ak.schema.morph.v1
ak.schema.morph.v1 · file: schemas/morph.schema.json * $ · object
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?id ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:morph:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.morph.v1"enum:
"ak.schema.morph.v1"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$scope_circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idOptional reference to an intra-Realm Circle that defines this Morph's effective scope. Omitted means Realm-default scope. The producer signs the corresponding Event.scope_ref; the receiver verifies scope_circle_id.realm_id == Morph.realm_id and exact equality between the derived scope and Event.scope_ref before materializing the object's immutable effective_scope.
pattern:
^ak:circle:[A-Za-z0-9_-]{44}$* schema_refs · array<string>
Authoritative structural schema set for Morph fields. Reducers MUST validate fields against exactly these refs; morph_kind and facets are not a replacement for schema_refs. Generic before-to-after transition validation is not provided by JSON Schema.
items ·
stringpattern:
^(ak\.schema\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v[0-9]+|[a-z0-9][a-z0-9_.-]*\.[a-z0-9][a-z0-9_.-]*[A-Za-z0-9_.:-]*)$* morph_kind ·
stringfacets ·
objectmetadata · object · $ref #/$defs/morph_metadata
Extensible user-readable Morph metadata. Morph business fields stay in the top-level fields object; metadata carries display-oriented fields such as title and summary. In MLS / E2EE realms this object is encrypted as encrypted_metadata unless the Realm explicitly opts into plaintext metadata.
title ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_512NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$summary ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/short_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$encrypted_metadata · object · $ref ./encrypted-envelope.schema.json
Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.
* version ·
const "1.0"enum:
"1.0"* content_type ·
stringpattern:
^[a-z0-9.+-]+/[a-z0-9.+-]+$* encryption_context ·
$ref #/$defs/encryption_context · $ref #/$defs/encryption_context* ciphertext ·
stringpattern:
^[A-Za-z0-9_-]+$content · object · $ref #/$defs/content_block
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* kind ·
string · $ref #/$defs/content_kindpattern:
^(ak\.content\.[a-z0-9_]+(?:\.[a-z0-9_]+)*|[a-z0-9][a-z0-9_.-]*\.[a-z0-9][a-z0-9_.-]*)$* body ·
stringformat ·
string (enum)enum:
"plain" "markdown" "prosemirror_json"formatted_body · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] ·
objectparts · array<$ref #/$defs/content_block>
items · object · $ref #/$defs/content_block
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* kind ·
string · $ref #/$defs/content_kindpattern:
^(ak\.content\.[a-z0-9_]+(?:\.[a-z0-9_]+)*|[a-z0-9][a-z0-9_.-]*\.[a-z0-9][a-z0-9_.-]*)$* body ·
stringformat ·
string (enum)enum:
"plain" "markdown" "prosemirror_json"formatted_body · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] ·
objectparts · array<$ref #/$defs/content_block>
items · object · $ref #/$defs/content_block
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* kind ·
string · $ref #/$defs/content_kindpattern:
^(ak\.content\.[a-z0-9_]+(?:\.[a-z0-9_]+)*|[a-z0-9][a-z0-9_.-]*\.[a-z0-9][a-z0-9_.-]*)$* body ·
stringformat ·
string (enum)enum:
"plain" "markdown" "prosemirror_json"formatted_body · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] ·
objectparts · array<$ref #/$defs/content_block>
items · object · $ref #/$defs/content_block
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* kind ·
string · $ref #/$defs/content_kindpattern:
^(ak\.content\.[a-z0-9_]+(?:\.[a-z0-9_]+)*|[a-z0-9][a-z0-9_.-]*\.[a-z0-9][a-z0-9_.-]*)$* body ·
stringformat ·
string (enum)enum:
"plain" "markdown" "prosemirror_json"formatted_body · oneOf[2]
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
parts · array<$ref #/$defs/content_block>
items ·
…recursion truncated at depth 8; see source schema for full shape
encrypted_content · object · $ref ./encrypted-envelope.schema.json
Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.
* version ·
const "1.0"enum:
"1.0"* content_type ·
stringpattern:
^[a-z0-9.+-]+/[a-z0-9.+-]+$* encryption_context ·
$ref #/$defs/encryption_context · $ref #/$defs/encryption_context* ciphertext ·
stringpattern:
^[A-Za-z0-9_-]+$fields ·
objectstate ·
string (enum)Morph lifecycle state. 'active' is the default. Reducer enforces transitions per common-fields.md §5.1: ak.morph.archive MUST come from 'active' (else failed_precondition reason=morph_not_active); ak.morph.restore MUST come from 'archived' (else morph_not_archived); ak.redaction targeting the morph MUST come from {'active','archived'} (else morph_already_terminal). Same-state self-transitions MUST fail. 'redacted' is the irreversible terminal.
enum:
"active" "archived" "redacted"state_changed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$stage ·
string (enum)Optional Morph business-progression stage. Orthogonal to top-level 'state' (physical lifecycle). Generic mirror/data Morphs may omit it; no v1 carrier can make it required at create time (realm morph_kind_profiles only tighten fields.* / facets / capability actions, see models/morph.md §4). If absent, the first ak.morph.stage.set initializes the axis to any registered value; later changes follow the normal transition rules. ak.morph.update patches on stage / stage_changed_at MUST be rejected. Stage transitions do not carry a reason/note; explanations belong in a referenced Message. See models/common-fields.md §5.3.
enum:
"draft" "proposed" "planned" "in_progress" "blocked" "done" "cancelled" "superseded"stage_changed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* created_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idupdated_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/morph.schema.json