proof binding object with payload_digest; the context constant is not a wire field in this generic shape. drift detection: `payload_digest#event_proof` in forbidden-wire-fields.json is the hard-reject mirror of this rule. New non-Event signed objects MAY $ref this shape; new signed Event-shaped objects MUST instead $ref event_proof.
* kind · string (enum)
Generic detached JWS proof over a canonical non-Event payload binding object that includes an object-family context constant.
enum: "detached_jws"
* verification_method · string
DID URL of the signing key for this non-Event detached proof. Same pattern as $defs/event_proof.verification_method; semantics are decoupled from Event proof (see $defs/event_proof for the Event-only shape).
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* payload_digest · string · $ref #/$defs/digest
Generic non-Event detached-proof hash. This $defs/proof shape is reused by non-Event schemas; Event.properties.producer_proof references $defs/event_proof and MUST use event_digest instead.
pattern: ^(sha256:)?[A-Za-z0-9_+\-/=:.]{32,}$
* created_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
domain · string
audience · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · array<string>
items · string
proof_purpose · string (enum)
Optional role discriminator for non-Event proofs. HandleClaim core, status and revocation carriers make issuer_attestation, holder_acceptance, status_attestation and revocation_authorization load-bearing. governance_authorization marks a resource-governance-key authorization (directory withdraw/takedown-appeal, discovery-directory.md 8.7.1). Generic proof consumers ignore it unless their object-family contract makes it load-bearing.
enum: "issuer_attestation" "holder_acceptance" "status_attestation" "revocation_authorization" "governance_authorization"
* jws · string
pattern: ^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$
anyOf · anyOf[1] · object · $ref #/$defs/room_binding
MIMI room binding effect payload. In authority-commit/authority-ordered projection state, the typed current result subject is payload.mimi_room_uri for mimi_room_binding.
schema · const "ak.schema.mimi_interop.v1"
enum: "ak.schema.mimi_interop.v1"
* kind · const "ak.mimi.room_binding"
enum: "ak.mimi.room_binding"
* payload · object
* profile · const "ak.profile.mimi_interop.v1"
enum: "ak.profile.mimi_interop.v1"
* mimi_room_uri · string · $ref #/$defs/mimi_room_uri
Canonical MIMI room URI. It is the mimi_room_binding typed current result subject source, so it is a closed canonical form rather than a free URI: lowercase mimi:// scheme, host[:port] authority with no userinfo, lowercase A-label host, no leading-zero port, at least one non-empty path segment, no dot or dot-dot segment, no trailing slash, no query, no fragment, uppercase percent escapes, and no percent-encoding of unreserved octets (RFC 3986 section 6.2.2.2). A receiver MUST reject a non-canonical value with schema_violation and MUST NOT normalize it first, because two spellings of one room would otherwise each own a first accepted binding and the revoked terminal state could be bypassed by respelling. typed current result subject encoding is the uri subject kind of zh/conformance/encoding.md section 4. The pattern below expresses the structural half of the canonical form; two rules it cannot express portably -- the default port 443 MUST NOT be written explicitly, and a percent escape MUST NOT encode an unreserved octet -- are normative all the same and are closed by ak.vector.encoding.result_selector_uri.v1 plus the SDK typed validator, which every producer and receiver MUST apply in addition to this pattern. See zh/extensions/mimi-interop.md section 4.
pattern: ^mimi://[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)*(?::(?:[1-9][0-9]{0,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?(?:/(?:[A-Za-z0-9\-._~!$&'()*+,;=:@]|%[0-9A-F]{2})+)+$
* binding_scope · object
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* strand_id · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
* hub_provider_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
follower_provider_ids · array<$ref #/$defs/did_core_id>
items · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* local_provider_role · string (enum)
enum: "hub" "follower" "observer"
mls_group_id · string · $ref ./common-ids.schema.json#/$defs/mls_group_id
RFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern: ^[A-Za-z0-9_-]{43}$
content_profile · string (enum)
enum: "application/mimi-content" "text/plain;charset=utf-8" "text/markdown;variant=GFM-MIMI" "application/vnd.arkret.content+json"
policy_revision · integer
* status · string (enum)
Room binding lifecycle status. Initial status MUST be proposed or accepted; legal transitions are proposed->accepted, proposed->revoked, accepted->migrating, accepted->revoked, migrating->accepted (verified migration proof), migrating->revoked. revoked is the only terminal state; illegal transitions are rejected with mimi_room_binding_status_transition_invalid. Normative state machine: zh/extensions/mimi-interop.md §4.2.
enum: "proposed" "accepted" "revoked" "migrating"
migration_outcome · string (enum)
Outcome of a migrating->accepted transition: completed (candidate topology in effect) or rolled_back (previous accepted topology restored). MUST be paired with migration_proof and absent on other transitions. Normative: zh/extensions/mimi-interop.md §4.2.
enum: "completed" "rolled_back"
migration_proof · object · $ref ./event-payload.schema.json#/$defs/mimi_room_binding_migration_proof
Commit-backed lineage proof for a migrating->accepted room-binding Event. Each Event ID MUST name an accepted ak.mimi.room_binding Event and each Commit ID MUST be its covering RealmCommit in the same Realm. Admission verifies that the migrating pair is the current typed-result source and the previous_accepted pair was the immediately preceding accepted binding state; see zh/extensions/mimi-interop.md §4.2.
* previous_accepted_event_id · $ref #/$defs/event_ref · $ref #/$defs/event_ref
* previous_accepted_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* migrating_event_id · $ref #/$defs/event_ref · $ref #/$defs/event_ref
* migrating_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
anyOf · anyOf[2] · object · $ref #/$defs/content_mapping_receipt
schema · const "ak.schema.mimi_interop.v1"
enum: "ak.schema.mimi_interop.v1"
* receipt_kind · const "content_mapping_receipt"
Interop-audit object discriminator. This object is not an Event Envelope and this value is not an event kind.
enum: "content_mapping_receipt"
* profile · const "ak.profile.mimi_interop.v1"
enum: "ak.profile.mimi_interop.v1"
* mimi_room_uri · string · $ref #/$defs/mimi_room_uri
Canonical MIMI room URI. It is the mimi_room_binding typed current result subject source, so it is a closed canonical form rather than a free URI: lowercase mimi:// scheme, host[:port] authority with no userinfo, lowercase A-label host, no leading-zero port, at least one non-empty path segment, no dot or dot-dot segment, no trailing slash, no query, no fragment, uppercase percent escapes, and no percent-encoding of unreserved octets (RFC 3986 section 6.2.2.2). A receiver MUST reject a non-canonical value with schema_violation and MUST NOT normalize it first, because two spellings of one room would otherwise each own a first accepted binding and the revoked terminal state could be bypassed by respelling. typed current result subject encoding is the uri subject kind of zh/conformance/encoding.md section 4. The pattern below expresses the structural half of the canonical form; two rules it cannot express portably -- the default port 443 MUST NOT be written explicitly, and a percent escape MUST NOT encode an unreserved octet -- are normative all the same and are closed by ak.vector.encoding.result_selector_uri.v1 plus the SDK typed validator, which every producer and receiver MUST apply in addition to this pattern. See zh/extensions/mimi-interop.md section 4.
pattern: ^mimi://[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)*(?::(?:[1-9][0-9]{0,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?(?:/(?:[A-Za-z0-9\-._~!$&'()*+,;=:@]|%[0-9A-F]{2})+)+$
* source_format · string (enum)
enum: "application/mimi-content" "text/plain;charset=utf-8" "text/markdown;variant=GFM-MIMI" "application/vnd.arkret.content+json"
* target_format · string (enum)
enum: "ak.message.create" "ak.message.revise" "ak.message.redact" "ak.reaction.add" "ak.reaction.remove" "ak.relation.create" "application/mimi-content" "application/vnd.arkret.content+json"
* original_envelope_digest · string · $ref #/$defs/digest
pattern: ^(sha256:)?[A-Za-z0-9_+\-/=:.]{32,}$
* mapped_operation_id · string
pattern: ^(?!ak:)
mimi_message_id · string
pattern: ^(?!ak:)
arkret_event_id · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
accepted_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$

Source