跳转到内容

ak.schema.notification.v1

← Schemas

Arkret Notification
ak.schema.notification.v1 · file: schemas/notification.schema.json
* $ · object
oneOf · oneOf[0] · object
id · string
SHA-256 suite byte 0x01 followed by the complete digest of the registered notification projection preimage. Recompute against recipient AccountId, RealmId, source EventId and notification_kind.
pattern: ^ak:notification_projection:[A-Za-z0-9_-]{44}$
actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
notification_kind · string (enum) · $ref #/$defs/ordinary_notification_kind
Closed notification_kind subset of the ordinary source-Event branch. invite has its own private Invite delivery carrier and agent belongs to the account-artifact branch, so neither participates in the deterministic projection preimage.
enum: "message" "mention" "reply" "assignment" "schedule" "reaction" "policy" "call" "applet" "moderation" "system"
oneOf · oneOf[1] · object
notification_kind · const "agent"
enum: "agent"
id · string
pattern: ^ak:notification:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* id · oneOf[2]
oneOf · oneOf[0] · string
SHA-256 suite byte 0x01 followed by the complete digest of the registered notification projection preimage. Recompute against recipient AccountId, RealmId, source EventId and notification_kind.
pattern: ^ak:notification_projection:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · string
pattern: ^ak:notification:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* schema · const "ak.schema.notification.v1"
enum: "ak.schema.notification.v1"
* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
source_event_id · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
source_account_artifact · object
Closed account-private artifact source for notifications that are not derived from a durable Realm Event.
* kind · const "agent_runtime_approval"
enum: "agent_runtime_approval"
* id · string
Profile-local approval_request_id. It is an opaque_correlation value, so its lexical space is disjoint from the ak: typed-ID namespace: a value MUST NOT begin with ak:.
pattern: ^(?!ak:)[A-Za-z0-9._:-]{1,128}$
source_ref · string
Optional canonical-object reference for clients that want to render the notification target without resolving source_event_id. Reducers MUST treat source_event_id as authoritative; source_ref is a render-only hint.
pattern: ^((?:ak:(message|strand|morph|relation|view):[A-Za-z0-9_-]{44}|ak:(blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})|ak:blob:(sha256|blake3):[0-9a-f]{64})$
strand_id · string
Optional Strand context for routing the notification.
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
track_name · string
Optional Strand track key on the source Strand.
pattern: ^[a-z][a-z0-9_]{0,63}$
* notification_kind · string (enum)
enum: "message" "mention" "reply" "assignment" "schedule" "invite" "reaction" "policy" "call" "applet" "agent" "moderation" "system"
* priority · string (enum)
enum: "low" "normal" "high" "urgent"
* state · string (enum)
enum: "unread" "read" "dismissed" "archived"
preview · object
Render summary. Under E2EE / redaction / history-limited scopes this MUST be empty or an authorized redacted digest; sender/reducer-enforced. A notification projection MUST NOT widen the plaintext visibility of the source Message. See models/private-objects.md §3.4.
* created_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
updated_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$

Source