跳转到内容

ak.schema.principal_registration_anchor.v1

← Schemas

Arkret Principal Registration Anchor
ak.schema.principal_registration_anchor.v1 · file: schemas/principal-registration-anchor.schema.json

Closed WebVH registration anchor for a v1 human principal. It is the single primary method-native material that human registration and PCR genesis both consume. v1 human registration supports exactly the active did:webvh adapter and anchor_kind=webvh_registration; every other DID method, including did:key and did:web, fails closed with unsupported_did_method before method-specific parsing. The anchor carries originals, never receipts: a verifier reconstructs did, method_history_head, version_id, the exact normalized DID document and the root verification method/key from the branch material alone, offline, without a current resolver, a database row or an Account Authority attestation. registration_did_evidence and identity_creation_control_proof keep their own registration anti-replay and control-intent roles and never substitute for this object. Adding another branch requires a separately registered publication-proof or independent-witness trust model, threat model and conformance vectors. Complete canonical anchor bytes MUST NOT exceed 1 MiB.

* $ · oneOf[1]
Closed WebVH registration anchor for a v1 human principal. It is the single primary method-native material that human registration and PCR genesis both consume. v1 human registration supports exactly the active did:webvh adapter and anchor_kind=webvh_registration; every other DID method, including did:key and did:web, fails closed with unsupported_did_method before method-specific parsing. The anchor carries originals, never receipts: a verifier reconstructs did, method_history_head, version_id, the exact normalized DID document and the root verification method/key from the branch material alone, offline, without a current resolver, a database row or an Account Authority attestation. registration_did_evidence and identity_creation_control_proof keep their own registration anti-replay and control-intent roles and never substitute for this object. Adding another branch requires a separately registered publication-proof or independent-witness trust model, threat model and conformance vectors. Complete canonical anchor bytes MUST NOT exceed 1 MiB.
oneOf · oneOf[0] · object · $ref #/$defs/webvh_registration_anchor
did:webvh registration anchor. log_entries is the gap-free native history from inception through the registration entry: log_entries[i].versionId MUST carry version number i+1, and registration_did_operation adds only the did/did_method/seq wrapper the registry accepted around the terminal entry. witness_records is the complete did-witness.json record set every witness policy active in that interval requires. The verifier re-executes the registered did:webvh:1.0 adapter over log_entries - SCID derivation, every entry-hash link and predecessor versionId anchor, every controller proof, rotation authorization against the preceding nextKeyHashes commitment, and every applicable witness threshold - and only then derives, from the verified terminal entry alone: did from registration_did_operation.did, version_id from terminal versionId, method_history_head as sha256 over RFC 8785 JCS of that terminal entry, the root control key from terminal parameters.updateKeys[0], and the root verification method from the terminal entry proof whose multikey is that same key. The derived did, method_history_head and version_id MUST equal the PCR genesis initial_resolution values byte-for-byte, and the derived root verification method and key MUST be the ones the genesis root producer proof used. A resolver summary, a partial log range, a bare current DID document or a caller-asserted head is not this anchor.
* anchor_kind · const "webvh_registration"
enum: "webvh_registration"
* registration_did_operation · object · $ref ./service-operation-dtos.schema.json#/$defs/DidOperationSubmitRequestBody
Exact accepted registration-time did:webvh operation wrapper. did_method MUST equal webvh, did MUST be the canonical did:webvh identifier this anchor establishes and is the anchor's only copy of that DID, seq when present MUST equal the version number of the terminal entry, and operation MUST be canonically equal to the last log_entries element. prev_event_digest MUST be absent: inside an anchor the predecessor is carried as the preceding log_entries elements, so a digest of it would be a mirror of material already present. The wrapper therefore states an invariant rather than offering a second, independently choosable copy of the registration entry.
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* did_method · string
DID method discriminator without the did: prefix (e.g. web, webvh, key). It MUST exactly equal the method component of did; verifiers dispatch method-specific validation only after that equality check.
pattern: ^[a-z0-9]+$
seq · integer
Optional method sequence number when the DID method exposes one.
prev_event_digest · string
Optional previous operation hash / key-log head, when required by the DID method.
pattern: ^sha256:[0-9a-f]{64}$
* operation · object
Complete DID method-native operation, including every controller/update/recovery proof required by that method. This is not a generic JSON Patch. The selected adapter MUST validate the immutable native operation and its full history before any state mutation; transport authentication never substitutes for method-native control proof.
* log_entries · array<object>
Exact ordered native did:webvh entry objects from inception through the registration anchor entry. Element i MUST be the entry whose versionId version number is i+1, so a missing predecessor, a duplicate, a surplus entry after the registration entry, or a first entry other than inception 1 fails closed.
items · object
* witness_records · array<object>
Exact native did-witness.json record objects required by log_entries. Each record is the closed {versionId, proof} pair, at most one record per versionId, and its proof array MUST satisfy that version's effective witness policy threshold with distinct listed witnesses. Every record MUST name a versionId present in log_entries: unlike a fetched did-witness.json, this anchor's log ends at the registration entry, so a record for any other version is surplus and fails closed. The array is empty exactly when the verified log activates no witness policy.
items · object
* normalized_did_document · object · $ref ./did-binding-contracts.schema.json#/$defs/normalized_did_document
The sole canonical normalized DID Document projection used by document_digest. It retains every v1-normative member, including also_known_as and metadata.primary_handle, and losslessly retains unknown extensions. contexts preserves source order because JSON-LD context order can affect interpretation; every other set-like array is sorted in unsigned UTF-8 order with duplicates rejected. Duplicate/conflicting source properties, ids, relationship entries, services, metadata keys, or extension names fail before digesting. document_digest is exactly sha256:lowercase_hex(SHA-256(RFC8785_JCS(this object))); raw resolver bytes use raw_document_digest and no third DID-document digest name exists.
* did · $ref #/$defs/did · $ref #/$defs/did
* contexts · array<oneOf[2]>
items · oneOf[2]
oneOf · oneOf[0] · string
oneOf · oneOf[1] · object
* controller_dids · array<$ref #/$defs/did>
items · $ref #/$defs/did · $ref #/$defs/did
* also_known_as · array<string>
items · string
Canonical URI validated by the DID resolver before projection; this array may contain non-network schemes such as acct: and therefore is not a URL field.
pattern: ^[A-Za-z][A-Za-z0-9+.-]*:[^\s]+$
* verification_methods · array<$ref #/$defs/normalized_did_verification_method>
items · $ref #/$defs/normalized_did_verification_method · $ref #/$defs/normalized_did_verification_method
* authentication · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* assertion_methods · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* key_agreements · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* capability_invocations · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* capability_delegations · $ref #/$defs/normalized_did_relationship · $ref #/$defs/normalized_did_relationship
* services · array<$ref #/$defs/normalized_did_service>
items · $ref #/$defs/normalized_did_service · $ref #/$defs/normalized_did_service
* metadata · $ref #/$defs/normalized_did_document_metadata · $ref #/$defs/normalized_did_document_metadata
* extensions · array<$ref #/$defs/normalized_did_document_extension>
items · $ref #/$defs/normalized_did_document_extension · $ref #/$defs/normalized_did_document_extension

Source