ak.schema.public_key.v1
ak.schema.public_key.v1 · file: schemas/public-key.schema.json Canonical wire shape of a public key carried in Arkret DTOs. It is defined in its own document so that device, agent and account surfaces reference one shared definition instead of reverse-referencing each other's bundles. Prose examples MUST use this exact shape: kty/kid/algorithm/key, no public_key alias.
* $ · object · $ref #/$defs/public_key
Canonical public key. key carries the base64url key material; kid is the typed identifier of the key holder (for a device key, ak:device:<uuidv7>). There is no public_key member: that spelling is not canonical wire and MUST be rejected.
* kty ·
string · $ref #/$defs/non_empty_string* kid ·
string · $ref #/$defs/non_empty_string* algorithm ·
string · $ref #/$defs/non_empty_string* key ·
string · $ref #/$defs/base64urlpattern:
^[A-Za-z0-9_-]+$key_digest ·
string · $ref #/$defs/digestpattern:
^sha256:[0-9a-f]{64}$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/public-key.schema.json