ak.schema.recovery_completion_attestation.v1
ak.schema.recovery_completion_attestation.v1 · file: schemas/recovery-authority.schema.json Closed recovery completion attestation and Standard-grant issuance carriers. Device recovery is authorized by the accepted PCR recovery policy; an optional DID-root proof is only one explicitly enabled factor. When deployment policy permits reactivation, the same completed closure is the only operation that may atomically author a deactivated-to-active successor for the original account before issuing its new-generation Standard grant.
* $ · oneOf[3]
Closed recovery completion attestation and Standard-grant issuance carriers. Device recovery is authorized by the accepted PCR recovery policy; an optional DID-root proof is only one explicitly enabled factor. When deployment policy permits reactivation, the same completed closure is the only operation that may atomically author a deactivated-to-active successor for the original account before issuing its new-generation Standard grant.
oneOf · oneOf[0] · object · $ref #/$defs/recovery_completion_attestation
Coordinator-signed proof created after one atomic recovery commit accepted the two producer-signed recovery Events, issued one PCR-stream RealmCommit for each of them, advanced the device generation, activated the replacement device, consumed the recovery session and completed the transaction. A RealmCommit accepts exactly one Event, so the two CommittedEventRef values MUST name two different Commits at consecutive positions n and n+1 of the same PCR Realm stream; their commit_id and their event_id MUST both differ.
* schema ·
const "ak.schema.recovery_completion_attestation.v1"enum:
"ak.schema.recovery_completion_attestation.v1"* transaction_id ·
string · $ref #/$defs/transaction_idpattern:
^ak:transaction:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* transaction_request_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* prepared_plan_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* recovery_session_id ·
string · $ref #/$defs/recovery_session_idpattern:
^ak:recovery_session:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* terminal_receipt_id ·
string · $ref #/$defs/receipt_idpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* terminal_receipt_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* replacement_device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* result_model_generation_ref ·
integer · $ref #/$defs/pcr_generation_ref* completed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* auth_data · object
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature_algorithm ·
const "Ed25519"enum:
"Ed25519"* signature ·
stringBase64URL signature over the closed completion projection, including reanchor_event_ref, device_authorization_event_ref and result_model_generation_ref.
pattern:
^[A-Za-z0-9_-]+$* reanchor_event_ref · allOf[1]
CommittedEventRef of the recovery re-anchor Event in the account PCR stream. It sits at position n, immediately before device_authorization_event_ref, in its own RealmCommit.
allOf · allOf[0] · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* stream_position ·
integer* device_authorization_event_ref · allOf[1]
CommittedEventRef of the replacement-device authorization Event. It sits at position n+1 of the same PCR Realm stream as reanchor_event_ref, in its own RealmCommit accepted by the same atomic recovery transaction.
allOf · allOf[0] · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* stream_position ·
integeroneOf · oneOf[1] · object · $ref #/$defs/issue_recovery_completion_grant_request
Closed request proving completed PCR recovery and the exact current replacement device generation. The Account Authority checks the committed re-anchor through its RealmCommit.
* transaction_id ·
string · $ref #/$defs/transaction_idpattern:
^ak:transaction:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* transaction_request_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* terminal_receipt · object · $ref ./recovery-receipt.schema.json
Replacement-device-signed terminal intent for one RecoveryTransaction. It binds the two exact producer Event ids, recovery session/policy/proof snapshot and resulting device generation expectation. It is signed before authority admission and therefore does not contain a RealmCommit id; successful completion is proven separately by the coordinator-signed recovery completion attestation and its CommittedEventRef values.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* schema ·
const "ak.schema.recovery_receipt.v1"enum:
"ak.schema.recovery_receipt.v1"* receipt_id ·
stringpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* transaction_id ·
stringRecoveryTransaction that reserved this receipt id. It MUST equal the transaction whose binding.terminal_receipt_id is this receipt_id, which is what lets a verifier holding only the receipt resolve the authorizing transaction; binding.terminal_receipt_id alone is one-way. See zh/identity/security-transactions.md section 2.
pattern:
^ak:transaction:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* transaction_request_digest ·
string · $ref #/$defs/digestStable request_digest of the RecoveryTransaction. It is signed by the replacement device so the terminal attestation cannot be rebound to a different transaction plan even if an identifier is substituted.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* prepared_plan_digest ·
string · $ref #/$defs/digestDigest of the closed typed prepared_plan stored by the RecoveryTransaction. It MUST equal transaction.prepared_plan_digest and is signed to prevent substituting different prepared bytes under the same reserved ids.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* recovery_session_id ·
stringStable session identifier used by every proof transcript, backup decrypt proof, and MLS Welcome replay during this recovery. A byte-identical resubmission of an already accepted receipt is idempotent and MUST return the stored receipt; only a SECOND, DIFFERENT receipt for the same session id and exact account is a conflict. Rejecting the byte-identical replay would make a lost response unrecoverable, which zh/identity/security-transactions.md section 1 invariants 3 and 4 forbid.
pattern:
^ak:recovery_session:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* policy_id ·
stringpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* policy_version ·
integer* trust_domain ·
string · $ref ./common-ids.schema.json#/$defs/trust_domainpattern:
^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$* new_device_id ·
stringpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* identity_model ·
const "pcr_policy"enum:
"pcr_policy"* recovery_authority_kind ·
string (enum)did_root is valid only when the accepted PCR policy explicitly enabled that optional factor.
enum:
"pcr_policy" "did_root"* previous_model_generation_ref ·
integerPCR device generation snapshotted at recovery-session creation.
* result_model_generation_ref ·
integerAccepted monotonic PCR device generation after completion.
* authorization_event_id ·
stringpattern:
^ak:event:[A-Za-z0-9_-]{44}$* reanchor_event_id ·
stringpattern:
^ak:event:[A-Za-z0-9_-]{44}$* proof_summary · object
* kind ·
string (enum)enum:
"did_root" "recovery_unlock" "device_quorum" "trusted_recovery_service"* proof_digest ·
string · $ref #/$defs/digestCanonical-JSON digest of the proof transcript used to satisfy the active recovery policy. Auditors recompute against the originating proof event to verify.
pattern:
^(sha256|blake3):[0-9a-f]{64}$quorum_participant_count ·
integerRequired for device_quorum; equals the number of distinct participating member devices.
* unlocked_backups · array<object>
items · object
* backup_kind ·
string (enum)enum:
"secret_storage"* backup_id ·
stringpattern:
^ak:backup:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* series_id ·
stringpattern:
^ak:backup_series:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* ciphertext_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* welcome_count ·
integerNumber of MLS Welcomes successfully replayed for the recovering device.
welcome_realm_summaries · array<object>
items · object
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* mls_group_id ·
string · $ref ./common-ids.schema.json#/$defs/mls_group_idRFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern:
^[A-Za-z0-9_-]{43}$* epoch ·
integer* outcome ·
string (enum)enum:
"completed" "partial" "aborted_by_user" "policy_denied" "evidence_insufficient" "service_defined"outcome_reason_code ·
stringFree-form reason code; MUST be present when outcome != 'completed'.
* started_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* completed_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampAuthoring time at which the replacement device signed 'complete this recovery if every check passes'. It is not proof that anything was committed. The durable, linearized commit time is the completed_at of the paired ak.schema.recovery_completion_attestation.v1, which MUST NOT be earlier than this value.
* auth_data · object
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature_algorithm ·
string (enum)v1 fixes the recovery-strand replacement device possession proof to Ed25519 (zh/crypto-media/device-lifecycle.md sections 5.2 and 14; transaction binding in zh/identity/security-transactions.md section 2). The three-algorithm set in zh/identity/key-management.md section 7.9 belongs to recovery_policy.method signing entries.alg and MUST NOT be reused as a reason to widen this one.
enum:
"Ed25519"* signature ·
stringbase64url signature over UTF8('ak.identity.recovery_receipt.signature.v1\n') followed by RFC 8785 JCS of all present top-level receipt members except auth_data. The closed receipt shape fixes the projection; absent optional members are omitted and every present optional member is authenticated.
pattern:
^[A-Za-z0-9_-]+$(^x_[a-z][a-z0-9_]{0,63}$) ·
any* completion_attestation · object · $ref #/$defs/recovery_completion_attestation
Coordinator-signed proof created after one atomic recovery commit accepted the two producer-signed recovery Events, issued one PCR-stream RealmCommit for each of them, advanced the device generation, activated the replacement device, consumed the recovery session and completed the transaction. A RealmCommit accepts exactly one Event, so the two CommittedEventRef values MUST name two different Commits at consecutive positions n and n+1 of the same PCR Realm stream; their commit_id and their event_id MUST both differ.
* schema ·
const "ak.schema.recovery_completion_attestation.v1"enum:
"ak.schema.recovery_completion_attestation.v1"* transaction_id ·
string · $ref #/$defs/transaction_idpattern:
^ak:transaction:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* transaction_request_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* prepared_plan_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* recovery_session_id ·
string · $ref #/$defs/recovery_session_idpattern:
^ak:recovery_session:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* terminal_receipt_id ·
string · $ref #/$defs/receipt_idpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* terminal_receipt_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* replacement_device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* result_model_generation_ref ·
integer · $ref #/$defs/pcr_generation_ref* completed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* auth_data · object
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature_algorithm ·
const "Ed25519"enum:
"Ed25519"* signature ·
stringBase64URL signature over the closed completion projection, including reanchor_event_ref, device_authorization_event_ref and result_model_generation_ref.
pattern:
^[A-Za-z0-9_-]+$* reanchor_event_ref · allOf[1]
CommittedEventRef of the recovery re-anchor Event in the account PCR stream. It sits at position n, immediately before device_authorization_event_ref, in its own RealmCommit.
allOf · allOf[0] · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* stream_position ·
integer* device_authorization_event_ref · allOf[1]
CommittedEventRef of the replacement-device authorization Event. It sits at position n+1 of the same PCR Realm stream as reanchor_event_ref, in its own RealmCommit accepted by the same atomic recovery transaction.
allOf · allOf[0] · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* stream_position ·
integer* device_authorization_event_id ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* result_model_generation_ref ·
integer · $ref #/$defs/pcr_generation_ref* initial_session · object · $ref ./service-operation-dtos.schema.json#/$defs/InitialSessionGrantIntent
Initial Standard SessionGrant intent embedded in identity_creation registration. It reuses the DPoP holder key established by account handoff; Account Authority recomputes RFC 7638 thumbprint of session_public_key and requires equality with the handoff/control-proof dpop_jkt. It is not a separate authorization or credential.
* device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* session_public_key ·
string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcsExact RFC 8785 JCS public JWK for the existing handoff DPoP holder key. Private members are forbidden.
* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* canonical_request_digest ·
string · $ref #/$defs/digestSHA-256 of JCS(request object with only canonical_request_digest omitted). The Bound AccountHandoff authorization and RFC 9449 HTTP DPoP proof authenticate the account and holder outside this closed business body.
pattern:
^(sha256|blake3):[0-9a-f]{64}$oneOf · oneOf[2] · object · $ref #/$defs/issue_recovery_completion_grant_outcome
Exact durable outcome for one completed recovery transaction. If the original account was deactivated, successful issuance also means the Account Authority atomically restored that same account and authored its deactivated-to-active successor; no replacement account or second PCR is created.
* transaction_id ·
string · $ref #/$defs/transaction_idpattern:
^ak:transaction:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* session_grant_outcome · object · $ref ./service-operation-dtos.schema.json#/$defs/SessionGrantOutcome
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_iddevice_id ·
stringpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* session_grant ·
stringShort-lived bearer/session grant bound to the requested principal, device and audience.
* expires_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* session_grant_id ·
string · $ref ./common-ids.schema.json#/$defs/session_grant_idStable id of the issued or rotated session grant. Returned for every grant so the client can reference, refresh, introspect or revoke this exact grant without re-parsing the opaque session_grant.
pattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$* session_public_key ·
string (canonical-public-jwk-jcs) · format=canonical-public-jwk-jcsJWK of the holder/session key the grant is bound to (the device holder key). The client needs this to perform RFC 9421 PoP and to derive the DPoP cnf.jkt for /_arkret/self/* requests (api-conventions.md §3.2 / §3.3); returning it avoids a mandatory introspect round-trip before the first self-path request.
* audience_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* granted_scope · array<string>
items ·
stringprevious_session_grant_id ·
string · $ref ./common-ids.schema.json#/$defs/session_grant_idPresent only on refresh. The predecessor grant atomically superseded by this successor.
pattern:
^ak:session_grant:[A-Za-z0-9_-]{44}$* issued_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/recovery-authority.schema.json