ak.schema.result_projection.v1
ak.schema.result_projection.v1 · file: schemas/typed-current-result.schema.json Closed domain result selected without protocol typed current result IDs. Every result names the last authority commit that affected the typed target.
* $ · oneOf[85]
Closed domain result selected without protocol typed current result IDs. Every result names the last authority commit that affected the typed target.
oneOf · oneOf[0] · object · $ref #/$defs/agent_interaction_result
* selector · object
* kind ·
const "agent_interaction"enum:
"agent_interaction"* agent_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/agent_interaction_value
* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* interaction_mode ·
string (enum)enum:
"private" "public"oneOf · oneOf[1] · object · $ref #/$defs/realm_authority_root_result
Singleton authority-root typed current result. The selector carries no component beyond its kind, so (realm_id, selector) is the Realm's lifetime-stable authority root identity.
* selector · object
* kind ·
const "realm_authority_root"enum:
"realm_authority_root"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/realm_authority_root_value
Closed value of the lifetime-stable Realm authority root. Every member is derived by the registered ak.realm.create value_projection from the signed envelope and create payload; an author-supplied member is a realm_authority_root_conflict, never an accepted write.
* controller_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* controller_epoch ·
integerIncrements only on a root controller rotation. Genesis is 0.
* authority_generation ·
integerRealm delegation-root generation. Genesis is 0 and only accepted ak.realm.authority.reset increments it; owner transfer and planned governance Station handoff preserve it, so neither invalidates existing grants.
* authority_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object · $ref #/$defs/realm_profile_result
* selector · object
* kind ·
const "realm_profile"enum:
"realm_profile"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./realm-profile.schema.json
* schema ·
const "ak.schema.realm_profile.v1"enum:
"ak.schema.realm_profile.v1"* title ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref ./string-profiles.schema.json#/$defs/display_text_256NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$summary ·
string (arkret-short-text) · format=arkret-short-text · $ref ./string-profiles.schema.json#/$defs/short_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$avatar_blob_ref ·
string · $ref ./common-ids.schema.json#/$defs/blob_refContent-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern:
^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$oneOf · oneOf[3] · object · $ref #/$defs/member_state_result
* selector · object
* kind ·
const "member_state"enum:
"member_state"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/member_state_value
Closed value of the member_state typed current result: the materialized membership register of one complete ActorId. models/common-fields.md section 4.5 fixes it as a four-state register over join/knock/leave/ban. It is a named def rather than an inline object because registry/contract-registry.json cites it as the value_schema_ref of ak.member.state; an enclosing _result envelope names the selector and revision beside the value, so citing the envelope would let a value_projection member be checked against the wrong object.
* membership ·
string (enum)enum:
"join" "knock" "leave" "ban"joined_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[4] · object · $ref #/$defs/strand_result
* selector · object
* kind ·
const "strand"enum:
"strand"* strand_id ·
stringpattern:
^ak:strand:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./strand.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
?allOf · allOf[6] ·
?id ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:strand:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.strand.v1"enum:
"ak.schema.strand.v1"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$scope_circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idOptional reference to an intra-Realm Circle (see models/circle.md) that defines this Strand's effective scope. When set, ALL Strand tracks (synthesis, discussion, etc.) share that Circle's membership, history visibility, delivery/query/projection boundary, and MLS activation state. When unset, the Strand lives in Realm-default scope. The producer signs the corresponding Event.scope_ref; the receiver verifies that the Circle belongs to this Realm and that the derived scope equals Event.scope_ref before materializing the object's immutable effective_scope. Rebinding scope_circle_id is forbidden by default (failed_precondition reason=scope_rebind_forbidden). For 'wide synthesis + narrow discussion' scenarios use two Strands linked by a confidential_discussion_of Relation (circle.md §7.2).
pattern:
^ak:circle:[A-Za-z0-9_-]{44}$schema_refs · array<string>
Optional authoritative schema set for profile-defined metadata.fields subtrees. Unlike Morph, a plain Strand carries no profile subtree and omits this field entirely; when present it MUST list at least one profile schema id. The container self-schema ak.schema.strand.v1 MUST NOT appear here. Every listed profile schema and its metadata.fields namespace MUST co-occur in both directions: the ref without the subtree and the subtree without the ref are both schema_violation, evaluated on the post-patch object by the registered event-kind payload class and reducer. Current-v1 has no per-Event requirements.schema[] carrier.
items ·
stringpattern:
^ak\.schema\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v[0-9]+$agent_participation · object
Optional wrapped five-bit Agent ceiling. When present every bit is explicit and may only tighten the enclosing Circle or Realm ceiling.
* agent · object · $ref ./principal-operations.schema.json#/$defs/participation_bits
* reply_message ·
boolean* reaction_add ·
boolean* reaction_remove ·
boolean* accept_third_party_mention ·
boolean* act_on_behalf ·
booleanmetadata ·
$ref #/$defs/strand_metadata · $ref #/$defs/strand_metadataencrypted_metadata · object · $ref ./encrypted-envelope.schema.json
Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.
* version ·
const "1.0"enum:
"1.0"* content_type ·
stringpattern:
^[a-z0-9.+-]+/[a-z0-9.+-]+$* encryption_context ·
$ref #/$defs/encryption_context · $ref #/$defs/encryption_context* ciphertext ·
stringpattern:
^[A-Za-z0-9_-]+$topic ·
$ref #/$defs/strand_topic · $ref #/$defs/strand_topicOptional single Topic classification for a stably bound Direct Conversation Chat. Root same-Realm Topic Space(kind=topic) only. Whole set/unset via ak.strand.update requires the exact current digest CAS. Omitted means unclassified; no Board position or canonical Relation mirrors this field.
content ·
$ref #/$defs/content_block · $ref #/$defs/content_blockStrand description body. This is base Strand content and is independent of the synthesis and discussion tracks.
encrypted_content · object · $ref ./encrypted-envelope.schema.json
Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.
* version ·
const "1.0"enum:
"1.0"* content_type ·
stringpattern:
^[a-z0-9.+-]+/[a-z0-9.+-]+$* encryption_context ·
$ref #/$defs/encryption_context · $ref #/$defs/encryption_context* ciphertext ·
stringpattern:
^[A-Za-z0-9_-]+$* tracks · object
Active Strand collaboration surfaces, keyed by an active name in track-name-registry.json. The synthesis entry may carry its own content / encrypted_content; the discussion entry configures a Message timeline and may not carry either field. Tracks do NOT carry independent membership / permissions / history visibility / E2EE: the entire Strand shares a single effective scope determined by Strand.scope_circle_id (see models/circle.md). At most one track entry may explicitly set is_primary=true; when none does, the reducer derives the primary track by the deterministic rules in models/strand-and-message.md §4.5. The map MUST contain at least one entry; propertyNames fails closed for names outside the registry-backed TrackName enum.
discussion · allOf[2]
allOf · allOf[0] ·
$ref #/$defs/strand_track · $ref #/$defs/strand_trackallOf · allOf[1] ·
?synthesis ·
$ref #/$defs/strand_track · $ref #/$defs/strand_trackstate ·
string (enum)Strand lifecycle state. 'active' is the default. Reducer enforces transitions per common-fields.md §5.1: ak.strand.archive MUST come from 'active' (else failed_precondition reason=strand_not_active); ak.strand.restore MUST come from 'archived' (else strand_not_archived); terminal state is reached only via a ak.redaction event targeting the strand (MUST come from {'active','archived'} else strand_already_terminal). Same-state self-transitions MUST fail. 'redacted' is the irreversible terminal.
enum:
"active" "archived" "redacted"state_changed_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampReducer-derived timestamp of the most recent state transition. MUST be set when state != 'active'; MUST be the created_at of the corresponding ak.strand.archive / ak.strand.restore / ak.redaction Event. Aligns with Space.state_changed_at and the common-fields rule in models/common-fields.md §3.
stage ·
string (enum)Optional Strand business-progression stage. Orthogonal to top-level 'state' (physical lifecycle): archive does NOT change stage; stage=done does NOT auto-archive. ak.strand.create MAY omit stage; when present it must be one of the protocol-level enum values and has no protocol-level default. The only wire path that mutates stage after creation is the dedicated ak.strand.stage.set event; ak.strand.update patches on stage / stage_changed_at MUST be rejected (schema_violation, single-source). Stage transitions intentionally do NOT carry a reason / note field — the ak.strand.stage.set event log is the audit source, and human-readable explanations belong in a Message on the discussion track that references the event. v1 has no per-Realm workflow profile carrier: the core reducer hard invariants (terminal state freeze, non-active reject) defined in models/common-fields.md §5.3.3 are the complete transition rule, and receivers MUST NOT narrow admission from Realm-private configuration (§5.3.4). See models/strand-and-message.md §3.2 for full semantics and models/common-fields.md §5.3 for the protocol-level enum / bucket mapping.
enum:
"draft" "proposed" "planned" "in_progress" "blocked" "done" "cancelled" "superseded"stage_changed_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampReducer-derived timestamp of the most recent stage transition. MUST NOT appear without stage. MUST be ignored when present on wire; reducer overwrites with the triggering ak.strand.stage.set event's created_at. Same-value self-transitions (stage value unchanged) MUST NOT update this field.
* created_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampupdated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idupdated_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[5] · object · $ref #/$defs/space_result
Registered projection of one Space object (zh/models/realm-and-space.md). ak.space.create writes the whole object and the dedicated ak.space.archive / restore / tombstone kinds move its state member through the mapping zh/models/common-fields.md section 5.2 fixes. The subject carries the object id because only the create Event derives it from its own event_id; every later write names it in the payload.
* selector · object
* kind ·
const "space"enum:
"space"* space_id ·
stringpattern:
^ak:space:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./space.schema.json
A Space is a structural grouping object inside a Realm. Boards, lists, swimlanes, calendar buckets, document outline groups, etc. are all Spaces. Authorization-transparent: never carries its own membership/policy/E2EE group; its metadata may be placed in an existing Realm/Circle effective scope via scope_circle_id.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] · oneOf[2]
oneOf · oneOf[0] ·
?oneOf · oneOf[1] · object
fields ·
objectid ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:space:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.space.v1"enum:
"ak.schema.space.v1"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$scope_circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idOptional Circle scope for this Space object's own metadata and scoped structural relation facts. Space still does not own a security boundary; it only places its metadata into an existing Circle scope. Omitted means Realm-default scope.
pattern:
^ak:circle:[A-Za-z0-9_-]{44}$child_scope_policy ·
$ref #/$defs/child_scope_policy · $ref #/$defs/child_scope_policyReducer-enforced placement/encryption policy for child resources created in or moved into this Space.
parent_space_id ·
stringOptional canonical parent, which MUST belong to the same actual realm_id. Cross-Realm parent is forbidden, including at creation, with failed_precondition / space_realm_mismatch. Missing or unverifiable parent evidence fails closed with space_parent_unreadable before disclosing Realm differences.
pattern:
^ak:space:[A-Za-z0-9_-]{44}$* kind ·
stringSpace kind. v1 standard kinds include 'space', 'project', 'folder', 'board', 'list', and 'topic'. Profile-defined kinds (e.g., 'swimlane', 'calendar_bucket', 'page_group') MAY be added via Realm schema/profile and MUST be registered. Unknown kind MUST schema_violation.
rank ·
stringFractional-index rank within parent. See encoding.md §9.
pattern:
^[0-9A-Za-z]{1,128}$schema_refs · array<string>
Optional schema/profile references that further constrain this Space's contained Strand types, fields, or position invariants.
items ·
stringtitle ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_256NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$summary ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/short_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$labels · array<string>
items ·
stringfields · object
Space kind-specific fields. For kind=list, wip_limit is an integer 1..100000 and wip_limit_enforcement is required with enum warn|reject|require_review whenever wip_limit is present; these are the sole write-policy source and MUST NOT be read from View. For kind=board, view_id may identify a default presentation. MUST NOT contain a 'rank' key (rank is a top-level Space field; see relation.md §2 for the symmetric Relation constraint and forbidden-wire-fields.json `fields.rank/space_payload`).
wip_limit ·
integerwip_limit_enforcement ·
string (enum)enum:
"warn" "reject" "require_review"avatar_blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$encrypted_metadata · object · $ref ./encrypted-envelope.schema.json
Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.
* version ·
const "1.0"enum:
"1.0"* content_type ·
stringpattern:
^[a-z0-9.+-]+/[a-z0-9.+-]+$* encryption_context ·
$ref #/$defs/encryption_context · $ref #/$defs/encryption_context* ciphertext ·
stringpattern:
^[A-Za-z0-9_-]+$state ·
string (enum)Space lifecycle state. 'active' is the default. State transitions are reducer-enforced per common-fields.md §5.1: ak.space.archive MUST come from state=='active' (else failed_precondition reason=space_not_active); ak.space.restore MUST come from state=='archived' (else failed_precondition reason=space_not_archived); ak.space.tombstone MUST come from {'active','archived'} AND must have no live dependents (failed_precondition reason=space_already_terminal for terminal source, space_has_live_dependents for live refs). Same-state self-transitions (archive on archived, etc.) MUST fail; clients re-archive by restore-then-archive. Tombstoned is irreversible (MUST NOT be restored). The transition timestamp lives on the writing Event and on state_changed_at.
enum:
"active" "archived" "tombstoned"state_changed_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampTimestamp of the most recent state transition. Required when state != 'active'.
* created_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampupdated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idupdated_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[6] · object · $ref #/$defs/message_reactions_result
Registered projection of one reaction target. models/strand-and-message.md section 9.8.3 is authoritative and says this family is a keyed-set projection of the closed enum in models/common-fields.md section 2, whose join that section defines: ak.reaction.add and ak.reaction.remove each project exactly one keyed_set_add, so a remove is itself an asserted element rather than an explicit revocation. The (target_ref, key, members[], count) summary of that section is the default view folded above this set, never the stored value.
* selector · object
Section 9.8 keys the set per target: the subject is the reacted-to object, and the payload carries no other target field. v1 core additionally requires an ak:message: target in the same effective scope (section 9.8.2), which a reducer enforces on admission; profiles MAY register further reactable kinds, so the wire type stays the generic object_ref of reaction_payload.
* kind ·
const "message_reactions"enum:
"message_reactions"* target_ref ·
string · $ref ./event-payload.schema.json#/$defs/object_refpattern:
^((?:ak:realm:[A-Za-z0-9_-]{44}|ak:(circle|space|actor_profile|strand|message|morph|relation|view|event|grant|invite|call|report):[A-Za-z0-9_-]{44}|ak:(policy|blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})|ak:blob:(sha256|blake3):[0-9a-f]{64}|did:[^\s]+|(sha256|blake3):[0-9a-f]{64})$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/message_reactions_value
Closed value of the message_reactions typed current result: the canonically sorted dot set of reaction assertions on one target. The join is the keyed-set union of models/common-fields.md section 2, which stays commutative, associative and idempotent; remove-wins convergence is a default-view fold above it and MUST NOT be implemented as a sixth state model. The set keeps both sides of a concurrent (add, remove) pair because models/strand-and-message.md section 9.8.3 requires the audit view to rebuild them.
* assertions · array<$ref #/$defs/reaction_assertion_entry>
items · object · $ref #/$defs/reaction_assertion_entry
One asserted element of the message_reactions keyed set. The tag is the canonical dot of the accepted Event write that produced it; the value is the complete reaction payload of that Event. The asserting actor and the polarity -- whether this is an add or a remove -- are deliberately NOT element fields: section 9.8.3 reads both from the signed envelope of the Event the dot names, because event-and-patch.md section 2.4.2 forbids a projection from assembling, renaming or trimming fields.
* tag_id ·
string · $ref #/$defs/canonical_event_dotStable tag of one registered reducer write: the canonical <event_id>:<write_index> dot of zh/models/event-and-patch.md section 2.4.2. A bare event_id is never a valid tag. Canonical dot-set order compares the complete event_id by unsigned UTF-8 bytes, then write_index as an integer (2 before 10). Index encoding has no leading zeros. Duplicate dots and conflicting values for one dot are rejected; sorting is not winner or causal ordering.
pattern:
^ak:event:[A-Za-z0-9_-]{44}:(0|[1-9][0-9]{0,2})$* value · object · $ref ./event-payload.schema.json#/$defs/reaction_payload
Reducer input for ak.reaction.add and ak.reaction.remove. The typed current result is a core authority-ordered keyed set of reaction assertions and both kinds project one keyed_set_add; default-view membership is keyed on (actor_id, target_ref, key), and a remove tombstones every add from the same actor with the same key that is not strictly causally later than it, which includes the adds concurrent with it. See zh/models/strand-and-message.md §9.8 for the authoritative Reaction model (target scope, authority-ordered keyed set, authz, anti-abuse) and zh/crypto-media/encryption-and-audit.md §2.8 for the plaintext-vs-encrypted policy.
allOf · allOf[0] ·
?* target_ref ·
$ref #/$defs/object_ref · $ref #/$defs/object_ref* key ·
stringReaction key. Plaintext scopes SHOULD use a single Unicode emoji cluster or registered short tag. End-to-end-encrypted scopes MUST carry the v1 keyed-HMAC routing tag here and carry the equivalent base64url tag in encrypted_payload.encryption_context.routing_context. The exact standard MLS derivation is routing_root[N] = MLS-Exporter("ak.reaction-routing-root-v1", canonical_effective_scope_key_bytes(effective_scope), KDF.Nh), then ExpandWithLabel(routing_root[N], "ak.reaction-routing-v1", JCS({effective_scope,target_ref,routing_window}), 32), followed by HMAC-SHA256 over NFC(canonical_emoji). routing_window is derived from outer Event.created_at and does not require an hourly MLS Commit. See zh/crypto-media/encryption-and-audit.md §2.8. The canonical emoji travels only in encrypted_payload.
annotation ·
stringOptional free-form annotation (e.g. issue triage label). MUST be omitted when `encrypted_payload` is present; in E2EE realms the annotation MUST instead be carried inside `encrypted_payload`.
encrypted_payload ·
$ref #/$defs/encrypted_envelope · $ref #/$defs/encrypted_envelopeEncrypted carrier for the canonical reaction key and any annotation in E2EE realms. The decrypted plaintext JSON MUST validate as #/$defs/reaction_encrypted_payload_plaintext. When present, outer plaintext `key` MUST be the routing tag and `annotation` MUST be omitted; service-side authority-ordered keyed set convergence still uses the outer routing key.
oneOf · oneOf[7] · object · $ref #/$defs/relation_result
The single Relation current value for one registered primary conflict domain (zh/models/relation.md section 6). Realm comes from the accepted Event envelope. The value retains its event-derived RelationId and immutable domain identity; create/update/tombstone all address this same subject and use exact revision CAS.
* selector · object
* kind ·
const "relation"enum:
"relation"* primary_conflict_domain · object · $ref ./relation.schema.json#/$defs/relation_primary_conflict_domain
The unique typed-current-result subject for one directly writable Relation domain. Realm comes from the Event envelope and Circle is not a key component. domain_kind MUST equal the matching relation-kind-registry.json shape's registered primary_conflict_domain: tuple keys on (relation_kind, from_ref, to_ref), while from keys on (relation_kind, from_ref). truth_source shapes have no directly writable Relation domain.
allOf · allOf[0] ·
?* domain_kind ·
string (enum)enum:
"tuple" "from"* relation_kind ·
stringThe current Relation's create-locked relation_kind. It MUST resolve to a directly writable relation-kind-registry.json shape whose registered primary_conflict_domain equals domain_kind; a derived_projection shape is rejected with schema_violation (reason=relation_kind_contains_derived / relation_kind_watches_derived).
* from_ref ·
$ref #/$defs/relation_endpoint · $ref #/$defs/relation_endpointto_ref ·
$ref #/$defs/relation_endpoint · $ref #/$defs/relation_endpointPresent exactly when domain_kind=tuple. A from domain already identifies the single current Relation for the from_ref, so carrying to_ref there would create a second spelling of the subject.
* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./relation.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?id ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:relation:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.relation.v1"enum:
"ak.schema.relation.v1"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$scope_circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idOptional intra-Realm Circle (models/circle.md) defining this Relation fact's effective scope, supplied in the submit payload. For confidential_discussion_of it points to the private Strand's Circle. For structural relations the resulting effective_scope MUST NOT be wider than the narrowest participating endpoint scope (circle.md §6.1). Sidecar context mappings are native sidecar.context typed results, not Relation objects.
pattern:
^ak:circle:[A-Za-z0-9_-]{44}$effective_scope ·
$ref #/$defs/effective_scope · $ref #/$defs/effective_scopeRead-only immutable effective scope of this Relation fact, materialized from the accepted Event.scope_ref after the receiver verifies it against scope_circle_id and endpoint pre-state (circle.md §6.1-§6.2). For structural relations it MUST NOT be wider than the narrowest participating endpoint scope. It remains immutable across any later scope rebind and MUST NOT appear in actor-supplied content payload (reason=effective_scope_reducer_managed).
* relation_kind ·
stringRelation semantic. The standard kind vocabulary (kind list, cardinality class, truth-source class, weak_semantic flag) is machine-indexed in artifacts/registry/relation-kind-registry.json; detailed dedupe/scope/conflict semantics in models/relation.md §3-§6. Cross-Realm constraint: the current governance Station's authoritative reducer MUST resolve both endpoints and reject structural relations 'contains' and 'belongs_to' when either endpoint realm differs from this Relation realm, with failed_precondition reason cross_realm_structural_relation and zero commit/projection effect; producer or SDK prechecks are non-authoritative. weak_semantic=true kinds per the registry MAY cross Realm subject to two-sided authorization. Stays a free string so extension profiles can add kinds; unregistered kinds are opaque edges (unknown_relation_kind), never container/visibility semantics.
* from_ref ·
$ref #/$defs/relation_endpoint · $ref #/$defs/relation_endpoint* to_ref ·
$ref #/$defs/relation_endpoint · $ref #/$defs/relation_endpointrank ·
$ref #/$defs/rank · $ref #/$defs/rankTop-level rank string for ordered relations (e.g. contains-list-strand position). Encoding follows the ak.rank.lexofractional.v1 grammar in zh/conformance/encoding.md section 9.1. Aligned with Space.rank so all rank-bearing canonical objects expose rank at the top level instead of fields.rank.
fields ·
objectEdge metadata. MUST NOT contain a 'rank' key — rank moved to the top level in v1 to align with Space.rank.
state ·
string (enum)Relation state. 'tombstoned' covers both deletion and redaction; the originating reason is preserved on the ak.relation.tombstone / ak.redaction event, not on the materialized object.
enum:
"active" "tombstoned"state_changed_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampReducer-derived timestamp of the most recent state transition. MUST be set when state != 'active'; MUST be the created_at of the corresponding ak.relation.tombstone / redaction Event. Aligns with Space.state_changed_at and the common-fields rule in models/common-fields.md §3.
* created_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampupdated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idupdated_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[8] · object · $ref #/$defs/mls_group_result
* selector · object
* kind ·
const "mls_group"enum:
"mls_group"* scope_ref · oneOf[4] · $ref ./event-envelope.schema.json#/$defs/scope_ref
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind ·
const "realm_genesis"enum:
"realm_genesis"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/mls_group_value
* effective_scope · oneOf[4] · $ref ./event-envelope.schema.json#/$defs/scope_ref
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind ·
const "realm_genesis"enum:
"realm_genesis"* genesis_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* cipher_suite ·
string · $ref ./event-payload.schema.json#/$defs/non_empty_string* current_mls_commit_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* epoch ·
integer* current_key_access_revision ·
integer* covered_key_access_revision ·
integer* public_tree_ref ·
string · $ref ./common-ids.schema.json#/$defs/blob_refContent-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern:
^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$oneOf · oneOf[9] · object · $ref #/$defs/agent_key_result
Registered reducer projection of one Agent signing key. It is the single state source a portable state witness may quote; a service-private key table is not an alternative.
* selector · object
Composite subject derived from (agent_id, agent_key_id). Producers MUST NOT spell it by string concatenation.
* kind ·
const "agent_key"enum:
"agent_key"* agent_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* agent_key_id ·
string · $ref ./event-payload.schema.json#/$defs/agent_key_idStable key identifier within the agent DID. Prefer the DID URL verification method id when available.
pattern:
^(did:[a-z0-9]+:[^\s#]+#[^\s#]+|[a-zA-Z0-9._:-]{1,256})$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/agent_key_value
Closed value of the agent_key typed current result.
* authorizations · array<$ref #/$defs/agent_key_authorization_entry>
Canonically sorted active tagged-set entries. A revoke entry is a witnessed revocation boundary marker, never an active authorization.
items · object · $ref #/$defs/agent_key_authorization_entry
One tagged entry of the agent_key typed current result. The tag is the canonical dot of the accepted Event write that produced it; the value is the complete authorize or revoke payload of that Event.
* tag_id ·
string · $ref #/$defs/canonical_event_dotStable tag of one registered reducer write: the canonical <event_id>:<write_index> dot of zh/models/event-and-patch.md section 2.4.2. A bare event_id is never a valid tag. Canonical dot-set order compares the complete event_id by unsigned UTF-8 bytes, then write_index as an integer (2 before 10). Index encoding has no leading zeros. Duplicate dots and conflicting values for one dot are rejected; sorting is not winner or causal ordering.
pattern:
^ak:event:[A-Za-z0-9_-]{44}:(0|[1-9][0-9]{0,2})$* value · oneOf[2]
oneOf · oneOf[0] · object · $ref ./event-payload.schema.json#/$defs/agent_key_authorize_payload
Payload for ak.agent.key.authorize. Binds one concrete agent signing key to an accountable principal, explicit agent_key_scope, audience, validity window, approval evidence, and both the service-surface and content-capability ceilings that later agent_key_proof sessions must narrow from.
* agent_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* key_id ·
$ref #/$defs/agent_key_id · $ref #/$defs/agent_key_id* verification_method ·
$ref #/$defs/verification_method · $ref #/$defs/verification_method* public_key · object · $ref ./agent-operations.schema.json#/$defs/agent_runtime_public_key
Closed v1 Agent runtime signing-key profile. Ed25519 is the fully-specified JOSE algorithm identifier from RFC 9864; polymorphic algorithm identifiers are rejected.
* kty ·
const "OKP"enum:
"OKP"* kid ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string* algorithm ·
const "Ed25519"enum:
"Ed25519"* key ·
stringpattern:
^[A-Za-z0-9_-]{43}$* accountable_principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* agent_key_scope ·
$ref #/$defs/agent_key_scope · $ref #/$defs/agent_key_scope* audience ·
$ref #/$defs/string_list · $ref #/$defs/string_list* issued_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampexpires_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampOptional: absent means the key authorization is non-expiring and governed solely by revocation (ak.agent.key.revoke / lifecycle cascade).
* approval_evidence ·
$ref #/$defs/agent_key_approval_evidence · $ref #/$defs/agent_key_approval_evidencesupersedes · array<object>
Exact complete active authorization set at expected_revision and first acceptance, sorted byte-lexicographically by (key_id, authorized_event_ref). Omit exactly when the active set is empty, including after revoke. Each authorization Event identifies its registered add dot. Same-key reauthorization uses the same exact-set rule. Remove the observed old-key typed results atomically and add the new authorization; never infer authority from historical row presence or map overwrite.
items · object
* key_id ·
…recursion truncated at depth 8; see source schema for full shape
* authorized_event_ref ·
…recursion truncated at depth 8; see source schema for full shape
revocation_check_ref ·
$ref #/$defs/object_ref · $ref #/$defs/object_refOptional freshness source for revocation checking. When expires_at is absent, authorization lifetime is governed by the canonical revocation chain and lifecycle cascade; this field may identify the freshness source used for that check.
runtime_attestation · object
Optional runtime / workload attestation captured at pairing approval time. v1 enum includes self_asserted as baseline; future profiles MAY register TEE / SLSA / SPIFFE attestation kinds. Implementations encountering an unknown kind MUST fail closed.
* kind ·
string (enum)v1 enum. Future profiles MAY extend via accepted attestation taxonomy.
enum:
"self_asserted"software ·
stringversion ·
stringattestation_ref ·
string · $ref ./common-ids.schema.json#/$defs/blob_refContent-addressed reference to exact Blob bytes. The embedded suite and digest are the sole wire commitment to those bytes; sibling content/ciphertext digest mirrors are forbidden.
pattern:
^ak:blob:(?:sha256|blake3):[0-9a-f]{64}$oneOf · oneOf[1] · object · $ref ./event-payload.schema.json#/$defs/agent_key_revoke_payload
Payload for ak.agent.key.revoke. The keyed-set projection typed current result subject is (agent_id, key_id); future protocol proofs from this key fail closed once this event is covered by an accepted RealmCommit. The authoring checkpoints is the current authority-committed state; the payload carries no checkpoint field.
* agent_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* key_id ·
$ref #/$defs/agent_key_id · $ref #/$defs/agent_key_id* revoked_by ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* revoked_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampreason ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/audit_reason_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$oneOf · oneOf[10] · object · $ref #/$defs/agent_status_result
Registered Agent lifecycle projection. The first active value has exactly one provenance: the delegated PCR genesis ak.realm.create conditional write of zh/models/realm-and-space.md section 2.5.1.
* selector · object
* kind ·
const "agent_status"enum:
"agent_status"* agent_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value ·
string (enum)enum:
"uninitialized" "active" "paused" "deactivated"oneOf · oneOf[11] · object · $ref #/$defs/realm_genesis_result
Singleton create-locked identity/security core. Written once by the registered ak.realm.create result write (zh/models/realm-and-space.md section 2.5.1); the value is the closed ak.schema.realm_genesis.v1 object.
* selector · object
* kind ·
const "realm_genesis"enum:
"realm_genesis"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./realm-genesis.schema.json
allOf · allOf[0] ·
?founding_device_descriptor is exclusive to human Principal Control Realm genesis. agent_control, collaboration and direct_conversation genesis MUST omit it. genesis_salt is required for every purpose since PCR genesis is event-derived like any other Realm.
allOf · allOf[1] ·
?Only identity-control Realm genesis carries initial_resolution, and every such genesis carries it. Collaboration/direct-conversation Realms MUST omit it.
allOf · allOf[2] ·
?Human Principal Control Realm genesis uses the independently closed human-principal DID method set.
allOf · allOf[3] ·
?Agent PCR genesis commits the already accepted did:webvh inception head. The later PCR service binding update is continuous from this head and does not participate in the create Event preimage.
allOf · allOf[4] ·
?Applet-managed PCR genesis commits exactly the initial resolution already frozen by its accepted provision Event.
* schema ·
const "ak.schema.realm_genesis.v1"enum:
"ak.schema.realm_genesis.v1"* purpose ·
string (enum)enum:
"collaboration" "direct_conversation" "principal_control" "agent_control" "applet_managed_control"* genesis_salt ·
stringCanonical unpadded Base64URL encoding of exactly 32 CSPRNG octets. It distinguishes event-derived creation intents and has no replay, ordering, authorization, freshness, or winner semantics.
pattern:
^[A-Za-z0-9_-]{43}$founding_device_descriptor ·
$ref #/$defs/founding_device_descriptor · $ref #/$defs/founding_device_descriptorHuman Principal Control Realm genesis only. The identity root commits to the exact founding device material and the canonical founding authorize payload digest. The enclosing pcr_genesis_unit requires it; Agent PCR genesis MUST omit it.
initial_resolution · object · $ref ./identity-resolution.schema.json#/$defs/resolution_commitment
Owner-committed current did and method-native history position. For a deterministic method, method_history_head and version_id use the adapter-defined deterministic canonical values; they are never omitted.
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* trust_domain ·
string · $ref ./realm.schema.json#/$defs/trust_domainpattern:
^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$* security_class ·
string (enum) · $ref ./realm.schema.json#/properties/security_classOptional security class. 'high_assurance' forbids federation_policy=open and SHOULD use stricter resolver/E2EE/audit defaults. Omitted = 'standard'.
enum:
"standard" "high_assurance"* governance_station_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* initial_join_rule ·
string (enum) · $ref ./realm.schema.json#/properties/default_join_ruleenum:
"public" "invite" "knock" "restricted" "knock_restricted" "closed"* initial_history_access ·
string (enum) · $ref ./realm.schema.json#/properties/history_accessScope-local history range ratchet initialized by Realm create. Only all_history_for_current_members to since_join may change state; widening back to all_history is permanently forbidden. Standard MLS requires since_join.
enum:
"since_join" "all_history_for_current_members"* initial_discoverability ·
string (enum) · $ref ./realm.schema.json#/properties/default_discoverabilityenum:
"public" "listed" "restricted" "unlisted" "invite_only" "secret"oneOf · oneOf[12] · object · $ref #/$defs/realm_history_access_result
Singleton Realm history-access FSM current state (zh/models/realm-and-space.md section 2.5.1). Initialized by the conditional ak.realm.create write and moved only by ak.realm.history_access.
* selector · object
* kind ·
const "realm_history_access"enum:
"realm_history_access"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value ·
string (enum) · $ref ./event-payload.schema.json#/$defs/history_access_valueenum:
"since_join" "all_history_for_current_members"oneOf · oneOf[13] · object · $ref #/$defs/identity_resolution_result
Singleton Realm identity-resolution projection. The PCR reducer initialises it from the genesis object's initial_resolution on the conditional ak.realm.create write and ak.identity.resolution.update is its only post-genesis writer (zh/identity/identity-did.md section 4.2). The stored value is the five-member resolution_projection, not the three-member commitment the owner signs: resolution_event_ref and updated_at are reducer-derived from the carrying envelope and are read back off this result by section 5.
* selector · object
* kind ·
const "identity_resolution"enum:
"identity_resolution"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./identity-resolution.schema.json#/$defs/resolution_projection
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[14] · object · $ref #/$defs/identity_accountability_result
One accountability endorsement (family identity_accountability). zh/models/actor.md section 3.3.1: there is one record with two writers, and its identity is (Realm, issuer principal, subject principal, normalized exact scope set) -- the Realm component is the scope this result lives in, so it is not a selector member. A grant that changes a provision endorsement MUST be written into the original controller PCR; the same tuple in another Realm is a different record and cannot revoke this one.
* selector · object
Composite subject. Producers MUST NOT spell it by string concatenation; the registered composite derives its third component as string_set_digest(accountability_scope, ak.accountability_scope_set.v1), so the scope set carried here is the normalized set that digest is taken over.
* kind ·
const "identity_accountability"enum:
"identity_accountability"* issuer_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* subject_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* accountability_scope · array<$ref #/$defs/scope> · $ref ./accountability-grant.schema.json#/$defs/accountability_projection/properties/accountability_scope
The normalized set, always an array even when the wire form was the singleton string, deduplicated and sorted by ascending raw UTF-8 bytes. This is the same normalization the composite subject digests under ak.accountability_scope_set.v1, which is what makes a provision projection and a later independent grant address one typed current result rather than two.
items ·
$ref #/$defs/scope · $ref #/$defs/scope* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./accountability-grant.schema.json#/$defs/accountability_projection
Canonical business value of the identity_accountability typed current result. zh/models/actor.md section 3.3.1 fixes these six members and keeps two things out on purpose: the inner proof, and any source event reference. The head Event and its accepted proof already carry where this endorsement came from, so copying an event id into the value would make two endorsements that say the same thing compare unequal. Both registered writers -- the independent ak.identity.accountability_grant and ak.agent.provision's atomic accountability projection -- MUST reach this shape through a declared value_projection rather than a renaming result_projection.value.field path.
* issuer_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* subject_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* accountability_scope · array<$ref #/$defs/scope>
The normalized set, always an array even when the wire form was the singleton string, deduplicated and sorted by ascending raw UTF-8 bytes. This is the same normalization the composite subject digests under ak.accountability_scope_set.v1, which is what makes a provision projection and a later independent grant address one typed current result rather than two.
items ·
$ref #/$defs/scope · $ref #/$defs/scope* not_before ·
$ref #/$defs/timestamp · $ref #/$defs/timestampak.agent.provision derives this from the carrying envelope's created_at, which is why its admission requires payload.created_at to equal it byte-for-byte.
expires_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampOptional, and absent is the meaning rather than the absence of a meaning: the grant is non-expiring and governed by grant_status. A writer whose payload omits it MUST leave this member out; writing JSON null is not the same statement.
* grant_status ·
string (enum)enum:
"active" "revoked"oneOf · oneOf[15] · object · $ref #/$defs/capability_grant_result
Registered projection of one Capability Grant. The subject GrantId is derived by retyping the accepted ak.capability.grant Event id; the value is the complete projected grant, including reducer-inserted id and the registered derived members authority_depth / authority_root_refs (zh/authz/capabilities.md section 10).
* selector · object
* kind ·
const "capability_grant"enum:
"capability_grant"* grant_id ·
string · $ref ./common-ids.schema.json#/$defs/grant_idpattern:
^ak:grant:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./capability-grant.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* id ·
stringpattern:
^ak:grant:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.capability.v1"enum:
"ak.schema.capability.v1"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* issuer_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* subject · oneOf[2]
oneOf · oneOf[0] · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idoneOf · oneOf[1] · object
* kind ·
const "condition"enum:
"condition"* required_claims · array<object> · $ref ./grant-constraint.schema.json#/properties/required_claims
Conditional claim requirements. resource-selector-grammar.md §3.3 caps this array at 32 entries as a normative DoS guard; the schema enforces maxItems:32 so condition-selector grants cannot smuggle in unbounded claim objects.
items · object
anyOf · anyOf[0] ·
?anyOf · anyOf[1] ·
?* claim_kind ·
stringissuer_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$trusted_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$subject_matches_actor ·
booleanIf true, the credential subject did_core_id MUST match the actor did_core_id after each proof's DID is independently validated and projected through its registered method adapter.
example:
truevalue_constraints ·
objectPer-field equality / membership constraints on credential claims.
organization_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$status ·
stringroles · array<string>
items ·
string* actions · array<string>
items ·
stringCanonical action vocabulary. MUST be of the form ak.<segment>.<segment>... matching capabilities.md §5. Bare names without the ak. prefix are not permitted; consult capabilities.md before introducing new action names. Wildcards within a segment are not permitted in this schema; the resource selector controls scope, not action expansion.
pattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$* resources · array<$ref ./resource-selector.schema.json>
items · object · $ref ./resource-selector.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?* kind ·
string (enum)enum:
"realm" "space" "circle" "strand" "message" "morph" "object" "relation" "view" "event" "actor" "schema" "policy" "invite" "notification" "read_cursor" "blob" "*"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$space_id ·
stringpattern:
^ak:space:[A-Za-z0-9_-]{44}$circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$object_kind ·
stringobject_ref ·
stringCanonical object reference. Acceptable typed-id kinds match the v1 resource selector kind enum (see resource-selector-grammar.md §3.1). Notably MUST NOT include 'actor_profile' (use the 'actor' selector with did pattern), nor non-canonical 'board' / 'list' / 'card' / 'subject' / 'room' kinds — board / list / swimlane / calendar bucket are Space objects and MUST use the 'space' kind together with the 'allowed_space_kinds' constraint to restrict which Space kinds the grant covers.
pattern:
^(?:ak:realm:[A-Za-z0-9_-]{44}|ak:(space|circle|strand|message|morph|relation|view|event|invite):[A-Za-z0-9_-]{44}|ak:(policy|blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})$strand_id ·
stringpattern:
^ak:strand:[A-Za-z0-9_-]{44}$message_id ·
stringpattern:
^ak:message:[A-Za-z0-9_-]{44}$morph_id ·
stringpattern:
^ak:morph:[A-Za-z0-9_-]{44}$morph_kind ·
stringrelation_kind ·
stringrelation_id ·
stringpattern:
^ak:relation:[A-Za-z0-9_-]{44}$view_id ·
stringpattern:
^ak:view:[A-Za-z0-9_-]{44}$event_id ·
stringpattern:
^ak:event:[A-Za-z0-9_-]{44}$actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idschema_ref ·
stringpolicy_id ·
stringpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$invite_id ·
stringpattern:
^ak:invite:[A-Za-z0-9_-]{44}$blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$match_scope ·
string (enum)Authorization selector breadth. exact matches only the named resource; realm_wide is valid only for the registered resource kinds with an explicit realm_id. Neither current navigation ancestry nor creation ancestry expands authorization. Hierarchy traversal belongs to queries, not grant matching. The normative algorithm is zh/authz/resource-selector-grammar.md section 6.
enum:
"exact" "realm_wide"constraints · array<$ref ./grant-constraint.schema.json>
Constraints applied to this grant. Re-grant control MUST be expressed via constraint_kind='authority_control' and max_authority_depth (see capabilities.md §10). A top-level 'delegable' field is forbidden and MUST be rejected as schema_violation. With no authority_control constraint the grant cannot be re-granted (equivalent to max_authority_depth=0).
items · object · $ref ./grant-constraint.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
?allOf · allOf[6] ·
?allOf · allOf[7] ·
?allOf · allOf[8] ·
?allOf · allOf[9] ·
?allOf · allOf[10] ·
?allOf · allOf[11] ·
?allOf · allOf[12] ·
?allOf · allOf[13] ·
?allOf · allOf[14] ·
?constraint_id ·
stringOptional stable identifier of this constraint within the grant; used for diagnostics and overrides.
pattern:
^(?!ak:)* constraint_kind ·
string (enum)Constraint family discriminator. v1 collapses what were 15 types into 8 by absorbing narrowly-scoped types into their conceptual parent: edit_window → temporal; container_move → scope_limitation; rate_limiting + resource_limit → quota; approval_workflow + accountability + device_session → claim_based (with constraint_subkind); encryption_requirement + visibility_control → confidentiality (with constraint_subkind). Use the optional 'constraint_subkind' field to indicate the original specialization where evaluation logic differs.
enum:
"temporal" "field_access" "kind_restriction" "scope_limitation" "authority_control" "quota" "claim_based" "confidentiality"* effect ·
string (enum)enum:
"allow" "deny" "quarantine" "require_review"evaluation_class ·
string (enum)Cacheability/dependency hint for the authorization evaluator. stateless = pure function of (constraint, op, now); grant_local = depends on the grant object only; realm_state = depends on the exact Realm authority revision (membership, policy_version, etc.); external = depends on data outside that authority state (claim revocation status, rate-limit counts, async approval). Each constraint_kind has a canonical evaluation_class declared in constraint-schema.md §2.3; implementations MAY tighten (e.g. grant_local → stateless) but MUST NOT loosen (e.g. external as stateless). Auth evaluators SHOULD use this hint to gate fast-path caching.
enum:
"stateless" "grant_local" "realm_state" "external"constraint_subkind ·
string (enum)Optional discriminator within a constraint_kind. Standard values: claim_based.{claim,approval,accountability}; quota.{rate,resource}; confidentiality.{encryption,visibility}; temporal.{window,edit_window,redact_window,session}; authority_control.{applet_authority}. Per constraint-schema.md §2.2, device/session binding is NOT an independent constraint_subkind: it is the claim_based constraint_subkind=claim sub-case expressed via an accepted PCR device issuer. Implementations MAY require constraint_subkind for these families and fail closed on unknown values.
enum:
"claim" "approval" "accountability" "rate" "resource" "encryption" "visibility" "window" "edit_window" "redact_window" "session" "applet_authority"applies_to_actions · array<string>
Optional restriction of a temporal constraint to specific capability actions (e.g. ['ak.message.revise.own', 'ak.message.redact.own']). Action mismatch is neutral in the effect fold: satisfied for effect=allow and not matched for deny/quarantine/require_review.
items ·
stringpattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$not_before ·
$ref #/$defs/timestamp · $ref #/$defs/timestampexpires_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamprecurrence · object
Recurrence rule for temporal constraints. Used by constraint-schema.md §3.1.
frequency ·
string (enum)enum:
"daily" "weekly" "monthly" "custom"days · array<string (enum)>
items ·
string (enum)enum:
"mon" "tue" "wed" "thu" "fri" "sat" "sun"window_start ·
stringpattern:
^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$window_end ·
stringpattern:
^([01][0-9]|2[0-3]):[0-5][0-9](:[0-5][0-9])?$timezone ·
stringmax_duration ·
stringISO 8601 duration.
pattern:
^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$max_session_duration ·
stringpattern:
^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$inactivity_timeout ·
stringpattern:
^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$expires_after ·
stringISO 8601 duration; used by approval_workflow constraint instead of expires_after_ms.
pattern:
^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$message_edit_window ·
stringpattern:
^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$message_redact_window ·
stringpattern:
^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$redact_after_window_allowed ·
booleancondition · object
Conditional predicate for field_access and similar constraints. The `kind` value is a registered named condition from constraint-schema.md §4.1; unknown kinds MUST fail closed. Implementations MUST NOT introduce ad hoc string DSL predicates.
* kind ·
string (enum)enum:
"object_is_owned_by_actor" "actor_is_assignee" "actor_is_responsible" "actor_is_guardian" "actor_is_controller" "object_in_actor_container" "object_is_unencrypted" "object_is_encrypted" "always" "never"allowed_write_fields · array<string>
items ·
stringdenied_write_fields · array<string>
items ·
stringallowed_read_fields · array<string>
items ·
stringdenied_read_fields · array<string>
items ·
stringsensitive_fields · array<string>
items ·
stringsensitive_handling ·
string (enum)enum:
"redact" "hash" "omit"allowed_object_kinds · array<string>
items ·
stringdenied_object_kinds · array<string>
items ·
stringallowed_morph_kinds · array<string>
items ·
stringdenied_morph_kinds · array<string>
items ·
stringallowed_space_kinds · array<string>
Allowed Space kinds (e.g. 'board', 'list', or profile-registered kinds like 'swimlane', 'calendar_bucket'). Reducer/profile MUST validate kind value.
items ·
stringdenied_space_kinds · array<string>
items ·
stringallowed_facets · array<string (enum)>
items ·
string (enum)enum:
"container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"denied_facets · array<string (enum)>
items ·
string (enum)enum:
"container" "replyable" "schedulable" "assignable" "stateful" "rankable" "reviewable" "notifiable" "documentable" "renderable"allowed_view_ids · array<string>
items ·
stringpattern:
^ak:view:[A-Za-z0-9_-]{44}$allowed_strand_ids · array<string>
items ·
stringpattern:
^ak:strand:[A-Za-z0-9_-]{44}$denied_strand_ids · array<string>
items ·
stringpattern:
^ak:strand:[A-Za-z0-9_-]{44}$allowed_space_ids · array<string>
items ·
stringpattern:
^ak:space:[A-Za-z0-9_-]{44}$denied_space_ids · array<string>
items ·
stringpattern:
^ak:space:[A-Za-z0-9_-]{44}$allowed_circle_ids · array<$ref ./common-ids.schema.json#/$defs/circle_id>
Limits Circle-scoped capability actions to the listed Circle ids. Used by ak.circle.manage / ak.circle.member.manage style grants; unconstrained Realm-wide Circle management grants are not a normal permission shape.
items ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$allowed_session_ids · array<string>
Limits applet interop-session operations to the listed applet-defined session correlation ids.
items ·
stringpattern:
^(?!ak:)allowed_view_kinds · array<string>
items ·
stringallowed_view_renderers · array<string>
items ·
stringdenied_view_kinds · array<string>
items ·
stringdenied_view_renderers · array<string>
items ·
stringallowed_relation_kinds · array<string>
items ·
stringallowed_from_container_refs · array<string>
items ·
stringpattern:
^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$allowed_to_container_refs · array<string>
items ·
stringpattern:
^ak:(space|strand|morph):[A-Za-z0-9_-]{44}$wip_limit_override ·
booleanexample:
falseallowed_tracks · array<string>
items ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$denied_tracks · array<string>
items ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$blob_presign_scope · object
Scope limiter for ak.self.blob.command.presign.v1 grants: allowed purposes plus optional blob/realm restrictions.
* allowed_purposes · array<string (enum)>
items ·
string (enum)enum:
"media_inline" "thumbnail" "download"blob_ref_pattern ·
stringrealm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
items ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$allowed_data_labels · array<string>
Data classification labels this grant may read, export, transform, or send to external endpoints.
items ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$allowed_endpoints · array<string>
Allowed outbound endpoint origins or deployment-approved endpoint patterns for applet / agent / connector operations.
items ·
stringmax_authority_depth ·
integerMaximum remaining authority hops. Bounded by the canonical authority-chain depth ceiling (4) defined in zh/conformance/scalability-constraints.md §3 and zh/authz/capabilities.md §10.2; reducers MUST reject grants declaring a larger value at accept time rather than only truncating during DFS.
authority_path_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$authority_regrant_allowed ·
booleanauthority_scope ·
string (enum)enum:
"narrowing_only" "same_scope" "custom"applet_id ·
string · $ref ./common-ids.schema.json#/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idregistration_epoch ·
stringauthority_control(constraint_subkind=applet_authority) binding to the canonical Applet registration epoch.
pattern:
^sha256:[0-9a-f]{64}$blob_max_bytes ·
integerblob_presign_max_ttl_seconds ·
integerMaximum TTL, in seconds, that this grant permits for ak.blob.presign. The service must clamp requested max_age_seconds to the smaller of this value and deployment policy.
max_total_blob_bytes ·
integermax_artifact_bytes ·
integerMaximum artifact size in bytes for applet / agent / export operations.
max_operations ·
integerMaximum number of distinct accepted idempotency identities in one UTC epoch-aligned fixed period. Enforcement is a linearizable check-and-reserve at one logical quota authority shared by every node in the enforcing service; per-node duplicated budgets and overshoot are forbidden.
period ·
stringISO 8601 duration. For quota constraints, a stricter conditional schema permits only a non-zero fixed-length week/day/hour/minute/second duration; year/month durations are forbidden so every authority derives the same UTC epoch-aligned window id.
pattern:
^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$burst ·
integerOptional token-bucket capacity at the same logical quota authority, capped by max_operations and refilled at max_operations/period. It never increases the fixed-window total budget.
constraint_scope ·
string (enum)Closed v1 quota counting scope. Unknown values are schema violations and MUST fail closed. Quota counters are actor-bound; the enum selects the additional slicing dimension: actor only, actor+space, actor+realm, or actor across all nodes/regions of the enforcing service's global quota domain. global is not an implicit federation-wide counter. Every node in the service domain MUST share one logical linearizable quota authority.
enum:
"per_actor" "per_space" "per_realm" "global"max_resources ·
integerresource_kind ·
stringapproval_required ·
booleanapproval_mode ·
string (enum)The only approval mode of v1. The approved write MUST NOT take effect before the approval evidence is verified and accepted in the same transaction (zh/authz/constraint-schema.md section 9.2.7). There is no second mode and no path that first materializes a proposal object and then approves that object.
enum:
"before_commit"approval_actor_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$approval_relation ·
string (enum)Responsibility classification of this grant explicit approval_actor_ids roster. It never creates a second dynamic roster or supplies action/scope capability. Missing explicit roster cannot satisfy approval.
enum:
"responsible" "controller" "guardian" "realm_admin" "custom"timeout ·
stringPositive fixed ISO 8601 duration (week/day/hour/minute/second, no calendar year/month). Each approval vote is valid only when the target covering committed_at <= that vote input.approved_at + timeout, inclusive and with zero tolerance. The same rule applies to Event and operation targets; receiver clocks and first-seen timestamps never anchor it. Omission adds no grant-local age limit.
pattern:
^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$approval_threshold · oneOf[2]
Closed executable vote threshold: majority means floor(N/2)+1, unanimous means N, and a positive integer is the exact quorum. N is the distinct eligible approver set at the accepting authority cut. Omission means unanimous. A missing or empty eligible set, or an integer greater than N, cannot satisfy approval. Repeated signatures by one approver count once. Parameterless quorum/custom strings are schema violations.
example:
"unanimous"oneOf · oneOf[0] ·
string (enum)enum:
"majority" "unanimous"oneOf · oneOf[1] ·
integeraccountability_required ·
booleanguardian_approval_required ·
booleancontroller_approval_required ·
booleanrequired_claims · array<object>
Conditional claim requirements. resource-selector-grammar.md §3.3 caps this array at 32 entries as a normative DoS guard; the schema enforces maxItems:32 so condition-selector grants cannot smuggle in unbounded claim objects.
items · object
anyOf · anyOf[0] ·
?anyOf · anyOf[1] ·
?* claim_kind ·
stringissuer_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$trusted_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$subject_matches_actor ·
booleanIf true, the credential subject did_core_id MUST match the actor did_core_id after each proof's DID is independently validated and projected through its registered method adapter.
example:
truevalue_constraints ·
objectPer-field equality / membership constraints on credential claims.
organization_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$status ·
stringroles · array<string>
items ·
stringtrusted_claim_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$claim_refresh_required ·
booleanclaim_max_age ·
stringpattern:
^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$allowed_history_access_values · array<string (enum)>
items ·
string (enum)enum:
"since_join" "all_history_for_current_members"redacted_history_allowed ·
booleanencryption_required ·
booleanmin_encryption_level ·
string (enum)confidentiality(constraint_subkind=encryption) static floor: the minimum content-encryption mechanism the grant requires. Pure static declaration evaluated as stateless unless cross-checked against the scope's current MLS activation state (see constraint-schema.md section 12).
enum:
"none" "mls_rfc9420" "external"plaintext_fallback_allowed ·
booleanconfidentiality(constraint_subkind=encryption) static flag: whether the grant permits plaintext in a scope that has no accepted ak.mls.genesis. After activation the flag cannot restore plaintext; the write MUST be rejected with mls_activation_irreversible. See constraint-schema.md §12.
audit_trail_required ·
booleanconfidentiality(constraint_subkind=encryption) static flag: whether the grant requires an audit trail (e.g. active Audit Applet Binding). See constraint-schema.md §12.
key_rotation_period ·
stringpattern:
^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$max_key_age ·
stringpattern:
^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$key_backup_required ·
booleanapproved_key_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$depends_on_moderation_state ·
booleanCache-invalidation hint: when true, this grant's authorization decisions depend on the moderation_state typed current result (see capabilities.md §18.1) and the grant's cache entry MUST be invalidated when that typed current result changes. Default false: ordinary grants (ak.strand.update / ak.message.create / organization membership grants) do NOT take a cache hit on every moderation decision. v1 capabilities.md §18.1 lists three conditions where MUST be explicitly true (moderator-role grants, condition-selector subjects referencing moderation state, constraints referencing moderation queue / typed current result). Schema-side enforcement of condition (2) is in capability-grant.schema.json via if/then on actions[]; conditions (1) and (3) are reducer-side lint. Cache invalidation hint outside the eight constraint families; it does not participate in allow/deny evaluation and is documented in capabilities.md §6 / constraint-schema.md.
allowed_managed_actor_roles · array<string (enum)>
Ordinary authority_control permits only these accepted roles of the Applet bound by the parent applet_authority constraint; no arbitrary third-party regrant.
items ·
string (enum)enum:
"bot" "ghost"(^x_[a-z][a-z0-9_]{0,63}$) ·
any* issued_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* status ·
string (enum)Reducer-derived lifecycle status of this Grant (zh/authz/capabilities.md section 12.1). It is absent from the closed authoring body of ak.capability.grant and is materialised by the registered capability_status derivation, so an author-supplied value MUST be rejected rather than trusted. The two terminal values stay distinct because section 10.4 gives them different authorities: revoke is issuer or root-controller authority, relinquish is the target subject's own signature and MUST NOT require ak.capability.revoke. Collapsing them into revoked_at alone would erase which authority closed the Grant. A terminal value is final -- section 12.1 forbids resurrecting a closed grant_id -- and compaction MUST preserve it.
enum:
"active" "revoked" "relinquished"updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idupdated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$revoked_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idrevoked_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* issuer_authority_refs · array<oneOf[3]>
The signed semantic authority lineage this grant was issued under. A root controller's grant anchors on the accepted Realm authority Event; any further grant anchors on grants its issuer already holds. These closed refs intentionally carry no producer-selected current-result revision, authorization-state digest, Station id or commit basis: the governing Station resolves their current typed results at acceptance, fails closed when current authority cannot be proved fresh, and records the accepting RealmCommit as the decision basis. Authorization is recomputed from these refs on every decision, so revoking an ancestor invalidates its descendants without a cascading write. The sole owned_agent ref is an explicit non-regrant exception; it pins ownership membership and continuously bounds the Agent by current controller authority.
items · oneOf[3]
oneOf · oneOf[0] · object
A grant the issuer holds. The issuer MUST be that grant's subject, and the ref MUST be active both at acceptance and evaluation time; its capability, resources and constraints all bound this child. Its current-result revision is an acceptance-time Station input, not a signed wire member.
* kind ·
const "grant"enum:
"grant"* grant_id ·
string · $ref ./common-ids.schema.json#/$defs/grant_idpattern:
^ak:grant:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
A committed authority root in the same Realm as the grant. It is terminal for cycle checks. The accepting Station verifies the named Event/controller/generation against durable current authority; the ref does not carry a Station-local commit wrapper.
* kind ·
const "realm_root"enum:
"realm_root"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* authority_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* authority_generation ·
integerRealm authority-root delegation generation at issuance, read from the realm_authority_root typed current result. A ref stays valid only while that value's current authority_generation still equals this one, and the read MUST use the registered inclusion proof at a RealmCommit basis, never an unproven cache. ak.realm.authority.reset is the only kind that advances it, so it is the only act that invalidates a whole delegated generation; ak.realm.owner.transfer preserves it and therefore leaves every child grant valid. This is NOT the governing Station tenure, which is governance_generation on RealmCommit -- a planned Station handoff MUST NOT invalidate any grant.
oneOf · oneOf[2] ·
$ref #/$defs/owned_agent_authority_ref · $ref #/$defs/owned_agent_authority_ref* authority_depth ·
integerReducer-derived absolute distance from the authority root: a realm_root ref counts 0, so a root controller's grant is 1 and a member's re-grant is 2. Derived from the refs, never author-declared, so it cannot be misreported — which is what makes it safe to answer 'how far did this authority spread' with a single field instead of a recursive join. Taken at issuance and not recomputed on revocation; a later chain may be shorter than the recorded value, which is the conservative direction for a max_authority_depth decision. A dedicated terminal owned_agent source has depth 1 and cannot become a parent grant.
* authority_root_refs · array<oneOf[2]>
Reducer-derived set of committed authority roots this grant ultimately descends from: direct realm_root refs plus the union of every parent grant's roots. Deduplicated on (realm_id, authority_event_ref, authority_generation) and sorted canonically by unsigned-byte order. For an owned_agent source the sole root is that exact owned_agent ref; it never confers Realm root-control authority.
items · oneOf[2]
oneOf · oneOf[0] · object
* kind ·
const "realm_root"enum:
"realm_root"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* authority_event_ref ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* authority_generation ·
integerThe delegation generation of the root this grant descends from, carried verbatim from the realm_root ref. Part of the dedup key, because the same root at a different generation is a different authority.
oneOf · oneOf[1] ·
$ref #/$defs/owned_agent_authority_ref · $ref #/$defs/owned_agent_authority_ref(^x_[a-z][a-z0-9_]{0,63}$) ·
anyoneOf · oneOf[16] · object · $ref #/$defs/call_state_result
Commit-ordered projection of the ak.call.state state_transition axis (crypto-media/call-state.md section 4.1).
* selector · object
* kind ·
const "call_state"enum:
"call_state"* call_id ·
string · $ref #/$defs/call_id_componentpattern:
^ak:call:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object
Creation initializes from=null with an allowed initial state; later accepted lifecycle deltas have a non-null predecessor.
allOf · allOf[0] ·
?* from · anyOf[2]
anyOf · anyOf[0] ·
nullanyOf · anyOf[1] ·
string (enum) · $ref ./event-payload.schema.json#/$defs/call_state_payload/properties/state_transition/properties/fromenum:
"scheduled" "ringing" "connecting" "active" "ended" "missed" "failed" "cancelled"* to ·
string (enum) · $ref ./event-payload.schema.json#/$defs/call_state_payload/properties/state_transition/properties/toenum:
"scheduled" "ringing" "connecting" "active" "ended" "missed" "failed" "cancelled"failure_reason_code · oneOf[2] · $ref ./event-payload.schema.json#/$defs/call_state_payload/properties/state_transition/properties/failure_reason_code
oneOf · oneOf[0] ·
string (enum)enum:
"media_negotiation_timeout" "permission_denied" "backend_unavailable" "media_source_unavailable" "storage_failed" "policy_revoked" "consent_withdrawn" "integrity_failed"oneOf · oneOf[1] ·
stringpattern:
^x_[a-z0-9_]{1,62}$oneOf · oneOf[17] · object · $ref #/$defs/call_focus_result
Commit-ordered projection of the ak.call.state focus axis. The first committed session_focus is binding (MEDIA-2); later writes MUST restate it verbatim.
* selector · object
* kind ·
const "call_focus"enum:
"call_focus"* call_id ·
string · $ref #/$defs/call_id_componentpattern:
^ak:call:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/call_state_payload/properties/focus
* mode ·
string (enum)enum:
"p2p" "mesh" "sfu" "mcu"session_focus ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringoneOf · oneOf[18] · object · $ref #/$defs/call_recording_state_result
Capture permission state typed current result of one recording segment (family call_recording_state), keyed by the (call_id, recording_id) segment key so several captures in one call never collide.
* selector · object
* kind ·
const "call_recording_state"enum:
"call_recording_state"* call_id ·
string · $ref #/$defs/call_id_componentpattern:
^ak:call:[A-Za-z0-9_-]{44}$* recording_id ·
string · $ref #/$defs/call_recording_id_componentStable opaque recording / transcript segment handle, canonical byte-for-byte (crypto-media/call-state.md section 5.1).
pattern:
^[A-Za-z0-9._-]{1,128}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value ·
string (enum) · $ref #/$defs/call_recording_state_valueCapture permission state of one recording segment: ak.call.recording.start opens it as recording, a committed ak.call.state recording_transition.to=stopped closes it. ready/failed artifact details live in the separate call_recording_artifact family.
enum:
"recording" "stopped"oneOf · oneOf[19] · object · $ref #/$defs/call_recording_artifact_result
Published artifact typed current result of one recording segment (family call_recording_artifact): the ready/failed details published from stopped, referencing the exact confirmed stop Event. It grants no capture, key or read authority.
* selector · object
* kind ·
const "call_recording_artifact"enum:
"call_recording_artifact"* call_id ·
string · $ref #/$defs/call_id_componentpattern:
^ak:call:[A-Za-z0-9_-]{44}$* recording_id ·
string · $ref #/$defs/call_recording_id_componentStable opaque recording / transcript segment handle, canonical byte-for-byte (crypto-media/call-state.md section 5.1).
pattern:
^[A-Za-z0-9._-]{1,128}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/call_state_payload/properties/recording_transition/properties/result
Ordinary capture outcome details. Result status is derived from to and stored with these details. Ready/failed require the exact confirmed stop Event for the same call, segment, capture authority and generation; they cannot modify permission or key access.
content_digest ·
$ref #/$defs/digest · $ref #/$defs/digestduration_ms ·
integermedia_type ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringretention_policy_id ·
string · $ref ./realm.schema.json#/properties/retention_policy_idpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$retention ·
$ref #/$defs/call_recording_retention · $ref #/$defs/call_recording_retentionrecording_start_event_id ·
$ref #/$defs/event_ref · $ref #/$defs/event_refartifact · object · $ref ./call-recording-artifact.schema.json
Canonical metadata for a call recording artifact after it has entered the Arkret blob pipeline. It binds the blob, recording start event, MLS exporter recording key context, retention policy and deletion audit surface without introducing a ak:recording or ak:artifact storage key.
anyOf · anyOf[0] ·
?anyOf · anyOf[1] · object
* retention ·
?* schema ·
const "ak.schema.call_recording_artifact.v1"enum:
"ak.schema.call_recording_artifact.v1"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* call_id ·
$ref #/$defs/call_id · $ref #/$defs/call_id* recording_id ·
$ref #/$defs/recording_id · $ref #/$defs/recording_id* recording_start_event_id ·
$ref #/$defs/event_ref · $ref #/$defs/event_ref* blob_ref ·
$ref #/$defs/blob_ref · $ref #/$defs/blob_ref* size_bytes ·
integer* duration_ms ·
integer* media_type ·
$ref #/$defs/media_type · $ref #/$defs/media_type* encryption ·
$ref #/$defs/recording_encryption · $ref #/$defs/recording_encryptionretention_policy_id ·
$ref #/$defs/policy_id · $ref #/$defs/policy_id* retention ·
$ref #/$defs/call_recording_retention · $ref #/$defs/call_recording_retention* produced_by ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idMedia service DID or recorder service DID that produced the encrypted recording bytes.
* recording_initiator_capability_ref ·
$ref #/$defs/grant_ref · $ref #/$defs/grant_refCapability grant reference proving the recording was initiated by an actor holding ak.call.record.
* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampdeletion_audit ·
$ref #/$defs/call_recording_deletion_audit · $ref #/$defs/call_recording_deletion_auditPresent only after a delete attempt is scheduled, completed, or blocked. The referenced erasure receipt remains the durable audit proof.
failure_reason_code ·
$ref #/$defs/call_capture_failure_reason_code · $ref #/$defs/call_capture_failure_reason_codeMachine reason for recording_state=failed.
failure_message ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringHuman-readable diagnostic for recording_state=failed. It MUST NOT contain recording plaintext or backend direct URLs.
recording_stop_event_id ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[20] · object · $ref #/$defs/call_transcript_state_result
Capture permission state typed current result of one transcript segment (family call_transcript_state), keyed by the (call_id, recording_id) segment key.
* selector · object
* kind ·
const "call_transcript_state"enum:
"call_transcript_state"* call_id ·
string · $ref #/$defs/call_id_componentpattern:
^ak:call:[A-Za-z0-9_-]{44}$* recording_id ·
string · $ref #/$defs/call_recording_id_componentStable opaque recording / transcript segment handle, canonical byte-for-byte (crypto-media/call-state.md section 5.1).
pattern:
^[A-Za-z0-9._-]{1,128}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value ·
string (enum) · $ref #/$defs/call_transcript_state_valueCapture permission state of one transcript segment: ak.call.recording.start opens it as transcribing, a committed ak.call.state transcript_transition.to=stopped closes it.
enum:
"transcribing" "stopped"oneOf · oneOf[21] · object · $ref #/$defs/call_transcript_artifact_result
Published artifact typed current result of one transcript segment (family call_transcript_artifact): the ready/failed details published from stopped, referencing the exact confirmed stop Event.
* selector · object
* kind ·
const "call_transcript_artifact"enum:
"call_transcript_artifact"* call_id ·
string · $ref #/$defs/call_id_componentpattern:
^ak:call:[A-Za-z0-9_-]{44}$* recording_id ·
string · $ref #/$defs/call_recording_id_componentStable opaque recording / transcript segment handle, canonical byte-for-byte (crypto-media/call-state.md section 5.1).
pattern:
^[A-Za-z0-9._-]{1,128}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/call_state_payload/properties/transcript_transition/properties/result
Ordinary capture outcome details. Result status is derived from to and stored with these details. Ready/failed require the exact confirmed stop Event for the same call, segment, capture authority and generation; they cannot modify permission or key access.
content_digest ·
$ref #/$defs/digest · $ref #/$defs/digestmedia_type ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringlanguage ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringretention_policy_id ·
string · $ref ./realm.schema.json#/properties/retention_policy_idpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$retention ·
$ref #/$defs/call_recording_retention · $ref #/$defs/call_recording_retentiontranscript_start_event_id ·
$ref #/$defs/event_ref · $ref #/$defs/event_reffailure_reason_code ·
$ref #/$defs/call_capture_failure_reason_code · $ref #/$defs/call_capture_failure_reason_codeMachine reason for transcript_state=failed.
transcript_stop_event_id ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[22] · object · $ref #/$defs/call_moderation_result
Commit-ordered projection of the ak.call.state moderation_delta axis (crypto-media/call-state.md section 4.1).
* selector · object
* kind ·
const "call_moderation"enum:
"call_moderation"* call_id ·
string · $ref #/$defs/call_id_componentpattern:
^ak:call:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · oneOf[2] · $ref ./event-payload.schema.json#/$defs/call_state_payload/properties/moderation_delta
oneOf · oneOf[0] · object
* op ·
const "remove_participant"enum:
"remove_participant"* removal · object
allOf · allOf[0] ·
?* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_iddevice_id ·
$ref #/$defs/device_id · $ref #/$defs/device_id* action ·
string (enum)enum:
"kick" "ban"* removed_by ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* removed_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[1] · object
* op ·
const "restore_participant"enum:
"restore_participant"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* restored_by ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* restored_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* expected_revision · object · $ref ./typed-current-result.schema.json#/$defs/revision
Exact current moderation revision for this participant observed by the producer. It is the typed revision of the value the producer read, so the compare-and-set names the same {commit_id, stream_position} the typed current result carries. A producer-chosen integer would be a producer-side order, which the authority-commit model does not have.
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integeroneOf · oneOf[23] · object · $ref #/$defs/call_roster_result
Commit-ordered projection of the ak.call.state roster_delta axis. The current value is the last accepted write on the stream; per-participant durable identity is (call_id, actor_id, device_id).
* selector · object
* kind ·
const "call_roster"enum:
"call_roster"* call_id ·
string · $ref #/$defs/call_id_componentpattern:
^ak:call:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · oneOf[2] · $ref ./event-payload.schema.json#/$defs/call_state_payload/properties/roster_delta
oneOf · oneOf[0] · object
* op ·
const "join"enum:
"join"* participant ·
$ref #/$defs/call_participant · $ref #/$defs/call_participantoneOf · oneOf[1] · object
* op ·
const "leave"enum:
"leave"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* device_id ·
$ref #/$defs/device_id · $ref #/$defs/device_id* expected_revision · object · $ref ./typed-current-result.schema.json#/$defs/revision
Exact current call-roster revision observed by the producer. It is the typed revision of the value the producer read, so the compare-and-set names the same {commit_id, stream_position} the typed current result carries. A producer-chosen integer would be a producer-side order, which the authority-commit model does not have.
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integeroneOf · oneOf[24] · object · $ref #/$defs/call_mute_override_result
Reserved call-only shape for the ak.call.state mute_override axis. v1 rejects every mute_override write; this single-leg value cannot establish per-leg media authority (crypto-media/call-state.md section 4.1).
* selector · object
* kind ·
const "call_mute_override"enum:
"call_mute_override"* call_id ·
string · $ref #/$defs/call_id_componentpattern:
^ak:call:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/call_state_payload/properties/mute_override
allOf · allOf[0] ·
?* status ·
string (enum)enum:
"active" "cleared"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* device_id ·
$ref #/$defs/device_id · $ref #/$defs/device_idaudio_muted ·
booleanvideo_muted ·
boolean* changed_by ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* changed_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampreason ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringoneOf · oneOf[25] · object · $ref #/$defs/realm_schema_result
Per-Realm declaration of the Realm-scoped Morph kind tightening (models/governance-objects.md section 4). Singleton: the Realm is given by the Event envelope, which conformance/encoding.md section 9.5.1 forbids repeating in the subject.
* selector · object
* kind ·
const "realm_schema"enum:
"realm_schema"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/realm_schema_payload/properties/value
* schema_refs · array<string>
Complete replacement set of activated schema ids. Members MUST be registered ak.schema.*.vN ids; unknown or unregistered ids fail closed. ak.schema.realm.v1 MUST be a member of every accepted value.
items ·
stringpattern:
^ak\.schema\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v[0-9]+$morph_kind_profiles ·
objectoneOf · oneOf[26] · object · $ref #/$defs/realm_link_result
One directed Realm-to-Realm link. models/realm-links.md section 5 makes the subject the (target_realm_id, link_kind) tuple with the source Realm given by Event scope, and the current value the last accepted write.
* selector · object
* kind ·
const "realm_link"enum:
"realm_link"* target_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* link_kind ·
string (enum) · $ref ./event-payload.schema.json#/$defs/realm_link_payload/properties/link_kindenum:
"governed_by" "discoverable_from" "join_gate_from" "confidential_extension_of" "mirror_of" "split_from" "replaces"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/realm_link_payload
* target_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* link_kind ·
string (enum)enum:
"governed_by" "discoverable_from" "join_gate_from" "confidential_extension_of" "mirror_of" "split_from" "replaces"* status ·
$ref #/$defs/hierarchy_link_status · $ref #/$defs/hierarchy_link_statuslabel ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_256NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$commitment ·
$ref #/$defs/digest · $ref #/$defs/digestcounterpart_event_ref ·
$ref #/$defs/event_ref · $ref #/$defs/event_refedge_nonce ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringedge_digest_commitment ·
$ref #/$defs/digest · $ref #/$defs/digestevidence_refs · array<$ref #/$defs/event_ref>
items ·
$ref #/$defs/event_ref · $ref #/$defs/event_refreason ·
stringoneOf · oneOf[27] · object · $ref #/$defs/realm_join_rule_result
The Realm default_join_rule enum. models/realm-and-space.md section 2.3 makes ak.realm.join_rule its sole canonical carrier.
* selector · object
* kind ·
const "realm_join_rule"enum:
"realm_join_rule"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value ·
string (enum) · $ref ./event-payload.schema.json#/$defs/realm_join_rule_payload/properties/valueenum:
"public" "invite" "knock" "restricted" "knock_restricted" "closed"oneOf · oneOf[28] · object · $ref #/$defs/realm_discovery_result
The Realm default_discoverability envelope (models/realm-and-space.md section 2.3).
* selector · object
* kind ·
const "realm_discovery"enum:
"realm_discovery"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/realm_discovery_payload/properties/value
* discoverability ·
string (enum)enum:
"public" "listed" "restricted" "unlisted" "invite_only" "secret"directory_visibility · object
public_directory ·
booleanorganization_directory ·
booleansource_realm_directory ·
booleanallowed_discoverers · array<object>
items · object
* selector_kind ·
const "claim"enum:
"claim"* claim_kind ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringorganization_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* issuer_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_iddirectory_ids · array<$ref #/$defs/did_core_id>
items ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idanti_enumeration · object
unlisted_exact_alias_required ·
booleanmember_count_mode ·
string (enum)enum:
"exact" "bucketed" "omit"not_found_blinding ·
booleanmember_count_hysteresis · object
absolute ·
integerratio ·
numbermember_count_min_residence_ms ·
integeroneOf · oneOf[29] · object · $ref #/$defs/realm_alias_result
The Realm-local alias declaration or its tombstone. The tombstone branch is retained rather than collapsed to null so durable withdrawal remains distinguishable from never-declared; Directory does not resolve aliases.
* selector · object
* kind ·
const "realm_alias"enum:
"realm_alias"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · oneOf[2] · $ref ./event-payload.schema.json#/$defs/realm_alias_payload
Closed payload for ak.realm.alias, the ONLY wire carrier of a Realm alias. A declaration writes the complete canonical alias; {tombstone:true} is a durable value tombstone that removes the alias from effective resolution without erasing the typed current result history. realm-genesis.schema.json and realm-profile.schema.json are closed and have no alias property, and ak.realm.create / ak.realm.profile payloads MUST NOT carry one.
oneOf · oneOf[0] ·
$ref #/$defs/realm_alias_declaration · $ref #/$defs/realm_alias_declarationoneOf · oneOf[1] ·
$ref #/$defs/realm_alias_tombstone · $ref #/$defs/realm_alias_tombstoneoneOf · oneOf[30] · object · $ref #/$defs/realm_policy_bundle_result
The Realm policy components that have no facet Event kind of their own. models/realm-and-space.md section 2.3 restates the whole bundle on every policy_revision.
* selector · object
* kind ·
const "realm_policy_bundle"enum:
"realm_policy_bundle"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/realm_policy_bundle_payload
Enabled Realm policy component set, written wholesale into the realm_policy_bundle commit-ordered projection typed current result: every revision restates the complete enabled component set and the Realm object's derived policy fields re-derive from the latest accepted bundle. policy_revision starts at 1 and every later authoritative reducer admission MUST equal previous.policy_revision + 1: rollback uses top-level policy_revision_rollback; a forward gap uses failed_precondition with reason_code policy_revision_gap and produces zero typed-current-result writes. policy_revision MUST cover policy_revision (see contract-registry event-kind row and models/realm-and-space.md section 2.3).
* policy_revision ·
integerStrictly monotonic bundle revision; rollback or gaps are rejected.
federation_policy ·
string (enum) · $ref ./realm.schema.json#/properties/federation_policyThe sole producer carrier of the effective Realm federation policy. High-assurance Realm reducers require closed, restricted, or quarantine and reject open.
enum:
"open" "restricted" "closed" "quarantine"media_service_decrypts ·
booleanWhether a media service listed in plaintext_visible_services may decrypt call media. Defaults to false when absent. It is one of three conditions that MUST all hold (ak.realm.media_service declaration + plaintext_visible_services grant + this toggle). Because it changes who may receive media keys, it enters the media scope key_access_revision; a generation that does not cover the current value cannot authorize media decryption. See crypto-media/media-service-binding.md section 8.2.
join_policy ·
$ref #/$defs/join_policy_component · $ref #/$defs/join_policy_componenthandle_issuer_policies · array<object>
Ordered Realm handle-issuer trust policy used by primary-handle resolution. Earlier entries have higher tie-break priority; every issuer is domain-scoped.
items · object
* issuer_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* authorized_handle_domains · array<string>
items ·
stringpattern:
^(?:\*\.)?[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$* issuer_class ·
string (enum)enum:
"domain_authority" "delegated_issuer" "directory_mirror"agent_participation · object · $ref ./realm.schema.json#/properties/agent_participation
Realm five-bit Agent participation ceiling. It may only tighten the target-service safety ceiling and is itself the parent of Circle and Strand ceilings.
* agent · object · $ref ./principal-operations.schema.json#/$defs/participation_bits
* reply_message ·
boolean* reaction_add ·
boolean* reaction_remove ·
boolean* accept_third_party_mention ·
boolean* act_on_behalf ·
booleanaccount_deactivation · object
* member_action ·
string (enum)How this Realm disposes of a principal's membership when the account enters deactivated. Defaults to leave_self_initiated when the component is absent. Unrecognized values fail closed to retain_membership with a policy parse warning and MUST NOT silently fall back to the default. The single authority for the closed enum and its disposition semantics is identity/account-lifecycle.md section 7.1.
enum:
"leave_self_initiated" "retain_membership" "leave_all"max_authority_lifetime_ms ·
integer · $ref ./realm.schema.json#/properties/max_authority_lifetime_msMaximum fixed child-chain lifetime only for actions explicitly required to be finite by their risk/constraint contract. Defaults to 24 hours for those actions; first use freezes the bound and redelegation cannot renew it. It does not impose expiry on unbounded ordinary chat/read/organizer authorization.
example:
86400000preauth · object
* consent_required ·
booleanWhen true, every invite into this Realm MUST pass the holder consent admission gate in identity/consent-model.md section 6.1 before the invite Event is submitted. It MUST NOT be read as permission for a cross-Realm authority-commit precondition.
allowed_third_party_invite_verification_ids · array<$ref #/$defs/did_core_id>
Complete current allow-set of service DIDs trusted to attest 3PID ownership for ak.invite.third_party / ak.invite.claim. The array is whole-value replacement state in this policy-bundle revision, not an incremental patch. Absence and [] both deny every third-party invite verification service. Removing a DID in a later policy_revision revokes it for every later claim re-check; no separate tombstone exists. Reducers MUST evaluate the current accepted bundle typed current result on a fresh basis before accepting ak.invite.claim.
items ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idoneOf · oneOf[31] · object · $ref #/$defs/realm_asset_privacy_policy_result
The Realm asset metadata and download policy (crypto-media/media-and-blob.md section 6). It is deliberately not a policy_bundle component and is excluded from key_access_revision.
* selector · object
* kind ·
const "realm_asset_privacy_policy"enum:
"realm_asset_privacy_policy"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/realm_asset_privacy_policy_payload/properties/value
download_mode ·
string (enum)enum:
"direct" "provider_proxy" "ohttp_relay" "client_mirror"allowed_modes · array<string (enum)>
items ·
string (enum)enum:
"direct" "provider_proxy" "ohttp_relay" "client_mirror"direct_download_allowed ·
booleanexample:
falseupload_ids · array<$ref #/$defs/did_core_id>
items ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_iddownload_proxy_ids · array<$ref #/$defs/did_core_id>
items ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idohttp_gateway_ids · array<$ref #/$defs/did_core_id>
items ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idmax_plaintext_metadata · array<string (enum)>
items ·
string (enum)enum:
"size_bucket" "media_type_family" "content_hash"client_digest_check_required ·
booleanoneOf · oneOf[32] · object · $ref #/$defs/realm_plaintext_visible_services_result
The declared set of services that may see plaintext in this Realm (models/realm-and-space.md section 2.3).
* selector · object
* kind ·
const "realm_plaintext_visible_services"enum:
"realm_plaintext_visible_services"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/plaintext_visible_services_payload
* services · array<object>
items · object
* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* service_kind ·
string* purposes · array<string>
items ·
string* data_classes · array<$ref #/$defs/plaintext_data_class>
Closed machine-checkable classes of plaintext or reversible derived content this service may receive. Human-readable purposes do not replace this field.
items ·
$ref #/$defs/plaintext_data_class · $ref #/$defs/plaintext_data_class* visibility ·
string (enum)enum:
"private_plaintext" "derived_plaintext"expires_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[33] · object · $ref #/$defs/realm_media_service_result
The single settled media service binding of the Realm. crypto-media/media-service-binding.md section 4 calls it a single-valued commit-ordered projection; section 2.1 pins the closed field set.
* selector · object
* kind ·
const "realm_media_service"enum:
"realm_media_service"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/realm_media_service_payload/properties/value
* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$modes · array<string (enum)>
items ·
string (enum)enum:
"turn" "sfu" "mcu"ice_config_endpoint ·
stringICE / TURN credential endpoint. Part of the section 2.1 integrity binding.
pattern:
^https://[^\s]+$* foci · array<$ref #/$defs/media_service_focus>
Non-empty multi-focus list. A descriptor carrying a single flat sfu_endpoint, or no foci at all, MUST fail closed with media_service_foci_required; a server MUST NOT normalize or infer one in the realtime path.
items ·
$ref #/$defs/media_service_focus · $ref #/$defs/media_service_focusdefault_call_mode ·
string (enum)enum:
"p2p" "sfu" "mcu"allowed_call_modes · array<string (enum)>
items ·
string (enum)enum:
"p2p" "sfu" "mcu"recording_supported ·
booleanoneOf · oneOf[34] · object · $ref #/$defs/realm_read_receipt_policy_result
The Realm read receipt disclosure requirement (discovery/read-receipts.md section 2.5). Strand-level separation goes through a Circle, not through a second subject on this family.
* selector · object
* kind ·
const "realm_read_receipt_policy"enum:
"realm_read_receipt_policy"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/read_receipt_policy_payload
disclosure ·
string (enum)enum:
"required" "optional" "disabled"visibility ·
string (enum)enum:
"public" "members" "private"scope_overrides_allowed ·
booleanoneOf · oneOf[35] · object · $ref #/$defs/realm_preview_policy_result
The Realm preview / peek policy (models/realm-and-space.md section 2.3). It is the projected source of the query field preview_policy_id and is a per-Realm singleton like every sibling facet in that sentence. The value is payload.value only: payload.reason is audit provenance carried by the Event, not projected state.
* selector · object
* kind ·
const "realm_preview_policy"enum:
"realm_preview_policy"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/preview_policy_payload/properties/value
allOf · allOf[0] ·
?* mode ·
string (enum)enum:
"none" "directory_card" "stripped_state" "history_stub" "history_snippet"* audiences · array<string (enum)>
items ·
string (enum)enum:
"anonymous" "authenticated" "invited" "knock_applicant" "restricted_claim_holder" "link_token_holder" "realm_member"* fields · array<string (enum)>
items ·
string (enum)enum:
"title" "avatar_blob_ref" "summary" "owning_organization_ids" "join_rule" "history_access" "member_count_bucket" "topic" "preview_ref" "server_hints"history · object
* range ·
string (enum)enum:
"none" "event_stubs" "last_n_events" "since_invite"* content ·
string (enum)enum:
"none" "redacted" "plaintext_if_unencrypted" "encrypted_payload_only"max_events ·
integerinclude_member_events ·
booleanexample:
falsesender_profile ·
string (enum)enum:
"none" "display_name_only" "full_if_authorized"example:
"none"token · object
required ·
booleanexample:
falsettl_seconds ·
integerbind_target_digest ·
const trueenum:
trueexample:
trueoneOf · oneOf[36] · object · $ref #/$defs/mimi_room_binding_result
One MIMI room binding (extensions/mimi-interop.md section 3). The subject is the MIMI room URI, not an Arkret id: the family records how one external room is bound, and the same Realm or Strand may be bound into more than one room. The binding is a projection into MIMI and is never canonical truth about the Arkret side.
* selector · object
* kind ·
const "mimi_room_binding"enum:
"mimi_room_binding"* mimi_room_uri ·
string · $ref ./event-payload.schema.json#/$defs/mimi_room_binding_payload/properties/mimi_room_uriCanonical MIMI room URI. It is the mimi_room_binding typed current result subject source, so it is a closed canonical form rather than a free URI: lowercase mimi:// scheme, host[:port] authority with no userinfo, lowercase A-label host, no leading-zero port, at least one non-empty path segment, no dot or dot-dot segment, no trailing slash, no query, no fragment, uppercase percent escapes, and no percent-encoding of unreserved octets (RFC 3986 section 6.2.2.2). A receiver MUST reject a non-canonical value with schema_violation and MUST NOT normalize it first, because two spellings of one room would otherwise each own a first accepted binding and the revoked terminal state could be bypassed by respelling. typed current result subject encoding is the uri subject kind of zh/conformance/encoding.md section 4. The pattern below expresses the structural half of the canonical form; two rules it cannot express portably -- the default port 443 MUST NOT be written explicitly, and a percent escape MUST NOT encode an unreserved octet -- are normative all the same and are closed by ak.vector.encoding.result_selector_uri.v1 plus the SDK typed validator, which every producer and receiver MUST apply in addition to this pattern. See zh/extensions/mimi-interop.md section 4.
pattern:
^mimi://[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)*(?::(?:[1-9][0-9]{0,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?(?:/(?:[A-Za-z0-9\-._~!$&'()*+,;=:@]|%[0-9A-F]{2})+)+$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/mimi_room_binding_payload
Payload for ak.mimi.room_binding. Writes the mimi_room_binding typed current result whose subject is payload.mimi_room_uri (see event-kind-registry.json result_selector). Authoritative field set: zh/extensions/mimi-interop.md §3. The binding is a projection of an Arkret Realm/Strand discussion track into a MIMI room; it is not canonical truth. Creation / update / revocation MUST hold ak.policy.manage, ak.realm.admin, or an equivalent interop capability. E2EE MIMI rooms MUST bind mls_group_id and pass the active MLS key_access_revision gate.
* profile ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringInterop profile id, e.g. ak.profile.mimi_interop.v1.
* mimi_room_uri ·
string · $ref ./mimi-interop.schema.json#/$defs/mimi_room_uriCanonical MIMI room URI. It is the mimi_room_binding typed current result subject source, so it is a closed canonical form rather than a free URI: lowercase mimi:// scheme, host[:port] authority with no userinfo, lowercase A-label host, no leading-zero port, at least one non-empty path segment, no dot or dot-dot segment, no trailing slash, no query, no fragment, uppercase percent escapes, and no percent-encoding of unreserved octets (RFC 3986 section 6.2.2.2). A receiver MUST reject a non-canonical value with schema_violation and MUST NOT normalize it first, because two spellings of one room would otherwise each own a first accepted binding and the revoked terminal state could be bypassed by respelling. typed current result subject encoding is the uri subject kind of zh/conformance/encoding.md section 4. The pattern below expresses the structural half of the canonical form; two rules it cannot express portably -- the default port 443 MUST NOT be written explicitly, and a percent escape MUST NOT encode an unreserved octet -- are normative all the same and are closed by ak.vector.encoding.result_selector_uri.v1 plus the SDK typed validator, which every producer and receiver MUST apply in addition to this pattern. See zh/extensions/mimi-interop.md section 4.
pattern:
^mimi://[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)*(?::(?:[1-9][0-9]{0,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?(?:/(?:[A-Za-z0-9\-._~!$&'()*+,;=:@]|%[0-9A-F]{2})+)+$* binding_scope · object
Arkret Realm + Strand scope this MIMI room projects. strand_id MUST point at an accepted Strand with discussion track enabled inside realm_id; the MIMI room timeline only projects that Strand's discussion track.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* strand_id ·
$ref #/$defs/strand_id · $ref #/$defs/strand_id* hub_provider_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idService DID explicitly delegated by Realm policy, Organization DID, or participant DID to host the hub role.
* local_provider_role ·
string (enum)enum:
"hub" "follower" "observer"follower_provider_ids · array<$ref #/$defs/did_core_id>
items ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idmls_group_id ·
string · $ref ./common-ids.schema.json#/$defs/mls_group_idRFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern:
^[A-Za-z0-9_-]{43}$content_profile ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringMIMI content profile, e.g. application/mimi-content.
policy_revision ·
integerAccepted ak.realm.policy_bundle revision this MIMI room binding projects. The facade compares it against the Realm's current committed policy revision and rejects a stale projection.
* status ·
string (enum)Lifecycle state of the binding. Initial status MUST be proposed or accepted; legal transitions are defined in zh/extensions/mimi-interop.md §4.2. accepted bindings authorize projection; revoked bindings stop new MIMI writes; migrating stops new writes until a verified migration proof returns the binding to accepted or revoked.
enum:
"proposed" "accepted" "revoked" "migrating"migration_outcome ·
string (enum)Required exactly for a migrating->accepted transition, paired with migration_proof. The signed Event asserts whether the migrating candidate topology became effective or the previous accepted topology was restored.
enum:
"completed" "rolled_back"migration_proof ·
$ref #/$defs/mimi_room_binding_migration_proof · $ref #/$defs/mimi_room_binding_migration_proofcreated_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[37] · object · $ref #/$defs/moderation_franking_proof_result
The receiving-service proof that one encrypted target Event was received (governance/content-moderation.md section 3.4). The subject is the proven Event id. Installing an authorized signed current row is independent of a later report and does not itself establish moderator verification or an existence-time verdict.
* selector · object
* kind ·
const "moderation_franking_proof"enum:
"moderation_franking_proof"* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./moderation-evidence.schema.json#/$defs/franking_proof
Canonical receiving-service receipt used both inside a moderation report and as the complete payload of an ak.moderation.franking_proof durable Event. The local signature uses domain ak.franking_proof.signature.v1 and covers every member except signature. event_id names the encrypted Event whose receipt is proven; the enclosing proof Event has its own distinct Event.event_id.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* received_by ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* received_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* replay_nonce ·
stringOpaque anti-replay nonce generated by the receiving service and covered by the proof signature.
pattern:
^[A-Za-z0-9_-]{16,256}$* signature ·
stringReceiving service signature over the canonical franking-proof transcript.
oneOf · oneOf[38] · object · $ref #/$defs/realm_tombstone_result
The terminal tombstone of the Realm, with its required successor_realm_id (models/realm-and-space.md section 2.6). Commit-ordered and written at most once.
* selector · object
* kind ·
const "realm_tombstone"enum:
"realm_tombstone"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/realm_tombstone_payload
* reason ·
string* successor_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$replacement_event_id ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[39] · object · $ref #/$defs/realm_destroy_result
The terminal destroy of the Realm, which MUST NOT carry a successor (models/realm-and-space.md section 2.6). Commit-ordered and written at most once.
* selector · object
* kind ·
const "realm_destroy"enum:
"realm_destroy"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/realm_destroy_payload
* reason ·
stringretention_policy_id ·
string · $ref ./realm.schema.json#/properties/retention_policy_idpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$verification_stub_required ·
booleanexample:
trueoneOf · oneOf[40] · object · $ref #/$defs/realm_set_default_strand_result
The authoritative default_strand_id pointer of the Realm (models/strand-and-message.md section 1). The current value is the last accepted write on the stream.
* selector · object
* kind ·
const "realm_set_default_strand"enum:
"realm_set_default_strand"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/realm_set_default_strand_value
The registered value shape of realm_set_default_strand. models/strand-and-message.md section 2 makes the authoritative current value the Realm projection field default_strand_id and normalizes absent and explicit null to one null before a whole-value comparison, so the value is the one-member object carrying that field rather than a bare pointer: only a member can be absent.
* default_strand_id ·
string | null · $ref ./realm.schema.json#/properties/default_strand_idDerived ordinary default-Strand selection from current-value projection realm_set_default_strand. The deterministic (depth, EventId) winner selects the candidate; it is effective only when the selected Strand is eligible, non-terminal, and in the same Realm. Selection grants no authority.
pattern:
^ak:strand:[A-Za-z0-9_-]{44}$oneOf · oneOf[41] · object · $ref #/$defs/strand_position_result
The position of one Strand on one Board. models/realm-and-space.md section 3.6 pins the subject to the reversible typed_pair of board_space_id and strand_id and forbids a hash subject, so both typed-ID components MUST be validated on parse.
* selector · object
* kind ·
const "strand_position"enum:
"strand_position"* board_space_id ·
string · $ref ./event-payload.schema.json#/$defs/board_space_idA Space with kind=board. Pattern matches any ak:space:; kind invariant enforced by reducer/profile.
pattern:
^ak:space:[A-Za-z0-9_-]{44}$* strand_id ·
string · $ref ./event-payload.schema.json#/$defs/strand_idpattern:
^ak:strand:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · oneOf[2] · $ref #/$defs/strand_position_value
The registered value shape of strand_position, pinned by models/realm-and-space.md section 3.6 as list_space_id with rank, or null. The null branch is the pre-placement state of a Strand that has been created but never moved onto a Board.
oneOf · oneOf[0] · object
* list_space_id ·
string · $ref ./event-payload.schema.json#/$defs/list_space_idA Space with kind=list.
pattern:
^ak:space:[A-Za-z0-9_-]{44}$* rank ·
string · $ref ./event-payload.schema.json#/$defs/rankStable manual sort position under the registered ak.rank.lexofractional.v1 profile: 1..128 characters from the fixed base62 alphabet, compared character by character in ASCII order. It is a producer-chosen ordering token, not a derived or causal value; see zh/conformance/encoding.md section 9.1 for the grammar, rank_between and rebalance rules.
pattern:
^[0-9A-Za-z]{1,128}$oneOf · oneOf[1] ·
nulloneOf · oneOf[42] · object · $ref #/$defs/invite_lifecycle_result
Registered projection of one Invite's process state. The subject InviteId is the create Event id retyped (zh/models/common-fields.md section 6.0), so a directed ak.invite.create and a third-party ak.invite.third_party each open exactly one of these and every later Event names it through payload.invite_id.
* selector · object
* kind ·
const "invite_lifecycle"enum:
"invite_lifecycle"* invite_id ·
string · $ref ./event-payload.schema.json#/$defs/invite_idpattern:
^ak:invite:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value ·
string (enum) · $ref #/$defs/invite_lifecycle_valueClosed value of the invite_lifecycle typed current result: the one process-state register of one Invite. zh/models/governance-objects.md section 5.3 declares the state set and the edge set, and registry/contract-registry.json carries the edges as event_kind_registry.transition_contracts.invite_lifecycle, so this def holds the state names only. The register carries nothing else on purpose: a transition projection writes one axis, and every other Invite fact that has to be checked against the pre-state is its own registered family (invite_directed_invitee, invite_live_target). A mirrored copy here would be the drifting second truth that section removed join_rule_snapshot for.
enum:
"pending" "claimed" "send_failed" "accepted" "rejected" "revoked" "expired" "revoked_by_capability_loss" "revoked_by_inviter_left" "invalidated_by_rate_limit"oneOf · oneOf[43] · object · $ref #/$defs/invite_live_target_result
The one live directed Invite slot of one invitee account inside one Realm. zh/models/governance-objects.md section 5.3 makes it the single source of truth for directed-invite liveness deduplication, keyed by the invitee AccountId alone: the Realm is already given by the Event envelope, so carrying realm_id in the subject is forbidden by zh/conformance/encoding.md section 4.
* selector · object
* kind ·
const "invite_live_target"enum:
"invite_live_target"* invitee_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · oneOf[2] · $ref #/$defs/invite_live_target_value
Closed value of the invite_live_target slot: the record of the directed Invite that currently occupies this account's slot, or null for an empty slot. zh/models/governance-objects.md section 5.3 fixes the occupant as create_event_id in the verbatim ak:event: spelling rather than the ak:invite: retype, because the projection grammar has no retype source; the slot carries no process state, since occupancy itself is what live means. null is the reusable empty state a registered release write returns it to, not a read-only sentinel.
oneOf · oneOf[0] · object
* create_event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
nulloneOf · oneOf[44] · object · $ref #/$defs/invite_directed_invitee_result
Registered create-locked projection of one directed Invite's invitee. The subject InviteId is the create Event id retyped, the same subject invite_lifecycle uses, so a later Event that names payload.invite_id reaches both the state register and this binding without carrying either of them on the wire.
* selector · object
* kind ·
const "invite_directed_invitee"enum:
"invite_directed_invitee"* invite_id ·
string · $ref ./event-payload.schema.json#/$defs/invite_idpattern:
^ak:invite:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/invite_directed_invitee_value
Closed value of the invite_directed_invitee record: the exact account one directed Invite is addressed to, written once by ak.invite.create from that same Event's payload and never updated. It is the reverse index of invite_live_target, and the two together are what make the slot release checkable: the slot answers "which Invite holds this account", this record answers "which account does this Invite hold". ak.invite.third_party writes no record at all, so a third-party Invite's stored invitee is absent rather than null -- that absence is what the stored_field_matches_payload pre-state requirement of zh/models/governance-objects.md section 5.3 reads.
* invitee_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idoneOf · oneOf[45] · object · $ref #/$defs/pin_result
Registered projection of one pin scope. models/pins.md section 4.1 is authoritative and spells this projection verbatim: ak.pin.add, ak.pin.remove and ak.pin.reorder each project exactly one keyed_set_add, so a remove and a reorder are themselves asserted elements rather than explicit revocations. The reason is in that section: keyed_set_remove_observed without a match would remove every target in the scope, and with a match it would only remove add dots alive in the frozen prior state, which silently converges a concurrent (add, remove) pair to add instead of surfacing it.
* selector · object
models/pins.md section 4.1 keys the set per pin scope: the subject is the whole closed pin_scope object, kind and id together. The id alone would not do -- pin_scope is a four-branch oneOf, so two scopes of different kinds carrying the same id would collide into one subject, and the subject would not be reversible into the object the payload signed. target_ref is a field on the element value, not part of the subject.
* kind ·
const "pin"enum:
"pin"* pin_scope · oneOf[4] · $ref ./event-payload.schema.json#/$defs/pin_scope
oneOf · oneOf[0] · object
* kind ·
const "strand"enum:
"strand"* id ·
$ref #/$defs/strand_id · $ref #/$defs/strand_idoneOf · oneOf[1] · object
* kind ·
const "realm"enum:
"realm"* id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "circle"enum:
"circle"* id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[3] · object
* kind ·
const "space"enum:
"space"* id ·
$ref #/$defs/space_id · $ref #/$defs/space_id* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/pin_value
Closed value of the pin typed current result: the canonically sorted dot set of pin assertions in one pin scope. The join is the keyed-set union of models/common-fields.md section 2, which stays commutative, associative and idempotent. Every one of the three pin kinds adds an assertion, including remove and reorder, so the set keeps both sides of a concurrent pair; the ordered roster, the remove-wins fold, the note inherited by a reorder and the conflict view are all read-side folds above this set, defined in models/pins.md section 4.1, and MUST NOT be implemented as further stored state.
* assertions · array<$ref #/$defs/pin_assertion_entry>
items · object · $ref #/$defs/pin_assertion_entry
One asserted element of the pin keyed set. The tag is the canonical dot of the accepted Event write that produced it; the value is the complete pin payload of that Event. The asserting actor and the polarity -- add, remove or reorder -- are deliberately NOT element fields: models/pins.md section 4.1 reads the polarity from `kind` and the asserter from `actor_id` on the signed envelope of the Event the dot names, because event-and-patch.md section 2.4.2 forbids a projection from assembling, renaming or trimming fields. The value branch is an anyOf and MUST NOT be read as a discriminator: pin_add_payload and pin_reorder_payload share the required {pin_scope, target_ref, rank} triple, so an add and a reorder that carry no optional member are byte-identical and only the envelope tells them apart.
* tag_id ·
string · $ref #/$defs/canonical_event_dotStable tag of one registered reducer write: the canonical <event_id>:<write_index> dot of zh/models/event-and-patch.md section 2.4.2. A bare event_id is never a valid tag. Canonical dot-set order compares the complete event_id by unsigned UTF-8 bytes, then write_index as an integer (2 before 10). Index encoding has no leading zeros. Duplicate dots and conflicting values for one dot are rejected; sorting is not winner or causal ordering.
pattern:
^ak:event:[A-Za-z0-9_-]{44}:(0|[1-9][0-9]{0,2})$* value · anyOf[3]
anyOf · anyOf[0] · object · $ref ./event-payload.schema.json#/$defs/pin_add_payload
* pin_scope ·
$ref #/$defs/pin_scope · $ref #/$defs/pin_scope* target_ref ·
$ref #/$defs/object_ref · $ref #/$defs/object_ref* rank ·
$ref #/$defs/rank · $ref #/$defs/ranknote ·
$ref #/$defs/encrypted_envelope · $ref #/$defs/encrypted_envelopeanyOf · anyOf[1] · object · $ref ./event-payload.schema.json#/$defs/pin_remove_payload
* pin_scope ·
$ref #/$defs/pin_scope · $ref #/$defs/pin_scope* target_ref ·
$ref #/$defs/object_ref · $ref #/$defs/object_refexpected_rank ·
$ref #/$defs/rank · $ref #/$defs/rankanyOf · anyOf[2] · object · $ref ./event-payload.schema.json#/$defs/pin_reorder_payload
* pin_scope ·
$ref #/$defs/pin_scope · $ref #/$defs/pin_scope* target_ref ·
$ref #/$defs/object_ref · $ref #/$defs/object_ref* rank ·
$ref #/$defs/rank · $ref #/$defs/rankexpected_rank ·
$ref #/$defs/rank · $ref #/$defs/rankoneOf · oneOf[46] · object · $ref #/$defs/space_parent_result
The structural parent of one Space. models/realm-and-space.md section 3.5 is authoritative: the subject is the SpaceId alone, the projection is an ordinary current value, and the current value is the last accepted write on the stream, ordered only by stream_position. The Space metadata projection deliberately excludes parent_space_id, so this family and not the object is the truth source models/relation.md and sync/views.md read the derived contains edge from. A directed cycle among current parents makes every edge in it domain-unresolved; it MUST NOT reselect a register value, fake a root, or produce a live contains.
* selector · object
* kind ·
const "space_parent"enum:
"space_parent"* space_id ·
string · $ref ./event-payload.schema.json#/$defs/space_idpattern:
^ak:space:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/space_parent_value
The registered value shape of space_parent, pinned by models/realm-and-space.md section 3.5. It is the one-member object carrying the parent pointer, with a nullable member, and it is never a bare null: only a member can be absent, which is the same argument realm_set_default_strand_value makes, and here a bare null would also make the family's own compare-and-set inexpressible, because a pre_state requirement is a predicate over a stored FIELD and a null value has no fields. null in the member is the root state, a Space with no structural parent, written explicitly by the ak.space.create genesis write when the signed object omits parent_space_id.
* parent_space_id · oneOf[2]
oneOf · oneOf[0] ·
string · $ref ./event-payload.schema.json#/$defs/space_idpattern:
^ak:space:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
nulloneOf · oneOf[47] · object · $ref #/$defs/space_child_scope_policy_result
The child placement policy of one Space, keyed by SpaceId. models/circle.md section 7.1 is authoritative for the enum and for the four reducer obligations it creates on ak.strand.create, ak.strand.move, ak.space.parent and structural contains writes; section 6.3 is authoritative for why it is not interchangeable with Space.scope_circle_id. It is a family rather than a create-locked object member because space_patch_payload carries a dedicated top-level child_scope_policy command whose own description makes it select security execution, while the generic metadata patch is forbidden from reaching the path at all.
* selector · object
* kind ·
const "space_child_scope_policy"enum:
"space_child_scope_policy"* space_id ·
string · $ref ./event-payload.schema.json#/$defs/space_idpattern:
^ak:space:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · oneOf[2] · $ref #/$defs/space_child_scope_policy_value
The registered value shape of space_child_scope_policy: the closed placement policy object of models/circle.md section 7.1, or null. null is the undeclared state; that section says a Space MAY declare a policy, and an undeclared policy adds no constraint, which is what allow_any also means. The reducer MUST NOT synthesize the allow_any object out of an absent member: a projection may only write a value the signed Event or the envelope supplies, and null is the one registered spelling of the absent state.
oneOf · oneOf[0] · object · $ref ./space.schema.json#/$defs/child_scope_policy
allOf · allOf[0] ·
?* kind ·
string (enum)enum:
"allow_any" "require_e2ee" "require_same_scope" "require_scope_circle_id"scope_circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] ·
nulloneOf · oneOf[48] · object · $ref #/$defs/agent_provisioning_result
One Agent provisioning fact (family agent_provisioning), the first of the four typed results one accepted ak.agent.provision writes atomically. zh/identity/key-management.md section 3.6.3 is authoritative. The subject is the Agent DID alone and deliberately not the Agent's full account ActorId: zh/models/actor.md derives that ActorId from payload.agent_id plus this Event's exact controller account and Station and only reconciles it against genesis.actor_id after genesis, so an ActorId subject would be unconstructible at the moment this write happens. The reason zh/identity/key-management.md section 3.6 forbids a bare DidCoreId for the LIFECYCLE subject -- one principal on two Stations is two accounts -- is already discharged here: this result lives in the controller PCR, and the same-Station rule of section 3.6.3 pins the Agent PCR to that same Station. It is a commit-ordered projection, and a second ak.agent.provision declaring an agent_id an accepted provision already carries MUST be rejected with zero writes (agent_provisioning_already_declared): the immutable requested_scope ceiling of section 3.6.1 can only be changed by provisioning a new Agent principal, so re-declaring one agent_id is the widening that section forbids.
* selector · object
* kind ·
const "agent_provisioning"enum:
"agent_provisioning"* agent_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/agent_provisioning_value
The registered value shape of agent_provisioning, pinned by zh/identity/key-management.md section 3.6.3. These are exactly the create-locked members every later authorization reader needs when all it holds is the Agent DID: the controller it is bound to, the Agent PCR that carries its lifecycle and key state, the delegation that authorized the controller, and the immutable requested-scope commitment zh/authz/capabilities.md section 9.1 recomputes a disclosure against. Nothing else from the payload belongs here -- agent_slug and the selector members are agent_selector_claim's, the endorsement members are identity_accountability's, and created_at is already the endorsement's not_before. requested_scope itself is controller-private and MUST NOT appear; only the digest does.
* controller_principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* controller_authorization_ref ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* requested_scope_digest ·
string · $ref ./agent-provision.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$oneOf · oneOf[49] · object · $ref #/$defs/agent_pcr_genesis_declaration_result
One Agent PCR realm-id declaration (family agent_pcr_genesis_declaration), the fourth of the four typed results one accepted ak.agent.provision writes atomically. zh/identity/key-management.md section 3.6.3 is authoritative: the subject is the forward-declared principal_control_realm_id, the projection is commit-ordered, and a second provision declaring a realm id an accepted provision already claims MUST be rejected with zero writes (agent_pcr_genesis_declaration_conflict). This result covers one controller PCR only; duplicate declarations across controllers are caught by the Station's local uniqueness index, and the two layers together are what makes "at most one provision declaration per realm id" hold. The Agent PCR genesis carries no ref back to its provision, so the reverse look-up against this family IS the whole binding: no row MUST fail closed with agent_pcr_genesis_declaration_missing and zero writes, materializing neither the Realm nor the agent_status transition.
* selector · object
* kind ·
const "agent_pcr_genesis_declaration"enum:
"agent_pcr_genesis_declaration"* principal_control_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/agent_pcr_genesis_declaration_value
The registered value shape of agent_pcr_genesis_declaration: the one-member object naming the Agent this realm id was declared for. It is an INDEX and not a second copy of the provisioning fact, which is what makes the two families separately closed and minimal in the sense zh/conformance/conformance-profiles.md requires: one fact, two registered lookup directions. The readers only ever hold a realm id -- genesis admission holds retype(create.event_id) and entry 1 admission holds serviceEndpoint.realm_id -- so they resolve the Agent here and read the remaining create-locked members from agent_provisioning keyed by it. It is an object rather than a bare id for the reason realm_set_default_strand_value and space_parent_value already give: only a member can be absent, so a register whose value is a bare id has no room to grow a second member without changing what its value IS.
* agent_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[50] · object · $ref #/$defs/agent_selector_claim_result
One controller-scoped Agent selector binding (family agent_selector_claim). zh/models/actor.md section 3.3 is authoritative: the only writer is the selector projection of ak.agent.provision, which has no inner proof, and a later provision of the same slug replaces the binding. The subject is principal-scoped -- (controller principal, agent_slug), never with a Station -- while the target is account-scoped; neither is derived from the other.
* selector · object
* kind ·
const "agent_selector_claim"enum:
"agent_selector_claim"* controller_principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* agent_slug ·
string (arkret-agent-slug) · format=arkret-agent-slug · $ref ./string-profiles.schema.json#/$defs/agent_slugCanonical controller-scoped Agent Agent selector slug. Maximum 64 Unicode code points in prepared form.
pattern:
^[^\s:@/#?\\]+$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/agent_selector_claim_value
The registered value shape of agent_selector_claim, written only by the selector projection of ak.agent.provision. zh/models/actor.md section 3.3 is authoritative. These are exactly the members label verification reads: the target, and the disclosure boundary. It deliberately does not repeat its own subject: the controller principal and the slug are the selector. issuer_id, vouching_id, source_refs, created_at, verified_at, expires_at and proofs are absent: the head Event and its acceptance proof already answer where the row came from, and a provision binding does not expire on a clock. There is no claim_scope, open or closed, and no portable signed-claim form of this value.
* subject_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* visibility ·
string (enum) · $ref ./agent-provision.schema.json#/properties/selector_visibilityenum:
"public" "restricted" "private"audience ·
string · $ref ./agent-provision.schema.json#/properties/selector_audienceoneOf · oneOf[51] · object · $ref #/$defs/consent_result
Registered projection of one holder-private Consent record inside the holder's Principal Control Realm. The subject is the producer-assigned stable consent_id (zh/identity/consent-model.md section 2); peers can never read it (section 8).
* selector · object
* kind ·
const "consent"enum:
"consent"* consent_id ·
string · $ref ./event-payload.schema.json#/$defs/consent_grant_payload/properties/consent_idStable identifier; used as the result_selector of the consent typed current result. ak.consent.revoke MUST reference the same consent_id.
pattern:
^ak:consent:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/consent_value
Closed value of the consent typed current result, one record per stable consent_id (zh/identity/consent-model.md section 2). status is the lifecycle axis and it lives inside the body rather than in event_kind_registry.transition_contracts, because ak.consent.revoke guards itself with expected_revision: a single {commit_id, stream_position} can only be the CAS operand if body and status share one result. See zh/sync/current-results.md section 2.1 for the two registered carriers of a lifecycle axis. expired is deliberately not a state here: zh/identity/consent-model.md section 5 evaluates the not_before / expires_at window at verification time, so a projected expired would be a clock-driven write no Event authorises.
* consent_id ·
string · $ref ./event-payload.schema.json#/$defs/consent_grant_payload/properties/consent_idStable identifier; used as the result_selector of the consent typed current result. ak.consent.revoke MUST reference the same consent_id.
pattern:
^ak:consent:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* peer · object · $ref ./event-payload.schema.json#/$defs/consent_peer
Closed consent counterparty identity. Ordinary accounts, Agents, pseudonymous accounts and MIMI-correlated parties use one exact ActorId, including Account Station and actor role.
* kind ·
const "actor"enum:
"actor"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* consent_scope ·
string (enum) · $ref ./event-payload.schema.json#/$defs/consent_grant_payload/properties/consent_scopeWhat kind of contact is consented to. 'invite' = peer may send Realm / Strand invites; 'direct_message' = peer may initiate 1:1 message; 'voice_call' / 'video_call' = peer may initiate WebRTC call; 'presence' = peer may observe presence; 'any' = full consent across all consent scopes.
enum:
"invite" "voice_call" "video_call" "presence" "any"not_before ·
string (date-time) · format=date-time · $ref ./event-payload.schema.json#/$defs/consent_grant_payload/properties/not_beforeCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$expires_at ·
string (date-time) · format=date-time · $ref ./event-payload.schema.json#/$defs/consent_grant_payload/properties/expires_atCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$constraints · array<object> · $ref ./event-payload.schema.json#/$defs/consent_grant_payload/properties/constraints
Optional consent-specific constraints (rate limits, time-of-day windows, device restrictions). v1 does not standardise constraint types beyond capability constraint vocabulary.
items ·
objectevidence_ref ·
string · $ref ./event-payload.schema.json#/$defs/consent_grant_payload/properties/evidence_refOptional reference to claim disclosure, presentation response, or invite proof that triggered this consent (audit trail).
reason ·
stringReason the holder recorded when granting.
* status ·
string (enum)Reducer-derived lifecycle status materialised by the registered consent_status derivation; an author-supplied value MUST be rejected rather than trusted. revoked is terminal: zh/identity/consent-model.md section 3.2 rejects a repeat revoke, and a revoked consent_id is never revived.
enum:
"active" "revoked"revoked_at ·
string (date-time) · format=date-time · $ref ./event-payload.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$revoked_reason ·
stringProjected from ak.consent.revoke payload.reason. Named apart from reason so the grant-time reason survives the close.
oneOf · oneOf[52] · object · $ref #/$defs/moderation_state_result
Registered projection of one moderated target. governance/content-moderation.md section 5.3 keys the set per target and folds several issuers' active records into one effective decision at read time; dismiss closes a report queue item and folds to none. payload.expected_revision of ak.moderation.decision.lift names this result's revision, which is why the lift is stale-checkable without the set carrying a lifecycle axis.
* selector · object
* kind ·
const "moderation_state"enum:
"moderation_state"* target_ref ·
string · $ref ./event-payload.schema.json#/$defs/object_refpattern:
^((?:ak:realm:[A-Za-z0-9_-]{44}|ak:(circle|space|actor_profile|strand|message|morph|relation|view|event|grant|invite|call|report):[A-Za-z0-9_-]{44}|ak:(policy|blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})|ak:blob:(sha256|blake3):[0-9a-f]{64}|did:[^\s]+|(sha256|blake3):[0-9a-f]{64})$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/moderation_state_value
Closed value of the moderation_state typed current result: the canonically sorted dot set of committed moderation assertions on one target. The join is the keyed-set union of models/common-fields.md section 2, which that section makes commutative, associative, idempotent and order-independent. Both writers project keyed_set_add and NEITHER removes a dot: that section says a family carrying concurrent assertions MUST express revocation as one more assertion, and governance/content-moderation.md section 5.3 has several issuers' records active at once, so a lift that deleted the decision dot would silently drop one side of a concurrent (decision, lift) pair and make the audit view unrebuildable. The active decision set and the hard_deny > quarantine > require_review > none fold of that section are read-side folds above this set and MUST NOT be stored as a second state.
* assertions · array<$ref #/$defs/moderation_decision_entry>
items · object · $ref #/$defs/moderation_decision_entry
One tagged entry of the moderation_state typed current result. The tag is the canonical dot of the accepted Event write that produced it; the value is the complete decision or lift payload of that Event, unassembled. The asserting issuer and the polarity are read from the dot's signed envelope and from which of the two payload branches matched, per models/common-fields.md section 2.
* tag_id ·
string · $ref #/$defs/canonical_event_dotStable tag of one registered reducer write: the canonical <event_id>:<write_index> dot of zh/models/event-and-patch.md section 2.4.2. A bare event_id is never a valid tag. Canonical dot-set order compares the complete event_id by unsigned UTF-8 bytes, then write_index as an integer (2 before 10). Index encoding has no leading zeros. Duplicate dots and conflicting values for one dot are rejected; sorting is not winner or causal ordering.
pattern:
^ak:event:[A-Za-z0-9_-]{44}:(0|[1-9][0-9]{0,2})$* value · oneOf[2]
oneOf · oneOf[0] · object · $ref ./event-payload.schema.json#/$defs/moderation_decision_payload
Payload for ak.moderation.decision. A committed moderation decision that writes a keyed_set_add effect onto the moderation_state typed current result whose subject is the canonical string of target_ref. Multiple active adds fold by hard_deny > quarantine > require_review > none. dismiss is valid only when target_ref identifies the report Event being closed and contributes none to the content verdict fold. Runtime allow and soft_deny remain out-of-band outcomes. The actor MUST independently hold the registered ak.moderation.decision capability.
* target_ref ·
$ref #/$defs/object_ref · $ref #/$defs/object_refThe moderated target (event / object). Canonical string of this ref is the moderation_state typed current result subject.
* decision ·
string (enum)committed moderation-state decision verb. dismiss only resolves a report queue item and does not loosen the target content verdict. allow and soft_deny are out-of-band runtime outcomes.
enum:
"hard_deny" "quarantine" "require_review" "dismiss"* issuer_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* request_canonical_digest ·
$ref #/$defs/digest · $ref #/$defs/digestJCS SHA-256 digest of the moderated request or Event preview. It is part of the projected element VALUE, not of the element tag: a keyed_set_add tag is exactly the canonical <event_id>:<write_index> dot, so no payload member ever enters set identity.
action ·
string (enum)Optional finer-grained §5.3 moderation_policy action family entry that the decision verb maps to (content-moderation.md §8.1).
enum:
"deny_join" "deny_restricted_join" "deny_invite" "deny_write" "deny_federation" "quarantine_message" "require_review" "redact_on_accept" "shadow_collapse"reason_code ·
stringMachine-readable diagnostic. Values that cross service or federation boundaries MUST be registered in error-code-registry.json reason_codes.
pattern:
^[a-z][a-z0-9_]{0,63}$reason ·
stringeffective_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampexpires_at ·
$ref #/$defs/nullable_timestamp · $ref #/$defs/nullable_timestamponeOf · oneOf[1] · object · $ref ./event-payload.schema.json#/$defs/moderation_decision_lift_payload
Payload for ak.moderation.decision.lift. The governance Station resolves decision_ref to the active decision for target_ref and applies the lift at exactly expected_revision.
* target_ref ·
$ref #/$defs/object_ref · $ref #/$defs/object_refThe moderated target whose moderation_state typed current result the lift mutates. Same typed current result subject as the original ak.moderation.decision.
* decision_ref ·
$ref #/$defs/event_ref · $ref #/$defs/event_refReference to the prior ak.moderation.decision Event whose committed tag is being removed.
* expected_revision · object · $ref ./typed-current-result.schema.json#/$defs/revision
Exact current moderation-target revision the producer observed. A different current revision rejects the Event as stale; exact retry remains idempotent. It is the typed revision of the value the producer read, so the compare-and-set names the same {commit_id, stream_position} the typed current result carries. A producer-chosen integer would be a producer-side order, which the authority-commit model does not have.
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integerreason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$reason ·
stringeffective_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[53] · object · $ref #/$defs/object_redaction_result
Registered projection of one redaction subject. The subject is the canonical typed-id string of the redaction target, taken verbatim: ak.message.redact carries it in payload.message_id and the cross-object ak.redaction in payload.target_ref, whose schema mechanically excludes ak:message:. A reducer MUST NOT canonicalize an ak:event: spelling into the typed id of the object that Event derived.
* selector · object
* kind ·
const "object_redaction"enum:
"object_redaction"* target_ref ·
string · $ref ./event-payload.schema.json#/$defs/object_refpattern:
^((?:ak:realm:[A-Za-z0-9_-]{44}|ak:(circle|space|actor_profile|strand|message|morph|relation|view|event|grant|invite|call|report):[A-Za-z0-9_-]{44}|ak:(policy|blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})|ak:blob:(sha256|blake3):[0-9a-f]{64}|did:[^\s]+|(sha256|blake3):[0-9a-f]{64})$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/object_redaction_value
Closed value of the object_redaction typed current result: the canonically sorted dot set of committed redaction assertions on one subject. The join is the keyed-set union of models/common-fields.md section 2. Both writers project keyed_set_add and neither removes a dot, because redaction is terminal and audit-sealed and a removal would erase the audit record of the redaction itself. models/event-and-patch.md section 4.2.4 fixes what this value depends on: the two target spellings of one event-derived token are two independent subjects that never merge, the ak:event: spelling trims that Event by preserve[] and MUST NOT move any object state, and several assertions may stand on one subject with no ordering rule. The object's own state=redacted and message.redaction_ref stay where they are and MUST NOT be mirrored here.
* assertions · array<$ref #/$defs/object_redaction_entry>
items · object · $ref #/$defs/object_redaction_entry
One tagged entry of the object_redaction typed current result. The tag is the canonical dot of the accepted Event write that produced it; the value is the complete redact payload of that Event, unassembled. models/event-and-patch.md section 4.2.4 says several redactions may stand on one subject and deliberately registers no rule for choosing among them, which is why each one keeps its own dot instead of replacing the previous value.
* tag_id ·
string · $ref #/$defs/canonical_event_dotStable tag of one registered reducer write: the canonical <event_id>:<write_index> dot of zh/models/event-and-patch.md section 2.4.2. A bare event_id is never a valid tag. Canonical dot-set order compares the complete event_id by unsigned UTF-8 bytes, then write_index as an integer (2 before 10). Index encoding has no leading zeros. Duplicate dots and conflicting values for one dot are rejected; sorting is not winner or causal ordering.
pattern:
^ak:event:[A-Za-z0-9_-]{44}:(0|[1-9][0-9]{0,2})$* value · oneOf[2]
oneOf · oneOf[0] · object · $ref ./event-payload.schema.json#/$defs/message_redact_payload
Payload for ak.message.redact, the object-scoped redact kind registered for Message. Message is the only object that enters state=redacted through its own kind rather than a cross-object ak.redaction, which is why message.schema.json materializes redaction_ref (models/common-fields.md 5.2). message_id is the single target carrier, so the object_redaction typed current result subject is always the Message typed ID.
* message_id ·
$ref #/$defs/message_id · $ref #/$defs/message_idtrack_name ·
$ref #/$defs/track_name · $ref #/$defs/track_nameActive track_name of the redacted message's parent Strand. Optional: when omitted, reducers MUST resolve from the existing message. When present, MUST equal that resolved track_name.
reason ·
stringpreserve · array<string>
items ·
stringmimi_provenance ·
$ref #/$defs/mimi_message_provenance · $ref #/$defs/mimi_message_provenanceoneOf · oneOf[1] · object · $ref ./event-payload.schema.json#/$defs/cross_object_redaction_payload
Payload for the cross-object ak.redaction. Shares the object_redaction typed current result family with ak.message.redact but carries a target set that mechanically excludes Message: message_id is not a member and target_ref cannot spell ak:message:. target_ref is the single target carrier; its lexical space covers both object targets and ak:event: targets, so the typed current result subject is well defined without a coalesce.
* target_ref ·
$ref #/$defs/cross_object_redaction_target_ref · $ref #/$defs/cross_object_redaction_target_refreason ·
stringpreserve · array<string>
items ·
stringoneOf · oneOf[54] · object · $ref #/$defs/organization_moderation_policy_result
Registered projection of one Organization's moderation policy document, selected by the Organization did_core_id.
* selector · object
* kind ·
const "organization_moderation_policy"enum:
"organization_moderation_policy"* organization_id ·
string · $ref ./event-payload.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/organization_moderation_policy_value
* policy_id ·
stringpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* policy_scope ·
$ref #/$defs/organization_moderation_policy_scope · $ref #/$defs/organization_moderation_policy_scope* rules · array<$ref #/$defs/organization_moderation_policy_rule>
items ·
$ref #/$defs/organization_moderation_policy_rule · $ref #/$defs/organization_moderation_policy_rulenot_before ·
$ref #/$defs/timestamp · $ref #/$defs/timestampexpires_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[55] · object · $ref #/$defs/view_result
Registered projection of one View. models/views.md section 3.2 is normative that ak.view.create, ak.view.update and ak.view.reconcile write ONE family: definition is the complete view.schema.json object and not a second business object, and three authority chains for one View would leave ak.view.update's apply_patch writing onto a result that was never written, which the current-value contract forbids filling with a registered initial_value. create derives the subject from its own event_id; update and reconcile name it in payload.view_id.
* selector · object
* kind ·
const "view"enum:
"view"* view_id ·
stringpattern:
^ak:view:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · allOf[2] · $ref #/$defs/view_value
Closed value of the view typed current result: the whole View definition object. models/views.md section 3.2 forbids storing the self-reportable id here -- the reader derives it from the subject -- so that ak.view.create's object snapshot and ak.view.reconcile's definition leave exactly one value shape in one family.
allOf · allOf[0] · object · $ref ./view.schema.json
allOf · allOf[0] ·
$ref #/$defs/kind_config_exclusivity · $ref #/$defs/kind_config_exclusivityallOf · allOf[1] ·
?id ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:view:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.view.v1"enum:
"ak.schema.view.v1"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* kind ·
string (enum)enum:
"collection" "timeline" "graph" "document" "composite"renderer ·
$ref #/$defs/view_renderer · $ref #/$defs/view_renderertitle ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_512NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$visibility ·
string (enum)View sharing visibility. Private views are actor-private account data; shared views are canonical Realm objects.
enum:
"private" "shared"* state ·
string (enum)Required View lifecycle state. Shared View removal is an ak.view.update patch to tombstoned; tombstoned is terminal.
enum:
"active" "tombstoned"state_changed_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampReducer-derived timestamp of the ak.view.update that transitioned state to tombstoned. Actor-supplied values MUST be rejected.
* query ·
$ref #/$defs/query · $ref #/$defs/queryvisible_fields · array<$ref #/$defs/field_path>
items ·
$ref #/$defs/field_path · $ref #/$defs/field_pathlayout ·
objectcollection ·
$ref #/$defs/collection_config · $ref #/$defs/collection_configtimeline ·
$ref #/$defs/timeline_config · $ref #/$defs/timeline_configgraph ·
$ref #/$defs/graph_config · $ref #/$defs/graph_configdocument ·
$ref #/$defs/document_config · $ref #/$defs/document_configdashboard ·
$ref #/$defs/dashboard_config · $ref #/$defs/dashboard_config* created_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampupdated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idupdated_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp(^x_[a-z][a-z0-9_]{0,63}$) ·
anyallOf · allOf[1] ·
?oneOf · oneOf[56] · object · $ref #/$defs/policy_result
Registered projection of one Policy document. models/governance-objects.md section 3.2: ak.policy.set is the only writer, its payload is {policy_id, value} for ordinary Policy/RecoveryPolicy, and {policy_id, expected_revision, value} for Agent/Applet management Policy with exact nullable CAS; value.schema selects the Policy or RecoveryPolicy family and semantic admission requires the outer policy_id to equal the document's own id verbatim. rules[] is a required non-empty member OF this value and the whole priority / default_effect evaluation of that section runs over it, so a rule is never a subject of its own. The separate ak.policy.rule Event kind that used to assert one rule at a time is deleted: it carried no policy_id, so its rule_id named nothing resolvable, and rule editing submits the whole authorized Policy document through ak.policy.set.
* selector · object
* kind ·
const "policy"enum:
"policy"* policy_id ·
string · $ref ./event-payload.schema.json#/$defs/policy_set_state_payload/properties/policy_idpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · oneOf[2] · $ref #/$defs/policy_value
oneOf · oneOf[0] · object · $ref ./policy.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?* id ·
stringpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* schema ·
const "ak.schema.policy.v1"enum:
"ak.schema.policy.v1"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* policy_kind ·
string (enum)enum:
"access" "encryption" "retention" "federation" "moderation" "discoverability" "join" "history_access" "plaintext_visibility" "media" "applet" "agent"* rules · array<$ref #/$defs/policy_rule>
items ·
$ref #/$defs/policy_rule · $ref #/$defs/policy_rule* default_effect ·
string (enum)enum:
"allow" "deny" "quarantine" "require_review"default_review_requirement ·
$ref #/$defs/management_review_requirement · $ref #/$defs/management_review_requirementdefault_operations · array<string (enum)>
Required when a managed default is require_review: only these review-capable operations use that default; nonselected operations default deny unless an explicit rule matches.
items ·
string (enum)enum:
"join" "publish" "create_bot" "map_ghost"priority ·
integernot_before ·
$ref #/$defs/timestamp · $ref #/$defs/timestampexpires_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* created_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampupdated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idupdated_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp(^x_[a-z][a-z0-9_]{0,63}$) ·
anyoneOf · oneOf[1] · object · $ref ./recovery-policy.schema.json
Normative grammar for an account's PCR recovery policy. Bound through signed control events to one exact AccountId and its local unique PCR lineage; receivers reject recovery and pcr_recovery device authorization whose proof family or optional DID-root factor is not allowed by the currently accepted policy.
* schema ·
const "ak.schema.recovery_policy.v1"enum:
"ak.schema.recovery_policy.v1"* policy_id ·
stringpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* version ·
integerMonotonically increasing counter scoped by the exact account_id. Receivers MUST reject a publish whose version is not strictly greater than the currently accepted policy.
* supersedes_id · oneOf[2]
Predecessor policy_id. Null only for the genesis policy of an exact account.
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
stringpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* trust_domain ·
string · $ref ./common-ids.schema.json#/$defs/trust_domainDeployment-scope trust domain identifier the policy applies to. Cross-domain proofs MUST fail.
pattern:
^ak:trust_domain:[a-z0-9][a-z0-9._\-:]{0,127}$cooldown_seconds ·
integerMinimum wall-clock delay, in seconds, between recovery session creation and acceptance of a recovery proof for that session. Receivers MUST reject a proof submitted earlier. Absence is no delay; the value is a signed policy constraint and MUST NOT be ignored.
* issued_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampnot_before ·
$ref #/$defs/timestamp · $ref #/$defs/timestampexpires_at · oneOf[2]
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* auth_data · object
* verification_method ·
$ref #/$defs/did_url · $ref #/$defs/did_urlDID URL identifying the authorized issuer: founding device after genesis; current-generation accepted device for later updates; identity root for re-anchor; or a coordinator satisfying the superseded policy quorum. Receivers resolve this semantic authority from accepted principal-control state, not from arbitrary DID Document membership.
* signature_algorithm ·
string (enum)enum:
"Ed25519"* signature ·
stringbase64url signature over UTF8('ak.identity.recovery_policy.signature.v1\n') followed by RFC 8785 JCS of all present top-level policy members except auth_data. The closed policy shape fixes the projection; absent optional members are omitted and null is retained only where the schema explicitly admits null.
pattern:
^[A-Za-z0-9_-]+$* methods · array<$ref #/$defs/recovery_method>
Single signed source of recovery acceptance and derived publication authority. Each kind occurs at most once (semantic MUST). Entries are independent OR alternatives; device_quorum.k counts distinct eligible member devices within that entry and MUST NOT exceed its member count. Empty methods is explicit policy revocation. did_root is an opt-in to validated DID history/pre-rotation authority, never an accepted device key. Every published entry MUST be executable by the receiving deployment; no constraint may be silently discarded.
items ·
$ref #/$defs/recovery_method · $ref #/$defs/recovery_method(^x_[a-z][a-z0-9_]{0,63}$) ·
anyoneOf · oneOf[57] · object · $ref #/$defs/device_authorization_result
Current authorization of one device inside its principal control Realm (family device_authorization). The selector is the device_id alone: the PCR already fixes the account, so an account_id selector component would be a second truth. zh/crypto-media/device-lifecycle.md section 5.5.1 is authoritative.
* selector · object
* kind ·
const "device_authorization"enum:
"device_authorization"* device_id ·
string · $ref ./event-payload.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/device_authorization_value
Closed value of the device_authorization typed current result, fixed by zh/crypto-media/device-lifecycle.md section 5.5.1. One accepted ak.device.authorize replaces it whole; there is no partial patch. Every member but device_authorize_event_id is a verbatim copy of the signed payload, and that one member comes from this Event's own envelope event_id because the payload MUST NOT carry it. device_status is deliberately absent: section 5.5.3 makes the lifecycle axis a read-side fold over this result, the revocation proposal set, the current generation and verified conflict evidence, so storing it here would be a second, staler truth. attested_at and the attestation's own expires_at are absent for the same reason in reverse: they are freshness coordinates of the section 8.2 device_projection_attestation, which is a DOWNSTREAM signed projection of this result and MUST NOT define it. authorization_window is not a member either -- it is the paired presentation of not_before and expires_at on the keys/query surface. No account_id or principal_id copy appears: the PCR and the Event envelope already fix them.
* device_public_key_did ·
string · $ref ./event-payload.schema.json#/$defs/non_empty_stringThe device signing key. Section 8.2 names this same value device_signing_key_did on the keys/query surface; that is one value under two surface names, never two facts.
* hpke_key ·
string · $ref ./event-payload.schema.json#/$defs/non_empty_string* algorithms · array<$ref #/$defs/non_empty_string> · $ref ./event-payload.schema.json#/$defs/string_list
Already UTF-8 bytewise sorted and deduplicated by admission.
items ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string* device_key_algorithm ·
const "Ed25519"enum:
"Ed25519"* authorized_by · oneOf[2] · $ref ./event-payload.schema.json#/$defs/device_or_principal_ref
oneOf · oneOf[0] ·
$ref #/$defs/device_id · $ref #/$defs/device_idoneOf · oneOf[1] ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* authorization_binding_kind ·
string (enum)enum:
"registration_anchor" "pcr_recovery" "accepted_device" "applet_managed_delegation"* authorized_generation_ref ·
integer · $ref ./recovery-session.schema.json#/$defs/pcr_generation_refThe PCR generation this authorization was accepted under. Section 5.5.2 puts it on the wire rather than deriving it, because no expected_state_digest freezes this Event's pre-state.
* not_before ·
string (date-time) · format=date-time · $ref ./event-payload.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$expires_at · oneOf[2] · $ref ./event-payload.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[1] ·
nullscopes · array<$ref #/$defs/non_empty_string> · $ref ./event-payload.schema.json#/$defs/string_list
items ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringapplet_id ·
string · $ref ./common-ids.schema.json#/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$recovery_session_id ·
stringpattern:
^ak:recovery_session:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$pairing_challenge_transcript_digest ·
string · $ref ./event-payload.schema.json#/$defs/digestSection 5.2.2 requires the accepted payload to keep it so the target signature stays reverifiable after the staged short-link record is cleaned up.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* device_signature · oneOf[2] · $ref ./event-payload.schema.json#/$defs/signature_material
oneOf · oneOf[0] ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringoneOf · oneOf[1] ·
object* device_authorize_event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$oneOf · oneOf[58] · object · $ref #/$defs/device_generation_result
Singleton PCR-local device generation fence (family device_generation). The selector carries no component beyond its kind: one principal control Realm has exactly one generation. Both writers are registered Event kinds, which is why this family has no genesis-only initializer -- the registration_anchor branch of ak.device.authorize IS the pcr_genesis_unit's second member.
* selector · object
* kind ·
const "device_generation"enum:
"device_generation"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/device_generation_value
Closed value of the device_generation typed current result: one member, fixed by zh/crypto-media/device-lifecycle.md section 5.5.4. The keys/query device_generation_state object presents only this member; there is no generation-level status.
* current_device_generation_ref ·
integer · $ref ./recovery-session.schema.json#/$defs/pcr_generation_refInitialized to 1 by the registration_anchor ak.device.authorize of the pcr_genesis_unit and advanced only by ak.device.reanchor to its new_device_generation. It is not and MUST NOT be derived from a DID versionId.
oneOf · oneOf[59] · object · $ref #/$defs/device_revocation_proposals_result
Accepted revocation proposals against one device (family device_revocation_proposals), keyed by device_id inside its principal control Realm. ak.schema.device_revocation_state.v1 in device-revocation-state.schema.json is the READ-SIDE fold of this set, not its write shape: its target_device_authorize_event_id and target_device_generation_ref come from joining the device_authorization result of the same device_id, accepted_at / acceptance_seq from the accepting transaction, and committed_at / denied_actions from the covering command result. That is why a producer never self-reports a derived pending selector.
* selector · object
* kind ·
const "device_revocation_proposals"enum:
"device_revocation_proposals"* device_id ·
string · $ref ./event-payload.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/device_revocation_proposals_value
Closed value of device_revocation_proposals: the canonically sorted dot set of accepted revocation proposals against one device. It is a keyed set under models/common-fields.md section 2 -- commutative, associative, idempotent, order-independent -- and nothing ever removes a dot. This is what makes 'several transactions count independently, rejecting one does not clear another' (zh/security/server-threat-model.md) structural rather than a rule an implementation could miss: each proposal is its own element and each element folds only its own covering command result.
* proposals · array<$ref #/$defs/device_revocation_proposal_entry>
items · object · $ref #/$defs/device_revocation_proposal_entry
One tagged element of device_revocation_proposals. The tag is the canonical dot of the accepted ak.device.revoke write that produced it -- that dot's event_id is the proposal_event_id of ak.schema.device_revocation_state.v1 -- and the value is that Event's complete payload, unassembled. The element is immutable and no second Event rewrites it: pending / rejected / revoked is a fold of this element against the committed command result of the RealmCommit that covers it (zh/crypto-media/device-lifecycle.md section 5.5.3).
* tag_id ·
string · $ref #/$defs/canonical_event_dotStable tag of one registered reducer write: the canonical <event_id>:<write_index> dot of zh/models/event-and-patch.md section 2.4.2. A bare event_id is never a valid tag. Canonical dot-set order compares the complete event_id by unsigned UTF-8 bytes, then write_index as an integer (2 before 10). Index encoding has no leading zeros. Duplicate dots and conflicting values for one dot are rejected; sorting is not winner or causal ordering.
pattern:
^ak:event:[A-Za-z0-9_-]{44}:(0|[1-9][0-9]{0,2})$* value · object · $ref ./event-payload.schema.json#/$defs/device_revoke_payload
Payload for ak.device.revoke. Its exact AccountId subject is derived exclusively from the Event envelope actor_id; the payload MUST NOT mirror a principal_id. The revocation's control-plane authorization basis is the current authority-committed state (covered by the canonical Event bytes and producer_proof); its permanent cutoff is the accepted RealmCommit covering this Event. First durable canonical acceptance atomically creates ak.schema.device_revocation_state.v1 revocation_pending for the exact reducer-derived current device authorization and generation. The payload carries no checkpoint or generation field, and producers cannot self-report derived pending selectors.
* device_id ·
$ref #/$defs/device_id · $ref #/$defs/device_id* revoked_by ·
$ref #/$defs/device_or_principal_ref · $ref #/$defs/device_or_principal_ref* revoked_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* reason ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$proof ·
$ref #/$defs/signature_material · $ref #/$defs/signature_materialoneOf · oneOf[60] · object · $ref #/$defs/agent_action_approval_result
* selector · object
* kind ·
const "agent_action_approval"enum:
"agent_action_approval"* approval_id · allOf[2] · $ref ./event-payload.schema.json#/$defs/agent_action_approve_payload/properties/approval_id
allOf · allOf[0] ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/agent_action_approve_payload
Controller-signed security command binding one complete pre-authored Event by content-derived EventId. The canonical Event bytes exist before approval, avoiding any digest or RealmCommit self-reference. Confirmation atomically consumes the nonce and authorizes only that exact Event.
* approval_id · allOf[2]
allOf · allOf[0] ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)request_id · allOf[2]
allOf · allOf[0] ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)draft_id · allOf[2]
allOf · allOf[0] ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)* agent_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* proposed_action ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string* target ·
$ref #/$defs/agent_action_target · $ref #/$defs/agent_action_target* approved_event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$draft_content_digest ·
$ref #/$defs/digest · $ref #/$defs/digest* approval_nonce ·
stringAt least 128 bits of controller-generated entropy; one immutable allocation per controller ActorId and target Realm. It cannot be released or reassigned.
pattern:
^[A-Za-z0-9_-]{22,86}$* expires_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampInclusive confirmation deadline judged only against signed RealmCommit committed_at with zero tolerance: the covering commit of this confirmation and the covering commit of the approved Event MUST each have committed_at <= expires_at. Envelope created_at is display-only and is not compared; no Station-local current time is read.
oneOf · oneOf[61] · object · $ref #/$defs/agent_sidecar_exchange_controls_result
* selector · object
* kind ·
const "agent_sidecar_exchange_controls"enum:
"agent_sidecar_exchange_controls"* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* source_context_ref · oneOf[2] · $ref ./event-payload.schema.json#/$defs/sidecar_context_attach_payload/properties/source_context_ref
oneOf · oneOf[0] · object
* kind ·
const "strand"enum:
"strand"* strand_id ·
$ref #/$defs/strand_id · $ref #/$defs/strand_idoneOf · oneOf[1] · object
* kind ·
const "relation"enum:
"relation"* relation_id ·
$ref #/$defs/relation_id · $ref #/$defs/relation_id* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/agent_sidecar_exchange_controls_value
* assertions · array<$ref #/$defs/agent_sidecar_exchange_control_entry>
items · object · $ref #/$defs/agent_sidecar_exchange_control_entry
* tag_id ·
string · $ref #/$defs/canonical_event_dotStable tag of one registered reducer write: the canonical <event_id>:<write_index> dot of zh/models/event-and-patch.md section 2.4.2. A bare event_id is never a valid tag. Canonical dot-set order compares the complete event_id by unsigned UTF-8 bytes, then write_index as an integer (2 before 10). Index encoding has no leading zeros. Duplicate dots and conflicting values for one dot are rejected; sorting is not winner or causal ordering.
pattern:
^ak:event:[A-Za-z0-9_-]{44}:(0|[1-9][0-9]{0,2})$* value · object · $ref ./event-payload.schema.json#/$defs/agent_sidecar_exchange_control_payload
Outer payload for ak.agent.sidecar.exchange.control. sidecar_id and source_context_ref route the Event inside a native Sidecar scope; encrypted_payload plaintext MUST validate as agent-sidecar-exchange-control.schema.json. Admission MUST require matching scope_ref.kind=sidecar and actor_id equal to the Sidecar controller.
* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* source_context_ref ·
$ref #/$defs/sidecar_context_attach_payload/properties/source_context_ref · $ref #/$defs/sidecar_context_attach_payload/properties/source_context_ref* encrypted_payload ·
$ref #/$defs/encrypted_envelope · $ref #/$defs/encrypted_envelopeoneOf · oneOf[62] · object · $ref #/$defs/applet_discovery_result
* selector · object
* kind ·
const "applet_discovery"enum:
"applet_discovery"* applet_id ·
string · $ref ./common-ids.schema.json#/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · allOf[2] · $ref ./event-payload.schema.json#/$defs/applet_discovery_state_payload/properties/value
allOf · allOf[0] ·
$ref #/$defs/resource_discovery_state_value · $ref #/$defs/resource_discovery_state_valueallOf · allOf[1] · object
resource_kind ·
const "applet"enum:
"applet"oneOf · oneOf[63] · object · $ref #/$defs/applet_registration_result
* selector · object
* kind ·
const "applet_registration"enum:
"applet_registration"* applet_id ·
string · $ref ./common-ids.schema.json#/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/applet_registration_payload
Payload for ak.applet.registration. Durable Realm-history Event registering an Applet (bridge / bot / Ghost Actor namespace). Field vocabulary: zh/extensions/applet-integration.md §4 and zh/extensions/applet-schema.md §1 (the authoritative machine schema is applet.schema.json, which documents the applet object snapshot; the wire Event payload is this closed class). An Applet's capability to enter a Realm MUST be granted by that Realm's owner / admin / Realm-policy-authorized administrator actor and checked by the Station authorization capability. The formal Event is signed by that installing administrator and admitted by the target Station; payload.proof is the exact controller-signed package proof and is not an Event proof.
* applet_id ·
string · $ref ./common-ids.schema.json#/$defs/applet_idStable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern:
^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* service_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* controller_principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* base_url ·
string (uri) · format=uripattern:
^https://* claimed_profiles · array<$ref #/$defs/profile_id>
Canonical Applet implementation profiles copied from the accepted package. These durable claims are the authority source for profile-bound grant rules.
items ·
$ref #/$defs/profile_id · $ref #/$defs/profile_id* protocols ·
$ref #/$defs/string_list · $ref #/$defs/string_list* namespaces · object · $ref applet-package.schema.json#/$defs/applet_namespaces
Applet namespace claims (actors / realms / handles patterns). Namespace match alone never grants write capability.
* actors · array<$ref #/$defs/actor_namespace_entry>
items ·
$ref #/$defs/actor_namespace_entry · $ref #/$defs/actor_namespace_entry* realms · array<$ref #/$defs/namespace_entry>
items ·
$ref #/$defs/namespace_entry · $ref #/$defs/namespace_entry* handles · array<$ref #/$defs/namespace_entry>
items ·
$ref #/$defs/namespace_entry · $ref #/$defs/namespace_entry* receive_events ·
boolean* receive_signals ·
boolean* rate_limited ·
boolean* requested_scopes · array<$ref #/$defs/non_empty_string>
items ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string* registration_epoch ·
$ref #/$defs/digest · $ref #/$defs/digest* webhook_auth · object · $ref applet-package.schema.json#/$defs/webhook_auth
HTTP message signature verification policy for transaction push. key_ref is the Applet service DID URL used to verify the app/bridge->arkret inbound HTTP message signature. Verifiers MUST take its bare controller did, validate it with the registered method adapter, and require project(did) to equal service_id (did_core_id); direct DID/core-id string comparison is forbidden. The key is bound to the effective registration_epoch. accepted_signature_algorithms pins the acceptable RFC 9421 signature algorithms.
* key_ref ·
$ref #/$defs/did_url · $ref #/$defs/did_urlDID URL under an Applet service did whose registered adapter projection equals service_id. For app/bridge->arkret inbound transaction push, Signature-Input keyid MUST equal this value. Node->Applet pushes verify the Arkret source service did/key binding selected by the Source-Service-ID did_core_id, not this field.
* accepted_signature_algorithms · array<$ref #/$defs/http_message_signature_algorithm>
items ·
$ref #/$defs/http_message_signature_algorithm · $ref #/$defs/http_message_signature_algorithmsignature_header ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string* kind ·
string (enum)enum:
"http_message_signature"(^x_[a-z][a-z0-9_]{0,63}$) ·
any* manifest · object
Closed package-derived manifest and the sole registration-epoch evidence carrier.
* claimed_profiles · array<$ref #/$defs/profile_id>
items ·
$ref #/$defs/profile_id · $ref #/$defs/profile_id* limits · object · $ref applet-package.schema.json#/$defs/limits
Service-side resource hints derived into the registration manifest.
max_transaction_events ·
integermax_payload_bytes ·
integerrate_limit_per_minute ·
integer(^x_[a-z][a-z0-9_]{0,63}$) ·
any* ghost_policy · object · $ref applet-package.schema.json#/$defs/ghost_policy
Ghost Actor support and accountability template. enabled defaults to false semantics; an explicit boolean is required.
* enabled ·
booleanaccountability_template ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_string(^x_[a-z][a-z0-9_]{0,63}$) ·
any* delegation_policy · object · $ref applet-package.schema.json#/$defs/delegation_policy
Delegated native-user acting request. Defaults to false; enabled MUST be explicit.
* enabled ·
boolean(^x_[a-z][a-z0-9_]{0,63}$) ·
any* e2ee_policy · object · $ref applet-package.schema.json#/$defs/e2ee_policy
MLS join request. Defaults to false; enabled MUST be explicit.
* enabled ·
booleanmls_join_requested ·
boolean(^x_[a-z][a-z0-9_]{0,63}$) ·
anywidget · object · $ref applet-package.schema.json#/$defs/widget
Closed declaration for an Applet UI widget origin, CSP, scoped token capability scope, and consent gate.
* schema ·
const "ak.schema.applet_widget_declaration.v1"enum:
"ak.schema.applet_widget_declaration.v1"* widget_origin · allOf[2]
Canonical HTTPS Web Origin only: lowercase scheme and host plus an optional valid non-default port. Userinfo, path (including a trailing slash), query, fragment, explicit :443, and out-of-range ports are forbidden.
allOf · allOf[0] ·
string (uri) · format=uri · $ref ./common-ids.schema.json#/$defs/web_originCanonical HTTP(S) Web Origin: lowercase scheme/host plus an optional valid non-default effective port. Userinfo, path (including a trailing slash), query, fragment, explicit :80 on HTTP, and explicit :443 on HTTPS are forbidden.
pattern:
^(?:http://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!80$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?|https://(?:\[[0-9A-Fa-f:.]+\]|[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?)(?::(?!443$)(?:[1-9]|[1-9][0-9]{1,3}|[1-5][0-9]{4}|6[0-4][0-9]{3}|65[0-4][0-9]{2}|655[0-2][0-9]|6553[0-5]))?)$allOf · allOf[1] ·
?pattern:
^https://* csp ·
stringContent-Security-Policy that the host client MUST enforce for the widget document.
* token_scope · object
Maximum capability scope for the short-lived widget token.
* actions · array<string>
items ·
stringpattern:
^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$* resources · array<$ref ./resource-selector.schema.json>
items · object · $ref ./resource-selector.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?* kind ·
string (enum)enum:
"realm" "space" "circle" "strand" "message" "morph" "object" "relation" "view" "event" "actor" "schema" "policy" "invite" "notification" "read_cursor" "blob" "*"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$space_id ·
stringpattern:
^ak:space:[A-Za-z0-9_-]{44}$circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$object_kind ·
stringobject_ref ·
stringCanonical object reference. Acceptable typed-id kinds match the v1 resource selector kind enum (see resource-selector-grammar.md §3.1). Notably MUST NOT include 'actor_profile' (use the 'actor' selector with did pattern), nor non-canonical 'board' / 'list' / 'card' / 'subject' / 'room' kinds — board / list / swimlane / calendar bucket are Space objects and MUST use the 'space' kind together with the 'allowed_space_kinds' constraint to restrict which Space kinds the grant covers.
pattern:
^(?:ak:realm:[A-Za-z0-9_-]{44}|ak:(space|circle|strand|message|morph|relation|view|event|invite):[A-Za-z0-9_-]{44}|ak:(policy|blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})$strand_id ·
stringpattern:
^ak:strand:[A-Za-z0-9_-]{44}$message_id ·
stringpattern:
^ak:message:[A-Za-z0-9_-]{44}$morph_id ·
stringpattern:
^ak:morph:[A-Za-z0-9_-]{44}$morph_kind ·
stringrelation_kind ·
stringrelation_id ·
stringpattern:
^ak:relation:[A-Za-z0-9_-]{44}$view_id ·
stringpattern:
^ak:view:[A-Za-z0-9_-]{44}$event_id ·
stringpattern:
^ak:event:[A-Za-z0-9_-]{44}$actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
schema_ref ·
stringpolicy_id ·
stringpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$invite_id ·
stringpattern:
^ak:invite:[A-Za-z0-9_-]{44}$blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$match_scope ·
string (enum)Authorization selector breadth. exact matches only the named resource; realm_wide is valid only for the registered resource kinds with an explicit realm_id. Neither current navigation ancestry nor creation ancestry expands authorization. Hierarchy traversal belongs to queries, not grant matching. The normative algorithm is zh/authz/resource-selector-grammar.md section 6.
enum:
"exact" "realm_wide"realm_ids · array<$ref ./common-ids.schema.json#/$defs/realm_id>
items ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* expires_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$max_ttl_seconds ·
integer(^x_[a-z][a-z0-9_]{0,63}$) ·
any* consent_required ·
boolean(^x_[a-z][a-z0-9_]{0,63}$) ·
any* registration_epoch_evidence · object · $ref applet-registration-epoch-evidence.schema.json
Versioned Applet service DID evidence used to derive a stable registration epoch and Service signer evidence root. Only did:webvh and did:key are accepted; did:web current snapshots cannot support historical producer verification.
allOf · allOf[0] · oneOf[2]
oneOf · oneOf[0] · object
did ·
string · $ref ./common-ids.schema.json#/$defs/webvh_didCanonical bare did:webvh identifier used at method-native registration, document and evidence boundaries. Role admission is enforced separately.
pattern:
^did:webvh:[^\s:/?#]+:[^\s/?#]+$method_version_evidence · object
method ·
const "did:webvh"enum:
"did:webvh"oneOf · oneOf[1] · object
did ·
stringpattern:
^did:key:[^\s/?#]+$method_version_evidence · object
method ·
const "did:key"enum:
"did:key"* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* document_digest ·
string · $ref ./account-operations.schema.json#/$defs/sha256_digestpattern:
^sha256:[0-9a-f]{64}$* method_version_evidence · object · $ref ./applet-registration-epoch-transcript.schema.json#/$defs/did_method_version
oneOf · oneOf[0] · object
* method ·
string (enum)enum:
"did:webvh" "did:key"* unversioned_refetch ·
const falseenum:
falseoneOf · oneOf[1] · object
* method ·
const "did:webvh"enum:
"did:webvh"* unversioned_refetch ·
const falseenum:
false* method ·
stringpattern:
^did:[a-z0-9]+$version_id · allOf[2]
allOf · allOf[0] ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)version_time ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* unversioned_refetch ·
boolean* accepted_signing_keys · array<$ref ./applet-registration-epoch-transcript.schema.json#/$defs/accepted_signing_key>
items · object · $ref ./applet-registration-epoch-transcript.schema.json#/$defs/accepted_signing_key
* key_ref ·
$ref #/$defs/did_url · $ref #/$defs/did_url* public_key_digest ·
$ref #/$defs/digest · $ref #/$defs/digest* proof · object · $ref applet-package.schema.json#/$defs/detached_proof
Controller-DID detached-JWS proof shape, aligned with event-envelope.schema.json#/$defs/proof (the generic non-Event signed-object proof). Non-Event objects bind their canonical payload via payload_digest; Event proofs MUST instead use event_digest and event_proof.
* kind ·
string (enum)enum:
"detached_jws"* verification_method ·
$ref #/$defs/did_url · $ref #/$defs/did_url* payload_digest ·
$ref #/$defs/digest · $ref #/$defs/digest* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampdomain ·
stringaudience · oneOf[2]
oneOf · oneOf[0] ·
stringoneOf · oneOf[1] · array<string>
items ·
string* jws ·
stringpattern:
^[A-Za-z0-9_-]+\.\.[A-Za-z0-9_-]+$(^x_[a-z][a-z0-9_]{0,63}$) ·
any* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[64] · object · $ref #/$defs/key_backup_active_series_result
* selector · object
* kind ·
const "key_backup_active_series"enum:
"key_backup_active_series"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* backup_kind ·
string (enum) · $ref ./key-backup-active-series.schema.json#/$defs/backup_kindenum:
"secret_storage"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./key-backup-active-series.schema.json
Signed principal-control record selecting the backup series for one actor and backup kind. Servers verify the accepted record; ordinary clients consume BackupActiveSeriesState from their Account Station instead of replaying PCR history.
* schema ·
const "ak.schema.key_backup_active_series.v1"enum:
"ak.schema.key_backup_active_series.v1"* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* backup_kind ·
$ref #/$defs/backup_kind · $ref #/$defs/backup_kind* active_series_id ·
$ref #/$defs/backup_series_id · $ref #/$defs/backup_series_id* series_pointer_version ·
integerStrictly monotonic per (actor_id, backup_kind). The first record is 1 and every successor is previous+1; receivers reject rollback, gaps and same-version forks.
* previous_series_ids · array<$ref #/$defs/backup_series_id>
Retained old series used only for read-old-data or erasure transition. MUST NOT be treated as a primary recovery source.
items ·
$ref #/$defs/backup_series_id · $ref #/$defs/backup_series_id* source_commit_ref ·
$ref #/$defs/source_commit_ref · $ref #/$defs/source_commit_refPrincipal Control Realm source RealmCommit and current identity-root device generation under which active_series_id was selected.
* issued_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* auth_data · object
* verification_method ·
$ref #/$defs/did_url · $ref #/$defs/did_url* signature_algorithm ·
string (enum)enum:
"Ed25519"* signature ·
stringbase64url signature over RFC 8785 JCS(record without auth_data.signature). The closed record shape fixes the authenticated projection.
pattern:
^[A-Za-z0-9_-]+$* device_authorize_event_id ·
stringAccepted current-generation ak.device.authorize Event anchoring the device that signed this active-series selection.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$(^x_[a-z][a-z0-9_]{0,63}$) ·
anyoneOf · oneOf[65] · object · $ref #/$defs/member_identity_updates_result
* selector · object
* kind ·
const "member_identity_updates"enum:
"member_identity_updates"* member_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* segment ·
string (enum) · $ref ./event-payload.schema.json#/$defs/member_identity_update_payload/properties/segmentv1 core defines a single full MemberIdentity segment. Narrower segments require a future schema/profile revision that extends this enum or defines a new payload schema; v1 receivers MUST reject unknown segment values.
enum:
"member_identity"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/member_identity_updates_value
* assertions · array<$ref #/$defs/member_identity_update_entry>
items · object · $ref #/$defs/member_identity_update_entry
* tag_id ·
string · $ref #/$defs/canonical_event_dotStable tag of one registered reducer write: the canonical <event_id>:<write_index> dot of zh/models/event-and-patch.md section 2.4.2. A bare event_id is never a valid tag. Canonical dot-set order compares the complete event_id by unsigned UTF-8 bytes, then write_index as an integer (2 before 10). Index encoding has no leading zeros. Duplicate dots and conflicting values for one dot are rejected; sorting is not winner or causal ordering.
pattern:
^ak:event:[A-Za-z0-9_-]{44}:(0|[1-9][0-9]{0,2})$* value · object · $ref ./event-payload.schema.json#/$defs/member_identity_update_payload
Payload for ak.member.identity.update. Append-only replacement event for one Realm-scoped member display/subject projection segment. Service-visible metadata names the segment and the prior events it replaces; the segment body is plaintext or the original encrypted envelope and MUST contain the complete data for that segment. Handle lifecycle is excluded from this event and is governed by ak.schema.handle_claim.v1 issuer claims.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* member_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* segment ·
string (enum)v1 core defines a single full MemberIdentity segment. Narrower segments require a future schema/profile revision that extends this enum or defines a new payload schema; v1 receivers MUST reject unknown segment values.
enum:
"member_identity"replaces · array<object>
Prior ak.member.identity.update events in the same (realm_id, actor_id, segment) that this event supersedes for current profile projection. Referenced events remain immutable history.
items · object
* event_id ·
$ref #/$defs/event_ref · $ref #/$defs/event_ref* payload_digest ·
$ref #/$defs/digest · $ref #/$defs/digestsha256 over RFC 8785 JCS canonical JSON of the replaced event's full payload.identity_payload carrier wrapper ({member_identity: ...} or {encrypted_payload: ...}). Prevents replacing a different payload under a reused or confused event id.
* identity_payload · oneOf[2]
oneOf · oneOf[0] · object
* member_identity · object · $ref ./member-identity.schema.json
Realm-scoped, actor-scoped full member_identity segment. It is carried by ak.member.identity.update in plaintext or inside encrypted-envelope.schema.json. Replacement events that name segment=member_identity MUST carry this complete object. This object discloses subject_actor_id and display_profile for Realm UI projection; handle lifecycle is intentionally excluded and is governed only by ak.schema.handle_claim.v1 issuer claims. Mention / reply / quote / actor attribution MUST use the exact ActorId, never a handle string or a bare principal DID.
* schema ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
…recursion truncated at depth 8; see source schema for full shape
* actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* subject_actor_id ·
…recursion truncated at depth 8; see source schema for full shape
* display_profile ·
…recursion truncated at depth 8; see source schema for full shape
* asserted_at ·
…recursion truncated at depth 8; see source schema for full shape
expires_at ·
…recursion truncated at depth 8; see source schema for full shape
* proof ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* encrypted_payload ·
$ref #/$defs/encrypted_envelope · $ref #/$defs/encrypted_envelopeexpected_state_digest ·
$ref #/$defs/digest · $ref #/$defs/digestOptional optimistic concurrency guard for the current effective set of this (realm_id, member_id, segment). When present, it MUST equal sha256 over RFC 8785 JCS of the array of the exact signed payload objects of every update in that effective set, ordered by carrying event_id ascending (the empty set is []), before applying this event (zh/sync/current-results.md section 2); a mismatch is member_identity_state_mismatch with zero writes. It is distinct from the locally derived identity_payload carrier digest and from a roster member_display_state_digest.
oneOf · oneOf[66] · object · $ref #/$defs/message_revision_result
* selector · object
* kind ·
const "message_revision"enum:
"message_revision"* message_id ·
string · $ref ./event-payload.schema.json#/$defs/message_idpattern:
^ak:message:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · oneOf[2] · $ref #/$defs/message_revision_value
oneOf · oneOf[0] · object · $ref ./event-payload.schema.json#/$defs/message_create_payload
Payload for ak.message.create. If content/encrypted_content contains an audience_mention AST node (for example @all or @here), reducer admission and notification dispatch MUST additionally enforce ak.message.mention.broadcast plus the audience policy / max_recipient / rate-limit rules in zh/models/strand-and-message.md §9.4.3. @here maps to audience="strand_engaged" and is not presence-filtered.
allOf · allOf[0] · oneOf[2]
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?* strand_id ·
$ref #/$defs/strand_id · $ref #/$defs/strand_id* track_name ·
$ref #/$defs/track_name · $ref #/$defs/track_namecontent ·
$ref #/$defs/content_block · $ref #/$defs/content_blockencrypted_content ·
$ref #/$defs/message_encrypted_content · $ref #/$defs/message_encrypted_contentmetadata ·
$ref #/$defs/message_metadata · $ref #/$defs/message_metadataencrypted_metadata ·
$ref #/$defs/message_encrypted_metadata · $ref #/$defs/message_encrypted_metadatablob_refs · array<$ref #/$defs/object_ref>
items ·
$ref #/$defs/object_ref · $ref #/$defs/object_refreply_to_id ·
$ref #/$defs/message_id · $ref #/$defs/message_idOptional creation convenience: the message this one replies to. The reducer records it as the message's reply linkage (lifting it onto the message content) and surfaces it as a replies_to relation in the message projection; it does not require a separate canonical ak.relation event. The materialized Message object itself carries no reply_to scalar. See strand-and-message.md §9.1.
agent_context · object
Auditable authorization context required when an Agent authors the message.
* agent_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* operator_or_controller ·
string* execution_purpose ·
string* authorization_ref ·
stringmimi_provenance ·
$ref #/$defs/mimi_message_provenance · $ref #/$defs/mimi_message_provenancepoll_response_heads · array<$ref #/$defs/poll_response_head>
Each entry binds a poll to the exact response Event being superseded.
items ·
$ref #/$defs/poll_response_head · $ref #/$defs/poll_response_headoneOf · oneOf[1] · object · $ref ./event-payload.schema.json#/$defs/message_revise_payload
Payload for ak.message.revise. Revisions that introduce new direct mentions MAY generate mention notifications only when the implementation can compare against the previous accepted visible revision. Revisions that introduce an audience_mention AST node (including @all / @here mappings) MUST satisfy the same ak.message.mention.broadcast and policy gates as create.
allOf · allOf[0] · oneOf[2]
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* message_id ·
$ref #/$defs/message_id · $ref #/$defs/message_idtrack_name ·
$ref #/$defs/track_name · $ref #/$defs/track_nameActive track_name of the target Strand. Optional on revise/redact: when omitted, reducers MUST resolve from the existing message identified by message_id. When present, MUST equal that resolved track_name.
content ·
$ref #/$defs/content_block · $ref #/$defs/content_blockencrypted_content ·
$ref #/$defs/message_encrypted_content · $ref #/$defs/message_encrypted_contentmetadata ·
$ref #/$defs/message_metadata · $ref #/$defs/message_metadataencrypted_metadata ·
$ref #/$defs/message_encrypted_metadata · $ref #/$defs/message_encrypted_metadatareason ·
stringmimi_provenance ·
$ref #/$defs/mimi_message_provenance · $ref #/$defs/mimi_message_provenanceoneOf · oneOf[67] · object · $ref #/$defs/actor_profile_realm_override_result
* selector · object
* kind ·
const "actor_profile_realm_override"enum:
"actor_profile_realm_override"* actor_profile_id ·
string · $ref ./event-payload.schema.json#/$defs/actor_profile_idpattern:
^ak:actor_profile:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/actor_profile_realm_override_value
* assertions · array<$ref #/$defs/actor_profile_realm_override_entry>
items · object · $ref #/$defs/actor_profile_realm_override_entry
* tag_id ·
string · $ref #/$defs/canonical_event_dotStable tag of one registered reducer write: the canonical <event_id>:<write_index> dot of zh/models/event-and-patch.md section 2.4.2. A bare event_id is never a valid tag. Canonical dot-set order compares the complete event_id by unsigned UTF-8 bytes, then write_index as an integer (2 before 10). Index encoding has no leading zeros. Duplicate dots and conflicting values for one dot are rejected; sorting is not winner or causal ordering.
pattern:
^ak:event:[A-Za-z0-9_-]{44}:(0|[1-9][0-9]{0,2})$* value · object · $ref ./event-payload.schema.json#/$defs/profile_realm_override_payload
Realm-scoped actor profile override payload for ak.profile.realm_override. target_ref is the Actor Profile being overridden; target_realm_id is the Realm where the override applies. resolution, principal_id and actor_kind are forbidden here for the same reasons they are forbidden on the generic profile write surface -- a per-Realm override is still not a place to rebind identity; the object-specific forbidden path set is machine-indexed in registry/reducer-managed-path-registry.json.
* target_ref ·
$ref #/$defs/actor_profile_id · $ref #/$defs/actor_profile_id* target_realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* patch · allOf[4]
allOf · allOf[0] ·
$ref #/$defs/patch · $ref #/$defs/patchallOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?expected_state_digest ·
$ref #/$defs/digest · $ref #/$defs/digestOptional guard over the folded current override: sha256 over RFC 8785 JCS of the display object obtained by applying every accepted assertion patch of this target in accepted commit order to {} ({} when there is none), zh/sync/current-results.md section 2. A mismatch rejects with zero writes.
oneOf · oneOf[68] · object · $ref #/$defs/realm_organization_result
* selector · object
* kind ·
const "realm_organization"enum:
"realm_organization"* organization_id ·
string · $ref ./event-payload.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* relationship ·
string (enum) · $ref ./event-payload.schema.json#/$defs/realm_organization_payload/properties/relationshipRelationship being asserted or revoked for this organization and Realm.
enum:
"owner" "governance" "sponsor" "directory_certifier"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/realm_organization_payload
Organization-side endorsement or revocation for a Realm relationship. Reducer validation MUST require realm_id to match the top-level Event.realm_id, organization_id to identify an Organization principal in accepted registration state, the Realm-side writer to hold ak.realm.admin, and authorization to verify against current organization DID control evidence or a delegated service whose purpose covers this relationship and control_scopes. The stable organization_id is not itself resolvable DID material.
allOf · allOf[0] ·
?* statement_id · allOf[2]
Stable id of this organization statement. It is audit identity, not the reducer typed current result subject; the reducer typed current result subject is (organization_id, relationship).
allOf · allOf[0] ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* organization_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idStable Organization principal identity that endorses, governs, sponsors, certifies, or revokes the Realm relationship. This did_core_id is bound to current Organization DID evidence through accepted registration/resolution state; it is not itself resolvable.
* relationship ·
string (enum)Relationship being asserted or revoked for this organization and Realm.
enum:
"owner" "governance" "sponsor" "directory_certifier"* status ·
string (enum)enum:
"active" "revoked"* control_scopes · array<string (enum)>
Machine-readable scopes covered by the organization's consent. A scope here is an endorsement boundary only; actual Realm control still requires the corresponding Realm policy, governance-Station authority, capability, or service-binding Event.
items ·
string (enum)enum:
"official_badge" "realm_admin" "realm_authority" "moderation_policy" "retention_policy" "directory_listing" "plaintext_visible_service"* issued_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampnot_before ·
$ref #/$defs/timestamp · $ref #/$defs/timestampexpires_at ·
$ref #/$defs/nullable_timestamp · $ref #/$defs/nullable_timestampAdministrative review/renewal hint only. It does not auto-transition account status; a later AccountStatusRecord is required and remains subject to sequence and terminal rules.
supersedes_statement_id · allOf[2]
allOf · allOf[0] ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)revokes_statement_id · allOf[2]
allOf · allOf[0] ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)realm_commit_ref ·
string · $ref common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$organization_policy_ref ·
$ref #/$defs/object_ref · $ref #/$defs/object_refOptional DID-document delegation URL, policy object, governance decision, or attestation reference used to evaluate the statement.
* authorization · object
Organization-side authorization proof. This is independent of the Realm-side ak.realm.admin authorization required to write the event into Realm history.
allOf · allOf[0] ·
?* issuer_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idStable Organization or delegated-service principal identity that issued this statement. The issuer_id is a did_core_id; verification_method and accepted registration/delegation state carry the DID evidence required to verify the issuer.
* issuer_role ·
string (enum)enum:
"organization" "governance_service" "account_authority" "threshold_quorum"* verification_method ·
$ref #/$defs/verification_method · $ref #/$defs/verification_methoddelegation_ref ·
$ref #/$defs/object_ref · $ref #/$defs/object_refRequired when issuer_role is governance_service or account_authority. It MUST resolve to a live organization DID delegation whose purpose covers ak.realm.organization and the requested relationship/control_scopes.
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* signed_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* proof ·
$ref #/$defs/signature_material · $ref #/$defs/signature_materialSignature, threshold transcript, or governance-service attestation over the canonical organization statement binding statement_id, realm_id, organization_id, relationship, status, control_scopes, issued_at, validity window, and statement replacement/revocation fields.
oneOf · oneOf[69] · object · $ref #/$defs/circle_member_state_result
* selector · object
* kind ·
const "circle_member_state"enum:
"circle_member_state"* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$* member_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/circle_member_state_value
Canonical Circle membership register of one complete ActorId. A join value carries the producer-signed parent_membership_revision copied from the accepted Event; no other value carries it. Effective Circle membership is this value being join AND the parent Realm member_state current of the same ActorId, in the same durable cut, being join at exactly this revision on the parent Realm stream (zh/models/circle.md §9.1). No reducer, Station or trigger rewrites this value when the parent membership ends.
allOf · allOf[0] ·
?* membership ·
string (enum) · $ref ./event-payload.schema.json#/$defs/membership_stateCanonical materialized membership state enum shared by ak.member.state (Realm) and ak.circle.member.state (Circle). Invite is a separate pending workflow and is never a member state. `knock` denotes a pending self-authored join request; see governance/join-policy.md §5 and models/circle.md §9.1.
enum:
"join" "knock" "leave" "ban"parent_membership_revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* effective_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$oneOf · oneOf[70] · object · $ref #/$defs/circle_result
Registered projection of one Circle object (zh/models/circle.md). ak.circle.create writes the whole object and the dedicated ak.circle.archive / restore / tombstone kinds move its state member through the mapping zh/models/common-fields.md section 5.2 fixes. The subject carries the object id because only the create Event derives it from its own event_id; every later write names it in the payload.
* selector · object
* kind ·
const "circle"enum:
"circle"* circle_id ·
stringpattern:
^ak:circle:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./circle.schema.json
Circle — an intra-Realm scoped event/message boundary with its own membership, history_access and optional independent MLS group. Parent Realm membership supplies only the current-membership intersection gate; history_access is never dynamically inherited.
allOf · allOf[0] ·
?id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:circle:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.circle.v1"enum:
"ak.schema.circle.v1"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$profile_ref ·
stringOptional create-locked Circle semantic profile discriminator. Ordinary Circles omit it. Profile-specific creation paths MUST persist their registered profile id. Agent Sidecar is a separate ak.schema.agent_sidecar.v1 object and MUST NOT be represented by this field.
pattern:
^ak\.profile\.[a-z0-9_.-]+\.v1$* title ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_256NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$summary ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/short_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$* display ·
$ref #/$defs/display · $ref #/$defs/display* directory_visibility ·
string (enum)Who may see this Circle exists as a directory entry. 'members' means only Circle members see its title/display/member_ids. 'realm_members' exposes directory metadata only and does NOT grant event or history access.
enum:
"members" "realm_members"* join_rule ·
string (enum)public permits parent-Realm members to self-join; invite requires an authorized administrator using ak.circle.member.add.others with the required same-unit audit. v1 has no Circle invitation or acceptance workflow. All joins bind the exact current parent membership revision.
enum:
"invite" "knock" "public"* history_access ·
string (enum)Circle's own governance history range ratchet, initialized by Circle create. The only state-changing update is all_history_for_current_members to since_join; widening is permanently forbidden. It is never dynamically inherited from or capped by the parent Realm history_access, while current access still requires active parent-Realm membership. Standard MLS requires since_join.
enum:
"since_join" "all_history_for_current_members"agent_participation · object
Optional wrapped five-bit Agent ceiling. When present every bit is explicit and may only tighten the parent Realm ceiling.
* agent · object · $ref ./principal-operations.schema.json#/$defs/participation_bits
* reply_message ·
boolean* reaction_add ·
boolean* reaction_remove ·
boolean* accept_third_party_mention ·
boolean* act_on_behalf ·
booleanmls_group_id ·
string · $ref ./common-ids.schema.json#/$defs/mls_group_idRFC 9420 group_id as base64url_no_pad(SHA-256(UTF8("ak.mls.group_id.v1") || 0x00 || canonical_effective_scope_key_bytes(effective_scope))), so exactly 43 characters. Derived by the reducer and the SDK from the effective scope alone; actors never submit it. The v1 formula is the only one: the earlier reversible base64url of the scope key bytes MUST NOT be accepted alongside it. See zh/models/realm-and-space.md section 2.2.
pattern:
^[A-Za-z0-9_-]{43}$* state ·
string (enum)Circle lifecycle state. v1 defines active, archived, and tombstoned only; Circle has no independent freeze or destroy state because parent Realm freeze/destroy applies at the Realm boundary.
enum:
"active" "archived" "tombstoned"state_changed_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* created_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampupdated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idupdated_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[71] · object · $ref #/$defs/realm_search_policy_result
* selector · object
* kind ·
const "realm_search_policy"enum:
"realm_search_policy"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/realm_search_policy_payload
* enabled_profile_refs · array<string (enum)>
items ·
string (enum)enum:
"ak.profile.search.client_index.v1" "ak.profile.search.blind_index.v1" "ak.profile.search.forward_private.v1"* allowed_service_ids · array<$ref #/$defs/did_core_id>
items ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* data_classes · array<string (enum)>
items ·
string (enum)enum:
"encrypted_index" "blind_tokens" "plaintext" "reversible_summary"index_retention_ms ·
integerrevocation_behavior ·
string (enum)enum:
"fail_closed" "drop_stale"leakage_class ·
string (enum)Machine-readable search leakage class. ak.profile.search.blind_index.v1 uses deterministic_token; ak.profile.search.forward_private.v1 requires forward_private; access_hiding is reserved for explicit PIR/ORAM-backed profiles.
enum:
"deterministic_token" "forward_private" "access_hiding"example:
"deterministic_token"token_rotation_cadence_ms ·
integerMaximum intended interval between search token generations for profiles that rotate index keys or OPRF blinds.
oneOf · oneOf[72] · object · $ref #/$defs/rsvp_result
* selector · object
* kind ·
const "rsvp"enum:
"rsvp"* event_ref ·
string · $ref ./event-payload.schema.json#/$defs/strand_idpattern:
^ak:strand:[A-Za-z0-9_-]{44}$* occurrence · oneOf[3] · $ref ./event-payload.schema.json#/$defs/rsvp_set_payload/properties/occurrence
JSON null for the whole series, or the canonical recurrence instance key: YYYY-MM-DD for all-day events and YYYY-MM-DDTHH:MM:SS[Zone] for timed events. The date component MUST be a real proleptic-Gregorian date, not merely match the digit pattern. The producer MUST canonicalize before signing; receivers MUST reject non-canonical keys instead of rewriting them.
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
string (date) · format=date · $ref ./time.schema.json#/$defs/local_dateProleptic Gregorian calendar date with no time, offset, or zone. Not an absolute instant: it resolves to an instant only through an explicitly carried IANA time zone plus TZDB version. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])$oneOf · oneOf[2] ·
stringpattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\[[A-Za-z][A-Za-z0-9_+-]*(?:/[A-Za-z0-9_+-]+)*\]$* responder_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/rsvp_entry
Complete RSVP typed current result value. The whole entry is the current-value projection set value, so the deterministic winner carries the schedule source the responder observed plus the response itself.
oneOf · oneOf[0] ·
?oneOf · oneOf[1] ·
?* schedule_basis_refs · array<$ref #/$defs/event_ref>
The unique schedule revision the responder actually observed, retained in the existing array wire shape as exactly one ak:event: typed id. It is the sole carrier of that association: the payload holds exactly one entry, so no envelope mirror is required and none is defined. Shape admission is decidable from this field alone, without resolving the referenced Event.
items ·
$ref #/$defs/event_ref · $ref #/$defs/event_refresponse ·
$ref #/$defs/rsvp_response · $ref #/$defs/rsvp_responsePlaintext response branch. Only admissible while the target Strand scope has no accepted ak.mls.genesis and the receiving service declares the rsvp_response plaintext data class; after activation it MUST be rejected with mls_activation_required.
encrypted_response ·
$ref #/$defs/rsvp_encrypted_response · $ref #/$defs/rsvp_encrypted_responseEncrypted response branch; content_type is pinned to application/vnd.arkret.calendar-rsvp-response+json and the decrypted plaintext MUST validate against rsvp_response. Required once the target Strand scope has an accepted ak.mls.genesis.
oneOf · oneOf[73] · object · $ref #/$defs/schema_definition_result
* selector · object
* kind ·
const "schema_definition"enum:
"schema_definition"* schema_id ·
stringpattern:
^ak\.schema\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v[0-9]+$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/schema_define_state_payload/properties/value
* $schema ·
const "https://json-schema.org/draft/2020-12/schema"enum:
"https://json-schema.org/draft/2020-12/schema"* $id ·
stringpattern:
^ak\.schema\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v[0-9]+$oneOf · oneOf[74] · object · $ref #/$defs/sidecar_context_result
* selector · object
* kind ·
const "sidecar_context"enum:
"sidecar_context"* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* source_context_ref · oneOf[2] · $ref ./event-payload.schema.json#/$defs/sidecar_context_attach_payload/properties/source_context_ref
oneOf · oneOf[0] · object
* kind ·
const "strand"enum:
"strand"* strand_id ·
$ref #/$defs/strand_id · $ref #/$defs/strand_idoneOf · oneOf[1] · object
* kind ·
const "relation"enum:
"relation"* relation_id ·
$ref #/$defs/relation_id · $ref #/$defs/relation_id* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/sidecar_context_attach_payload
Controller-signed versioned attachment of a source Realm context to an existing native Sidecar. It creates no Strand or Relation protocol object.
allOf · allOf[0] ·
?* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* source_context_ref · oneOf[2]
oneOf · oneOf[0] · object
* kind ·
const "strand"enum:
"strand"* strand_id ·
$ref #/$defs/strand_id · $ref #/$defs/strand_idoneOf · oneOf[1] · object
* kind ·
const "relation"enum:
"relation"* relation_id ·
$ref #/$defs/relation_id · $ref #/$defs/relation_id* version ·
integerpredecessor_event_ref ·
$ref #/$defs/event_ref · $ref #/$defs/event_refoneOf · oneOf[75] · object · $ref #/$defs/sidecar_result
* selector · object
* kind ·
const "sidecar"enum:
"sidecar"* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./agent-sidecar.schema.json
Controller-account-owned private AI workspace bound one-to-one to (realm_id, controller_account_id). Agent Sidecar is a first-class native protocol scope, not a Circle profile, backing Circle, or editable membership container. See spec/v1/zh/models/sidecar.md.
allOf · allOf[0] ·
?* id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.agent_sidecar.v1"enum:
"ak.schema.agent_sidecar.v1"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* controller_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* state ·
string (enum)enum:
"active" "suspended" "tombstoned"state_changed_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampupdated_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[76] · object · $ref #/$defs/strand_watch_result
* selector · object
* kind ·
const "strand_watch"enum:
"strand_watch"* strand_id ·
string · $ref ./event-payload.schema.json#/$defs/strand_idpattern:
^ak:strand:[A-Za-z0-9_-]{44}$* watcher_actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · oneOf[2] · $ref #/$defs/strand_watch_value
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] · object
* level ·
string (enum)enum:
"mentions_only" "participating" "all" "muted"level_public ·
booleanoneOf · oneOf[77] · object · $ref #/$defs/calendar_schedule_source_result
* selector · object
* kind ·
const "calendar_schedule_source"enum:
"calendar_schedule_source"* strand_id ·
stringpattern:
^ak:strand:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/calendar_schedule_source_value
* effective_scope · oneOf[4] · $ref ./event-envelope.schema.json#/$defs/scope_ref
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
Native controller-and-owned-Agents private scope. It is not a Circle and has no editable membership.
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$oneOf · oneOf[3] · object
Genesis scope for ak.realm.create only. It carries no realm_id because the receiver derives every Realm id, including Collaboration, Direct Conversation, human PCR, and Agent PCR, as retype(event_id, "realm") from this create Event (zh/models/realm-and-space.md section 2.5.0). The uniform omission also prevents the digest cycle.
* kind ·
const "realm_genesis"enum:
"realm_genesis"* source · oneOf[2]
oneOf · oneOf[0] · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* stream_position ·
integeroneOf · oneOf[1] ·
null* strand_revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* metadata_context · oneOf[2]
oneOf · oneOf[0] · object · $ref #/$defs/calendar_metadata_context
* source · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* stream_position ·
integer* event_kind ·
string (enum)enum:
"ak.strand.create" "ak.strand.update"* signer_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* payload_digest ·
string · $ref ./event-payload.schema.json#/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$oneOf · oneOf[1] ·
nulloneOf · oneOf[78] · object · $ref #/$defs/actor_profile_result
Registered projection of one global Actor Profile (zh/discovery/profiles-presence.md section 2.3). ak.profile.create and ak.profile.update write ONE family: section 2.3 is normative that the two kinds share a typed current result, and it used to name it profile_create:<target_actor_profile_id> -- a create-only spelling for a value the update kind also writes, and a third spelling beside the registry's and the owning report's. The one registered name is actor_profile. create derives the subject from its own event_id; update names it in payload.target_ref.
* selector · object
* kind ·
const "actor_profile"enum:
"actor_profile"* actor_profile_id ·
stringpattern:
^ak:actor_profile:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./actor-profile.schema.json
allOf · allOf[0] ·
?id ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:actor_profile:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.actor_profile.v1"enum:
"ak.schema.actor_profile.v1"realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* actor_kind ·
string (enum)Closed Actor classification. agent is reserved exclusively for a controller-provisioned Agent; Applet-created or Applet-hosted automation uses bot; Ghost Actor is provenance rather than an actor_kind and uses integration for an external account/integration mirror or bot for an external bot mirror. MUST NOT include device: a device is an endpoint rather than an Actor principal. actor_kind alone grants no authority; authorization still requires the normative DID, provisioning/registration, Grant and Constraint evidence. See zh/models/actor.md.
enum:
"user" "organization" "team" "agent" "bot" "service" "integration"* display_name ·
string (arkret-single-line-display-text) · format=arkret-single-line-display-text · $ref string-profiles.schema.json#/$defs/display_text_128NFC multilingual single-line display text; mixed scripts, emoji, and symbols are allowed.
pattern:
^[^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*[^\s\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF][^\u0000-\u001F\u007F-\u009F\u202A-\u202E\u2066-\u2069\uFEFF]*$handle ·
string (arkret-canonical-handle) · format=arkret-canonical-handle · $ref string-profiles.schema.json#/$defs/canonical_handleCanonical <prepared-localpart>:<lowercase-A-label-domain> handle or realm alias. The prepared localpart maximum is 128 Unicode code points; the domain maximum is 253 ASCII octets.
pattern:
^(?!ak:)[^\s:@/#?\\]+:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?(?:\.[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)+$agent_slug ·
string (arkret-agent-slug) · format=arkret-agent-slug · $ref string-profiles.schema.json#/$defs/agent_slugCanonical controller-scoped Agent Agent selector slug. Maximum 64 Unicode code points in prepared form.
pattern:
^[^\s:@/#?\\]+$avatar_blob_ref ·
stringpattern:
^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$accountable_principal_ids · array<$ref #/$defs/did_core_id>
items ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idresolution · object · $ref ./identity-resolution.schema.json#/$defs/resolution_projection
Read-only current principal did projection derived from the PCR identity resolution typed current result. It is not writable through Actor Profile create/update patches and is not an authorization root.
* did ·
string · $ref ./common-ids.schema.json#/$defs/didCanonical bare DID used for registration, DID method resolution and owner-published current resolution. It contains no path, query or fragment and MUST project through the registered method adapter to exactly one did_core_id.
pattern:
^did:[a-z0-9]+:[^\s/?#]+$* method_history_head ·
string* version_id ·
stringpattern:
^(?!ak:)* resolution_event_ref ·
string · $ref ./event-envelope.schema.json#/$defs/event_refComplete Event reference carrying the suite wire_code and all 32 digest octets. It is suitable for authorization, equality, deduplication, RealmCommit coverage, and exact replay after normal recomputation and acceptance checks.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* updated_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$profile_fields · object
bio ·
stringstatus_message ·
stringapplet_interaction ·
$ref #/$defs/applet_interaction · $ref #/$defs/applet_interaction* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampupdated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idupdated_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[79] · object · $ref #/$defs/direct_conversation_binding_result
Registered projection of one canonical Direct Conversation participant endorsements (contact-and-direct-conversation.md section 8.3). It is NOT a uniqueness device: at most one Realm exists per pair because only the founder derived from the pair root Contact round may author the founding unit (section 5.4 admission), and pair_key is that verified founding unit semantic coordinate rather than a global slot any Realm may claim. The result lives inside the Direct Conversation own Realm, which is why neither realm_id nor main_strand_id is a selector member (conformance/encoding.md section 4): admission already verifies both against the Realm settled coordinates, and repeating them here would be a second copy of the scope the result is already in.
* selector · object
* kind ·
const "direct_conversation_binding"enum:
"direct_conversation_binding"* pair_key ·
string · $ref ./event-payload.schema.json#/$defs/direct_conversation_bound_payload/properties/pair_keyCanonical unordered pair key: SHA-256(UTF8(ak.direct-conversation.pair-key.v1 followed by LF) || JCS({participants:[p0,p1],trust_domain_id})) where p0/p1 are exact ActorIds sorted by their RFC 8785 JCS bytes. Receivers MUST recompute it exactly as contact-and-direct-conversation.md section 5.1 defines; handles, bare principal IDs and unresolved pairwise DIDs are forbidden inputs.
pattern:
^sha256:[0-9a-f]{64}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/direct_conversation_binding_value
Closed value of the direct_conversation_binding typed current result.
* endorsements · array<$ref #/$defs/direct_conversation_binding_endorsement_entry>
Canonically sorted endorsement entries, at least one. Both participants may endorse the same binding and both entries coexist; the domain dedupe key is (binding_digest, envelope.actor_id), so repeated confirmations by one participant of one digest count as a single endorsement. Folding on read MUST NOT rewrite an element: each entry keeps the exact signed payload that was accepted.
items · object · $ref #/$defs/direct_conversation_binding_endorsement_entry
One endorsement of the settled Direct Conversation binding. The tag is the canonical dot of the accepted Event write that produced it; the value is that Event complete payload. binding_digest is receiver-derived and deliberately absent from both: it is not a wire field (contact-and-direct-conversation.md section 8.3), and storing it here would create a second copy of a value every reader MUST recompute anyway.
* tag_id ·
string · $ref #/$defs/canonical_event_dotStable tag of one registered reducer write: the canonical <event_id>:<write_index> dot of zh/models/event-and-patch.md section 2.4.2. A bare event_id is never a valid tag. Canonical dot-set order compares the complete event_id by unsigned UTF-8 bytes, then write_index as an integer (2 before 10). Index encoding has no leading zeros. Duplicate dots and conflicting values for one dot are rejected; sorting is not winner or causal ordering.
pattern:
^ak:event:[A-Za-z0-9_-]{44}:(0|[1-9][0-9]{0,2})$* value · object · $ref ./event-payload.schema.json#/$defs/direct_conversation_bound_payload
Participant endorsement of the settled Direct Conversation coordinates and the first exact-pair state in the scope's single immutable derived MLS group. It does not enforce uniqueness: at most one Realm can exist per pair because only the founder derived from the pair's root Contact round may author the founding unit. What the first accepted write settles is the BINDING CONTENT -- a later endorsement carrying a different semantic binding_digest is refused before projection -- not the membership of the result: contact-and-direct-conversation.md section 8.3 makes this a set-shaped collection, and the second participant endorsement of the same binding MUST be acceptable. binding_digest is a receiver-derived off-wire semantic digest over the closed normalized binding object defined by contact-and-direct-conversation.md section 8.3 and MUST NOT be added to this payload.
* pair_key ·
stringCanonical unordered pair key: SHA-256(UTF8(ak.direct-conversation.pair-key.v1 followed by LF) || JCS({participants:[p0,p1],trust_domain_id})) where p0/p1 are exact ActorIds sorted by their RFC 8785 JCS bytes. Receivers MUST recompute it exactly as contact-and-direct-conversation.md section 5.1 defines; handles, bare principal IDs and unresolved pairwise DIDs are forbidden inputs.
pattern:
^sha256:[0-9a-f]{64}$* unordered_participant_ids · array<$ref ./common-ids.schema.json#/$defs/actor_id>
items · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* main_strand_id ·
$ref #/$defs/strand_id · $ref #/$defs/strand_id* founding_unit_digest ·
stringDigest of the accepted four Event atomic founding unit this binding endorses.
pattern:
^sha256:[0-9a-f]{64}$* authorization_basis ·
$ref #/$defs/direct_conversation_authorization_basis · $ref #/$defs/direct_conversation_authorization_basis* initial_exact_pair_group_state_ref ·
$ref #/$defs/event_ref · $ref #/$defs/event_refThe winning Add Commit Event that first establishes both exact participants in the scope's single immutable derived MLS group.
* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[80] · object · $ref #/$defs/moderation_report_result
The accepted moderation report itself (governance/content-moderation.md section 3.3). The subject is the report Event's own EventId, which is the same value ak.moderation.decision carries in payload.target_ref for decision=dismiss. The value is the complete report payload. The queue item is a read-side View over this family and the dismiss records in moderation_state, not a second stored state.
* selector · object
* kind ·
const "moderation_report"enum:
"moderation_report"* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./event-payload.schema.json#/$defs/moderation_report_payload
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$effective_scope ·
$ref #/$defs/effective_scope · $ref #/$defs/effective_scopeGovernance boundary for the report. Defaults to the Realm scope when absent; Circle-scoped targets MUST resolve to the target Circle and route only to scoped moderators/admins.
* target_ref ·
$ref #/$defs/object_ref · $ref #/$defs/object_ref* report_reason_code ·
string (enum)enum:
"spam" "harassment" "hate_speech" "nsfw" "illegal" "misinformation" "other"description ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/short_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$* reporter_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idprovenance ·
string (enum)Delivery provenance. Absent or "self" is a native self-authored report. "mimi_facade" is a service-attested report authored by the authorized receiving facade service after authenticating the source Provider and the reporter's claim and current authority. The facade never writes the reporter Actor as Event actor; source_provider_id is required only for mimi_facade.
enum:
"self" "mimi_facade"source_provider_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idOrigin MIMI provider's service DID for a facade-mapped report. Required exactly when provenance is "mimi_facade"; forbidden otherwise.
evidence_refs · array<$ref #/$defs/object_ref>
items ·
$ref #/$defs/object_ref · $ref #/$defs/object_refevidence_package · object · $ref ./moderation-evidence.schema.json#/$defs/evidence_package
Canonical encrypted moderation evidence-package descriptor. target_refs names exactly the report target at admission; recipient_public_key_ref and encrypted_to MUST be byte-identical and resolve to an authorized moderator key for the report's exact effective scope. reporter_signature covers the descriptor and referenced ciphertext. The encrypted material MUST contain only reporter-visible evidence for target_refs and MUST NOT contain MLS epoch/exporter private material or unrelated plaintext.
* target_refs · array<$ref #/$defs/object_ref>
items ·
$ref #/$defs/object_ref · $ref #/$defs/object_ref* encryption ·
string* recipient_public_key_ref ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* encrypted_to_kid ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* ciphertext ·
stringBase64url without padding.
pattern:
^[A-Za-z0-9_-]+$* ciphertext_digest ·
$ref #/$defs/digest · $ref #/$defs/digestplaintext_digest ·
$ref #/$defs/digest · $ref #/$defs/digest* reporter_signature ·
stringfranking_proof · object · $ref ./moderation-evidence.schema.json#/$defs/franking_proof
Canonical receiving-service receipt used both inside a moderation report and as the complete payload of an ak.moderation.franking_proof durable Event. The local signature uses domain ak.franking_proof.signature.v1 and covers every member except signature. event_id names the encrypted Event whose receipt is proven; the enclosing proof Event has its own distinct Event.event_id.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* received_by ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* received_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* replay_nonce ·
stringOpaque anti-replay nonce generated by the receiving service and covered by the proof signature.
pattern:
^[A-Za-z0-9_-]{16,256}$* signature ·
stringReceiving service signature over the canonical franking-proof transcript.
oneOf · oneOf[81] · object · $ref #/$defs/morph_result
Registered projection of one Morph object (zh/models/morph.md). ak.morph.create writes the whole object and the dedicated ak.morph.archive / restore / tombstone kinds move its state member through the mapping zh/models/common-fields.md section 5.2 fixes. The subject carries the object id because only the create Event derives it from its own event_id; every later write names it in the payload.
* selector · object
* kind ·
const "morph"enum:
"morph"* morph_id ·
stringpattern:
^ak:morph:[A-Za-z0-9_-]{44}$* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref ./morph.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?id ·
stringPresent on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern:
^ak:morph:[A-Za-z0-9_-]{44}$* schema ·
const "ak.schema.morph.v1"enum:
"ak.schema.morph.v1"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$scope_circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idOptional reference to an intra-Realm Circle that defines this Morph's effective scope. Omitted means Realm-default scope. The producer signs the corresponding Event.scope_ref; the receiver verifies scope_circle_id.realm_id == Morph.realm_id and exact equality between the derived scope and Event.scope_ref before materializing the object's immutable effective_scope.
pattern:
^ak:circle:[A-Za-z0-9_-]{44}$* schema_refs · array<string>
Authoritative structural schema set for Morph fields. Reducers MUST validate fields against exactly these refs; morph_kind and facets are not a replacement for schema_refs. Generic before-to-after transition validation is not provided by JSON Schema.
items ·
stringpattern:
^(ak\.schema\.[a-z0-9_]+(?:\.[a-z0-9_]+)*\.v[0-9]+|[a-z0-9][a-z0-9_.-]*\.[a-z0-9][a-z0-9_.-]*[A-Za-z0-9_.:-]*)$* morph_kind ·
stringfacets ·
objectmetadata ·
$ref #/$defs/morph_metadata · $ref #/$defs/morph_metadataencrypted_metadata · object · $ref ./encrypted-envelope.schema.json
Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.
* version ·
const "1.0"enum:
"1.0"* content_type ·
stringpattern:
^[a-z0-9.+-]+/[a-z0-9.+-]+$* encryption_context ·
$ref #/$defs/encryption_context · $ref #/$defs/encryption_context* ciphertext ·
stringpattern:
^[A-Za-z0-9_-]+$content ·
$ref #/$defs/content_block · $ref #/$defs/content_blockencrypted_content · object · $ref ./encrypted-envelope.schema.json
Minimal ciphertext wire. purpose, effective scope and Event kind come from the frozen signed outer Event; mls_group_id is derived from that scope. The canonical pre-encryption header is reconstructed and is not duplicated on wire.
* version ·
const "1.0"enum:
"1.0"* content_type ·
stringpattern:
^[a-z0-9.+-]+/[a-z0-9.+-]+$* encryption_context ·
$ref #/$defs/encryption_context · $ref #/$defs/encryption_context* ciphertext ·
stringpattern:
^[A-Za-z0-9_-]+$fields ·
objectstate ·
string (enum)Morph lifecycle state. 'active' is the default. Reducer enforces transitions per common-fields.md §5.1: ak.morph.archive MUST come from 'active' (else failed_precondition reason=morph_not_active); ak.morph.restore MUST come from 'archived' (else morph_not_archived); ak.redaction targeting the morph MUST come from {'active','archived'} (else morph_already_terminal). Same-state self-transitions MUST fail. 'redacted' is the irreversible terminal.
enum:
"active" "archived" "redacted"state_changed_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampReducer-derived timestamp of the most recent state transition. MUST be set when state != 'active'; MUST be the created_at of the corresponding ak.morph.archive / ak.morph.restore / redaction Event. Aligns with Space.state_changed_at and the common-fields rule in models/common-fields.md §3.
stage ·
string (enum)Optional Morph business-progression stage. Orthogonal to top-level 'state' (physical lifecycle). Generic mirror/data Morphs may omit it; no v1 carrier can make it required at create time (realm morph_kind_profiles only tighten fields.* / facets / capability actions, see models/morph.md §4). If absent, the first ak.morph.stage.set initializes the axis to any registered value; later changes follow the normal transition rules. ak.morph.update patches on stage / stage_changed_at MUST be rejected. Stage transitions do not carry a reason/note; explanations belong in a referenced Message. See models/common-fields.md §5.3.
enum:
"draft" "proposed" "planned" "in_progress" "blocked" "done" "cancelled" "superseded"stage_changed_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampReducer-derived timestamp of the most recent stage transition. MUST be ignored when present on wire; reducer overwrites with the triggering ak.morph.stage.set event's created_at. Same-value self-transitions MUST NOT update this field.
* created_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampupdated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
const "account"enum:
"account"* account_id ·
$ref #/$defs/account_id · $ref #/$defs/account_idoneOf · oneOf[1] · object
* kind ·
const "service"enum:
"service"* service_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idupdated_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[82] · object · $ref #/$defs/policy_action_result
Registered projection of one approval CONFIGURATION (models/governance-objects.md section 3.4). The value is the closed {action, approval_required, approval_quorum, policy_scope} document and nothing else: an accepted ak.policy.action is not an execution receipt and not an approval grant, so it confers no authority to run the action and satisfies no actual approval. The payload's closed XOR over policy_id / action_id is TWO namespaces rather than one coalesced subject, and the selector carries the branch tag verbatim so they can never merge: branch=policy_ref is keyed by (policy_id, value.action), because one Policy document may configure several actions and keying on policy_id alone would let an edit of one action silently overwrite the others; branch=realm_action is keyed by a Realm-local configuration name that hangs off no Policy document, and MUST NOT be read as naming an action inside one. Both branches live inside the Event's own Realm, which is why no realm_id member appears here (conformance/encoding.md section 4).
* selector · object
oneOf · oneOf[0] · object
branch ·
const "policy_ref"enum:
"policy_ref"oneOf · oneOf[1] · object
branch ·
const "realm_action"enum:
"realm_action"* kind ·
const "policy_action"enum:
"policy_action"* branch ·
string (enum)The branch tag is part of the key, not a rendering hint: without it the two subject spaces would be an untagged coalesce.
enum:
"policy_ref" "realm_action"policy_id ·
string · $ref ./event-payload.schema.json#/$defs/policy_action_state_payload/properties/policy_idpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$action ·
string · $ref ./event-payload.schema.json#/$defs/policy_action_document/properties/actionpattern:
^ak\.[a-z0-9_]+(?:\.[a-z0-9_]+)*$action_id · allOf[2] · $ref ./event-payload.schema.json#/$defs/policy_action_state_payload/properties/action_id
allOf · allOf[0] ·
$ref #/$defs/non_empty_string · $ref #/$defs/non_empty_stringallOf · allOf[1] ·
? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floorLexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern:
^(?!ak:)* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/policy_action_value
* action ·
stringpattern:
^ak\.[a-z0-9_]+(?:\.[a-z0-9_]+)*$* approval_required ·
boolean* approval_quorum ·
integer* policy_scope ·
stringpattern:
^(ak:[a-z0-9_]+:[A-Za-z0-9._~=-]+(?::[A-Za-z0-9._~=-]+)*|did:[^\s]+)$oneOf · oneOf[83] · object · $ref #/$defs/realm_archive_result
Per-Realm singleton gate written by the reversible pair in the zh/models/realm-and-space.md section 2.6.0 table. Commit-ordered; the two kinds write the same family with opposite constants, and neither lifts a terminal, a redaction, another gate or a capability limit.
* selector · object
* kind ·
const "realm_archive"enum:
"realm_archive"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/realm_archive_value
Closed value of the realm_archive typed current result. zh/models/realm-and-space.md section 2.6.0 fixes the effect on the event kind itself, so realm_archive_payload carries only an optional reason and MUST NOT carry the flag, an effective_at or an expiry. The value is a one-member object rather than a bare boolean for the same reason space_parent is: a bare scalar leaves the family's pre_state predicates with no stored field to name.
* archived ·
booleanT.rue after an accepted ak.realm.archive, false after an accepted ak.realm.restore
oneOf · oneOf[84] · object · $ref #/$defs/realm_freeze_result
Per-Realm singleton gate written by the reversible pair in the zh/models/realm-and-space.md section 2.6.0 table. Commit-ordered; the two kinds write the same family with opposite constants, and neither lifts a terminal, a redaction, another gate or a capability limit.
* selector · object
* kind ·
const "realm_freeze"enum:
"realm_freeze"* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* revision · object · $ref #/$defs/revision
* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_position ·
integer* value · object · $ref #/$defs/realm_freeze_value
Closed value of the realm_freeze typed current result. zh/models/realm-and-space.md section 2.6.0 fixes the effect on the event kind itself, so realm_freeze_payload carries only an optional reason and MUST NOT carry the flag, an effective_at or an expiry. The value is a one-member object rather than a bare boolean for the same reason space_parent is: a bare scalar leaves the family's pre_state predicates with no stored field to name.
* frozen ·
booleanT.rue after an accepted ak.realm.freeze, false after an accepted ak.realm.unfreeze
Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/typed-current-result.schema.json