ak.schema.realm.v1
ak.schema.realm.v1 · file: schemas/realm.schema.json * $ · object
allOf · allOf[0] ·
?id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.realm.v1"enum:
"ak.schema.realm.v1"* title ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_256NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$summary ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/short_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$security_class ·
string (enum)Optional security class. 'high_assurance' forbids federation_policy=open and SHOULD use stricter resolver/E2EE/audit defaults. Omitted = 'standard'.
enum:
"standard" "high_assurance"* trust_domain ·
string · $ref #/$defs/trust_domainImmutable deployment trust domain captured by ak.realm.create. Receivers MUST require this to match the current Realm trust domain before accepting cross-domain replay-sensitive proofs.
pattern:
^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$owning_organization_ids · array<$ref #/$defs/did_core_id>
Declared or projected stable Organization principal identities associated with this Realm. Each value is a did_core_id and is not itself resolvable DID material; Organization classification and current DID evidence are established by accepted registration/resolution state. This field alone is not a verified ownership/governance endorsement; clients and directories MUST require an active ak.realm.organization statement for verified badges or organization-controlled semantics.
items ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* schema_refs · array<string>
Currently activated registered schema id set. It carries no Realm structural role: the signed ak.schema.realm_genesis.v1 purpose is the only authority for Realm class (zh/models/realm-and-space.md section 2.3), so a profile id here would be a second, editable class discriminator. The core member ak.schema.realm.v1 is initialised by the genesis reducer, is always present and can never be removed. Every other member MUST be a registered ak.schema.*.vN id; third-party namespaces are not accepted and no registered Event mints a non-ak. schema id. ak.realm.schema replaces this whole set (realm_schema_payload); policy, deployment conformance and operation-local profiles have their own carriers and are forbidden here.
items ·
stringpattern:
^ak\.schema\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v[0-9]+$fields · object
Product/profile fields. purpose and collaboration_role are reducer-managed read-only projections of the signed genesis purpose and MUST equal it (zh/models/realm-and-space.md section 2.3); they are schema constrained below so a producer cannot mint a Realm class here. Other product fields remain extension-defined.
purpose ·
string (enum)Projection of genesis purpose for the three identity-control classes. genesis purpose=collaboration and purpose=direct_conversation project no value here. Authorization MUST verify the genesis, never this field.
enum:
"principal_control" "agent_control" "applet_managed_control"collaboration_role ·
string (enum)Projection of genesis purpose=direct_conversation. No other genesis purpose projects this field, and authorization MUST verify the genesis rather than this projection.
enum:
"direct_conversation"policy_id ·
stringpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$preview_policy_id ·
stringOptional materialized pointer to the effective preview / peek policy. Canonical writes use ak.realm.preview_policy; absence means directory card / stripped state only, no history stub/snippet preview.
pattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$default_strand_id ·
string | nullDerived ordinary default-Strand selection from current-value projection realm_set_default_strand. The deterministic (depth, EventId) winner selects the candidate; it is effective only when the selected Strand is eligible, non-terminal, and in the same Realm. Selection grants no authority.
pattern:
^ak:strand:[A-Za-z0-9_-]{44}$* default_discoverability ·
string (enum)enum:
"public" "listed" "restricted" "unlisted" "invite_only" "secret"* default_join_rule ·
string (enum)enum:
"public" "invite" "knock" "restricted" "knock_restricted" "closed"* history_access ·
string (enum)Scope-local history range ratchet initialized by Realm create. Only all_history_for_current_members to since_join may change state; widening back to all_history is permanently forbidden. Standard MLS requires since_join.
enum:
"since_join" "all_history_for_current_members"* governance_station_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$agent_participation · object
Realm five-bit Agent participation ceiling. It may only tighten the target-service safety ceiling and is itself the parent of Circle and Strand ceilings.
* agent · object · $ref ./principal-operations.schema.json#/$defs/participation_bits
* reply_message ·
boolean* reaction_add ·
boolean* reaction_remove ·
boolean* accept_third_party_mention ·
boolean* act_on_behalf ·
booleanfederation_policy ·
string (enum)enum:
"open" "restricted" "closed" "quarantine"max_authority_lifetime_ms ·
integerMaximum fixed child-chain lifetime only for actions explicitly required to be finite by their risk/constraint contract. Defaults to 24 hours for those actions; first use freezes the bound and redelegation cannot renew it. It does not impose expiry on unbounded ordinary chat/read/organizer authorization.
example:
86400000retention_policy_id ·
stringpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$avatar_blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$* created_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
string · $ref #/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$updated_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/realm.schema.json