ak.schema.realm_authority_handoff.v1
ak.schema.realm_authority_handoff.v1 · file: schemas/realm-authority-handoff.schema.json Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* $ · object
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_old_signature.v1"enum:
"ak.realm_authority_handoff_old_signature.v1"* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_new_acceptance_signature.v1"enum:
"ak.realm_authority_handoff_new_acceptance_signature.v1"allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_old_signature.v1"enum:
"ak.realm_authority_handoff_old_signature.v1"* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_old_signature.v1"enum:
"ak.realm_authority_handoff_old_signature.v1"* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_new_acceptance_signature.v1"enum:
"ak.realm_authority_handoff_new_acceptance_signature.v1"allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_new_acceptance_signature.v1"enum:
"ak.realm_authority_handoff_new_acceptance_signature.v1"allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_old_signature.v1"enum:
"ak.realm_authority_handoff_old_signature.v1"* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_old_signature.v1"enum:
"ak.realm_authority_handoff_old_signature.v1"* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_new_acceptance_signature.v1"enum:
"ak.realm_authority_handoff_new_acceptance_signature.v1"allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_old_signature.v1"enum:
"ak.realm_authority_handoff_old_signature.v1"* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_old_signature.v1"enum:
"ak.realm_authority_handoff_old_signature.v1"* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_authority_handoff_idContent-addressed identity of one closed old-to-new Realm authority handoff.
pattern:
^ak:realm_authority_handoff:[A-Za-z0-9_-]{44}$* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* from_generation ·
integer* to_generation ·
integer* from_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* to_service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* final_stream_heads_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$historical_signer_facts_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestNew handoffs require SHA256(JCS complete sorted {target,producer_signer_fact} inventory); existing_original-only schema absence cannot transfer new digest-bearing history. Both original handoff contexts sign it.
pattern:
^sha256:[0-9a-f]{64}$* snapshot_ref ·
string · $ref ./common-ids.schema.json#/$defs/realm_snapshot_idContent-addressed identity of an authority-signed typed Realm snapshot.
pattern:
^ak:realm_snapshot:[A-Za-z0-9_-]{44}$* change_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* change_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* old_authority_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_old_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature · allOf[2] · $ref ./detached-object-signature.schema.json#/$defs/realm_authority_handoff_new_acceptance_signature
allOf · allOf[0] · object · $ref #
Closed planned transfer from one Realm authority generation to its unique successor. Both service signatures and the controller-authored change Event are required; this is not a quorum vote.
* handoff_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* from_generation ·
…recursion truncated at depth 8; see source schema for full shape
* to_generation ·
…recursion truncated at depth 8; see source schema for full shape
* from_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* to_service_id ·
…recursion truncated at depth 8; see source schema for full shape
* final_stream_heads_digest ·
…recursion truncated at depth 8; see source schema for full shape
historical_signer_facts_digest ·
…recursion truncated at depth 8; see source schema for full shape
* snapshot_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
* change_commit_id ·
…recursion truncated at depth 8; see source schema for full shape
* old_authority_signature ·
…recursion truncated at depth 8; see source schema for full shape
* new_authority_acceptance_signature ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_new_acceptance_signature.v1"enum:
"ak.realm_authority_handoff_new_acceptance_signature.v1"allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_new_acceptance_signature.v1"enum:
"ak.realm_authority_handoff_new_acceptance_signature.v1"allOf · allOf[1] · object
context ·
const "ak.realm_authority_handoff_new_acceptance_signature.v1"enum:
"ak.realm_authority_handoff_new_acceptance_signature.v1"Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/realm-authority-handoff.schema.json