ak.schema.realm_genesis.v1
ak.schema.realm_genesis.v1 · file: schemas/realm-genesis.schema.json * $ · object
allOf · allOf[0] ·
?founding_device_descriptor is exclusive to human Principal Control Realm genesis. agent_control, collaboration and direct_conversation genesis MUST omit it. genesis_salt is required for every purpose since PCR genesis is event-derived like any other Realm.
allOf · allOf[1] ·
?Only identity-control Realm genesis carries initial_resolution, and every such genesis carries it. Collaboration/direct-conversation Realms MUST omit it.
allOf · allOf[2] ·
?Human Principal Control Realm genesis uses the independently closed human-principal DID method set.
allOf · allOf[3] ·
?Agent PCR genesis commits the already accepted did:webvh inception head. The later PCR service binding update is continuous from this head and does not participate in the create Event preimage.
allOf · allOf[4] ·
?Applet-managed PCR genesis commits exactly the initial resolution already frozen by its accepted provision Event.
* schema ·
const "ak.schema.realm_genesis.v1"enum:
"ak.schema.realm_genesis.v1"* purpose ·
string (enum)enum:
"collaboration" "direct_conversation" "principal_control" "agent_control" "applet_managed_control"* genesis_salt ·
stringCanonical unpadded Base64URL encoding of exactly 32 CSPRNG octets. It distinguishes event-derived creation intents and has no replay, ordering, authorization, freshness, or winner semantics.
pattern:
^[A-Za-z0-9_-]{43}$founding_device_descriptor · object · $ref #/$defs/founding_device_descriptor
Closed founding-device commitment embedded in the root-signed human Principal Control Realm genesis payload and required by pcr_genesis_unit. It is not an independent signed object. Agent PCR creation omits this human-device descriptor.
* descriptor_version ·
const 1enum:
1* device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* device_public_key_did ·
stringdid:key form of the founding device Ed25519 signing key. The descriptor carries the raw key inside the root-signed genesis payload, so it carries no key digest; the receipt pcr_genesis_scope.device_key_digest is SHA-256(UTF-8(canonical multikey)) over this value with the did:key: prefix removed.
pattern:
^did:key:z[1-9A-HJ-NP-Za-km-z]+$* device_key_algorithm ·
const "Ed25519"enum:
"Ed25519"* device_key_purpose ·
const "event_signing_and_mls_identity"enum:
"event_signing_and_mls_identity"* hpke_key ·
stringFounding device X25519 HPKE public key as the canonical multibase base58btc multikey of the X25519 multicodec (0xec), always starting with z6LS. It is the same encoding discipline as device_public_key_did without the did:key: prefix and the same value the founding ak.device.authorize payload carries; the receipt pcr_genesis_scope.hpke_key_digest is SHA-256(UTF-8(this exact string)).
pattern:
^z6LS[1-9A-HJ-NP-Za-km-z]+$* hpke_key_algorithm ·
const "X25519"enum:
"X25519"* algorithms · array<string>
items ·
string* founding_authorize_payload_digest ·
string · $ref ./event-envelope.schema.json#/$defs/digestCanonical digest of the proof-free founding ak.device.authorize payload. It MUST NOT be an Event id or envelope digest.
pattern:
^(sha256|blake3):[0-9a-f]{64}$initial_resolution · object · $ref ./identity-resolution.schema.json#/$defs/resolution_commitment
Owner-committed current did and method-native history position. For a deterministic method, method_history_head and version_id use the adapter-defined deterministic canonical values; they are never omitted.
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* trust_domain ·
string · $ref ./realm.schema.json#/$defs/trust_domainpattern:
^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$* security_class ·
string (enum) · $ref ./realm.schema.json#/properties/security_classOptional security class. 'high_assurance' forbids federation_policy=open and SHOULD use stricter resolver/E2EE/audit defaults. Omitted = 'standard'.
enum:
"standard" "high_assurance"* governance_station_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* initial_join_rule ·
string (enum) · $ref ./realm.schema.json#/properties/default_join_ruleenum:
"public" "invite" "knock" "restricted" "knock_restricted" "closed"* initial_history_access ·
string (enum) · $ref ./realm.schema.json#/properties/history_accessScope-local history range ratchet initialized by Realm create. Only all_history_for_current_members to since_join may change state; widening back to all_history is permanently forbidden. Standard MLS requires since_join.
enum:
"since_join" "all_history_for_current_members"* initial_discoverability ·
string (enum) · $ref ./realm.schema.json#/properties/default_discoverabilityenum:
"public" "listed" "restricted" "unlisted" "invite_only" "secret"Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/realm-genesis.schema.json