ak.schema.relation.v1
ak.schema.relation.v1 · file: schemas/relation.schema.json * $ · object
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?id ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:relation:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.relation.v1"enum:
"ak.schema.relation.v1"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$scope_circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idOptional intra-Realm Circle (models/circle.md) defining this Relation fact's effective scope, supplied in the submit payload. For confidential_discussion_of it points to the private Strand's Circle. For structural relations the resulting effective_scope MUST NOT be wider than the narrowest participating endpoint scope (circle.md §6.1). Sidecar context mappings are native sidecar.context typed results, not Relation objects.
pattern:
^ak:circle:[A-Za-z0-9_-]{44}$effective_scope · oneOf[2] · $ref #/$defs/effective_scope
Read-only immutable effective scope of this Relation fact, materialized from the accepted Event.scope_ref after the receiver verifies it against scope_circle_id and endpoint pre-state (circle.md §6.1-§6.2). For structural relations it MUST NOT be wider than the narrowest participating endpoint scope. It remains immutable across any later scope rebind and MUST NOT appear in actor-supplied content payload (reason=effective_scope_reducer_managed).
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$* relation_kind ·
stringRelation semantic. The standard kind vocabulary (kind list, cardinality class, truth-source class, weak_semantic flag) is machine-indexed in artifacts/registry/relation-kind-registry.json; detailed dedupe/scope/conflict semantics in models/relation.md §3-§6. Cross-Realm constraint: the current governance Station's authoritative reducer MUST resolve both endpoints and reject structural relations 'contains' and 'belongs_to' when either endpoint realm differs from this Relation realm, with failed_precondition reason cross_realm_structural_relation and zero commit/projection effect; producer or SDK prechecks are non-authoritative. weak_semantic=true kinds per the registry MAY cross Realm subject to two-sided authorization. Stays a free string so extension profiles can add kinds; unregistered kinds are opaque edges (unknown_relation_kind), never container/visibility semantics.
* from_ref · oneOf[2] · $ref #/$defs/relation_endpoint
A typed object-reference string or a structured full ActorId. Equality and deduplication preserve the complete ActorId including Station. This branch represents an actor.
oneOf · oneOf[0] ·
string · $ref #/$defs/object_refTyped canonical object reference. Allowed kinds: realm, space, actor_profile, strand, message, morph, relation, event, view, blob metadata ID and content-addressed blob ref (sha256 / blake3). Actor endpoints use the structured ActorId branch of relation_endpoint, never a DID or serialized JSON string.
pattern:
^((?:ak:(realm|space|actor_profile|strand|message|morph|relation|event|view):[A-Za-z0-9_-]{44}|ak:(blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})|ak:blob:(sha256|blake3):[0-9a-f]{64})$oneOf · oneOf[1] · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* to_ref · oneOf[2] · $ref #/$defs/relation_endpoint
A typed object-reference string or a structured full ActorId. Equality and deduplication preserve the complete ActorId including Station. This branch represents an actor.
oneOf · oneOf[0] ·
string · $ref #/$defs/object_refTyped canonical object reference. Allowed kinds: realm, space, actor_profile, strand, message, morph, relation, event, view, blob metadata ID and content-addressed blob ref (sha256 / blake3). Actor endpoints use the structured ActorId branch of relation_endpoint, never a DID or serialized JSON string.
pattern:
^((?:ak:(realm|space|actor_profile|strand|message|morph|relation|event|view):[A-Za-z0-9_-]{44}|ak:(blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})|ak:blob:(sha256|blake3):[0-9a-f]{64})$oneOf · oneOf[1] · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idrank ·
string · $ref #/$defs/rankStable manual sort position under the registered ak.rank.lexofractional.v1 profile: 1..128 characters from the fixed base62 alphabet, compared character by character in ASCII order. It is a producer-chosen ordering token, not a derived or causal value; see zh/conformance/encoding.md section 9.1 for the grammar, rank_between and rebalance rules.
pattern:
^[0-9A-Za-z]{1,128}$fields ·
objectEdge metadata. MUST NOT contain a 'rank' key — rank moved to the top level in v1 to align with Space.rank.
state ·
string (enum)Relation state. 'tombstoned' covers both deletion and redaction; the originating reason is preserved on the ak.relation.tombstone / ak.redaction event, not on the materialized object.
enum:
"active" "tombstoned"state_changed_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* created_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idupdated_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/relation.schema.json