ak.schema.registration_did_evidence.v1
ak.schema.registration_did_evidence.v1 · file: schemas/registration-did-evidence.schema.json Account-onboarding historical DID evidence retained inside the Station account/PCR boundary. It is not federated signer-key evidence and does not identify an external principal account-local lineage.
* $ · oneOf[2]
Account-onboarding historical DID evidence retained inside the Station account/PCR boundary. It is not federated signer-key evidence and does not identify an external principal account-local lineage.
oneOf · oneOf[0] · object · $ref #/$defs/registration_did_evidence_draft
Client-authored historical DID evidence before Account Authority acceptance. control_proof signs canonical_json({context:'ak.registration_did_evidence_control_proof.v1',principal_id,did,adapter_version,method_history_head,version_id,control_key_digest,method_evidence_digest,verification_method,created_at}); method_evidence_digest is sha256 over RFC 8785 JCS of method_evidence. accepted_at is deliberately absent: the Account Authority adds it only after the exact did_operation has been accepted by the registry.
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref ./common-ids.schema.json#/$defs/webvh_didCanonical bare did:webvh identifier used at method-native registration, document and evidence boundaries. Role admission is enforced separately.
pattern:
^did:webvh:[^\s:/?#]+:[^\s/?#]+$* adapter_version ·
const "did:webvh:1.0"enum:
"did:webvh:1.0"* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* control_key_digest ·
stringpattern:
^sha256:[0-9a-f]{64}$* method_evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
const "ak.did.binding_evidence.v1"enum:
"ak.did.binding_evidence.v1"* method ·
$ref #/$defs/method_token · $ref #/$defs/method_token* document_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of the resolver's verified normalized DID Document projection (did-usage-and-verification.md section 5.1); never the raw response bytes (those use the differently named raw_document_digest).
* method_proofs · array<$ref #/$defs/webvh_log_evidence>
Closed per-method proof rows; empty for proofless methods (did:key, bare did:web). v1 registers exactly one row kind (webvh_log); receiving any unregistered proof kind fails closed. Rows never reuse resolver response order: each row kind registers its own canonical sort and duplicate-rejection rules.
items ·
$ref #/$defs/webvh_log_evidence · $ref #/$defs/webvh_log_evidence* control_proof · object · $ref ./principal-operations.schema.json#/$defs/signature
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$oneOf · oneOf[1] · object · $ref #/$defs/registration_did_evidence
Account-Authority-accepted form of registration_did_evidence_draft. accepted_at records the trusted registry's own original acceptance time for the exact did_operation and is not retroactively inserted into the client signature, while control_proof.created_at records the instant the proof signer committed inside its own signature. The two timestamps come from independent Authority clocks and establish no dependable causal order, so verifiers MUST NOT accept or reject this evidence by comparing them numerically. The pcr_genesis_unit receipt commits the canonical digest of this complete object.
* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* did ·
string · $ref ./common-ids.schema.json#/$defs/webvh_didCanonical bare did:webvh identifier used at method-native registration, document and evidence boundaries. Role admission is enforced separately.
pattern:
^did:webvh:[^\s:/?#]+:[^\s/?#]+$* adapter_version ·
const "did:webvh:1.0"enum:
"did:webvh:1.0"* accepted_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* control_key_digest ·
stringpattern:
^sha256:[0-9a-f]{64}$* method_evidence · object · $ref ./did-binding-contracts.schema.json#/$defs/evidence_receipt
Canonical evidence receipt. evidence_digest = "sha256:" + lowercase_hex(SHA-256(RFC8785_JCS(evidence_receipt))). The receipt MUST be retained so an auditor can recompute the digest; a method without proofs degrades to an empty method_proofs array (a document-bound receipt), never to an implementation-invented placeholder. Unknown method or proof kinds fail closed.
* kind ·
const "ak.did.binding_evidence.v1"enum:
"ak.did.binding_evidence.v1"* method ·
$ref #/$defs/method_token · $ref #/$defs/method_token* document_digest ·
$ref #/$defs/digest · $ref #/$defs/digestDigest of the resolver's verified normalized DID Document projection (did-usage-and-verification.md section 5.1); never the raw response bytes (those use the differently named raw_document_digest).
* method_proofs · array<$ref #/$defs/webvh_log_evidence>
Closed per-method proof rows; empty for proofless methods (did:key, bare did:web). v1 registers exactly one row kind (webvh_log); receiving any unregistered proof kind fails closed. Rows never reuse resolver response order: each row kind registers its own canonical sort and duplicate-rejection rules.
items ·
$ref #/$defs/webvh_log_evidence · $ref #/$defs/webvh_log_evidence* control_proof · object · $ref ./principal-operations.schema.json#/$defs/signature
Registration control signature whose transcript digest is committed by the pcr_genesis_unit receipt.
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/registration-did-evidence.schema.json