跳转到内容

ak.schema.realm_genesis.v1

← Schemas

Arkret Realm Genesis
ak.schema.realm_genesis.v1 · file: schemas/realm-genesis.schema.json
* $ · object
allOf · allOf[0] · ?
founding_device_descriptor is exclusive to human Principal Control Realm genesis. agent_control, collaboration and direct_conversation genesis MUST omit it. genesis_salt is required for every purpose since PCR genesis is event-derived like any other Realm.
allOf · allOf[1] · ?
Only identity-control Realm genesis carries initial_resolution, and every such genesis carries it. Collaboration/direct-conversation Realms MUST omit it.
allOf · allOf[2] · ?
Human Principal Control Realm genesis uses the independently closed human-principal DID method set.
allOf · allOf[3] · ?
Agent PCR genesis commits the already accepted did:webvh inception head. The later PCR service binding update is continuous from this head and does not participate in the create Event preimage.
allOf · allOf[4] · ?
Applet-managed PCR genesis commits exactly the initial resolution already frozen by its accepted provision Event.
* schema · const "ak.schema.realm_genesis.v1"
enum: "ak.schema.realm_genesis.v1"
* purpose · string (enum)
enum: "collaboration" "direct_conversation" "principal_control" "agent_control" "applet_managed_control"
* genesis_salt · string
Canonical unpadded Base64URL encoding of exactly 32 CSPRNG octets. It distinguishes event-derived creation intents and has no replay, ordering, authorization, freshness, or winner semantics.
pattern: ^[A-Za-z0-9_-]{43}$
founding_device_descriptor · object · $ref #/$defs/founding_device_descriptor
Closed founding-device commitment embedded in the root-signed human Principal Control Realm genesis payload and required by pcr_genesis_unit. It is not an independent signed object. Agent PCR creation omits this human-device descriptor.
* descriptor_version · const 1
enum: 1
* device_id · string · $ref ./common-ids.schema.json#/$defs/device_id
pattern: ^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* device_public_key_did · string
did:key form of the founding device Ed25519 signing key. The descriptor carries the raw key inside the root-signed genesis payload, so it carries no key digest; the receipt pcr_genesis_scope.device_key_digest is SHA-256(UTF-8(canonical multikey)) over this value with the did:key: prefix removed.
pattern: ^did:key:z[1-9A-HJ-NP-Za-km-z]+$
* device_key_algorithm · const "Ed25519"
enum: "Ed25519"
* device_key_purpose · const "event_signing_and_mls_identity"
enum: "event_signing_and_mls_identity"
* hpke_key · string
Founding device X25519 HPKE public key as the canonical multibase base58btc multikey of the X25519 multicodec (0xec), always starting with z6LS. It is the same encoding discipline as device_public_key_did without the did:key: prefix and the same value the founding ak.device.authorize payload carries; the receipt pcr_genesis_scope.hpke_key_digest is SHA-256(UTF-8(this exact string)).
pattern: ^z6LS[1-9A-HJ-NP-Za-km-z]+$
* hpke_key_algorithm · const "X25519"
enum: "X25519"
* algorithms · array<string>
items · string
* founding_authorize_payload_digest · string · $ref ./event-envelope.schema.json#/$defs/digest
Canonical digest of the proof-free founding ak.device.authorize payload. It MUST NOT be an Event id or envelope digest.
pattern: ^(sha256|blake3):[0-9a-f]{64}$
initial_resolution · object · $ref ./identity-resolution.schema.json#/$defs/resolution_commitment
Owner-committed current did and method-native history position. For a deterministic method, method_history_head and version_id use the adapter-defined deterministic canonical values; they are never omitted.
* did · string · $ref ./common-ids.schema.json#/$defs/did
Canonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern: ^did:[a-z0-9]+:[^\s/?#]+$
* method_history_head · string
* version_id · string
pattern: ^(?!ak:)
* trust_domain · string · $ref ./realm.schema.json#/$defs/trust_domain
pattern: ^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$
* security_class · string (enum) · $ref ./realm.schema.json#/properties/security_class
Optional security class. 'high_assurance' forbids federation_policy=open and SHOULD use stricter resolver/E2EE/audit defaults. Omitted = 'standard'.
enum: "standard" "high_assurance"
* governance_station_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* initial_join_rule · string (enum) · $ref ./realm.schema.json#/properties/default_join_rule
enum: "public" "invite" "knock" "restricted" "knock_restricted" "closed"
* initial_history_access · string (enum) · $ref ./realm.schema.json#/properties/history_access
Scope-local history range ratchet initialized by Realm create. Only all_history_for_current_members to since_join may change state; widening back to all_history is permanently forbidden. Standard MLS requires since_join.
enum: "since_join" "all_history_for_current_members"
* initial_discoverability · string (enum) · $ref ./realm.schema.json#/properties/default_discoverability
enum: "public" "listed" "restricted" "unlisted" "invite_only" "secret"

Source