ak.schema.search_service.v1
ak.schema.search_service.v1 · file: schemas/search-service.schema.json * $ · oneOf[3]
oneOf · oneOf[0] · object · $ref #/$defs/encrypted_index_manifest
* realm_id ·
stringpattern:
^ak:realm:[A-Za-z0-9_-]{44}$* index_generation ·
integer* shards · array<$ref #/$defs/encrypted_shard_ref>
items · object · $ref #/$defs/encrypted_shard_ref
* shard_key ·
string* blob_ref ·
stringpattern:
^ak:blob:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* ciphertext_digest ·
stringpattern:
^sha256:[0-9a-f]{64}$* updated_hlc ·
stringoneOf · oneOf[1] · object · $ref #/$defs/blind_index_query
* realm_id ·
stringpattern:
^ak:realm:[A-Za-z0-9_-]{44}$* effective_scope · oneOf[3] · $ref ./event-payload.schema.json#/$defs/effective_scope
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* epoch ·
integer* index_generation ·
integer* blind_tokens · array<string>
items ·
stringoneOf · oneOf[2] · object · $ref #/$defs/search_policy
* enabled_profile_refs · array<string (enum)>
items ·
string (enum)enum:
"ak.profile.search.client_index.v1" "ak.profile.search.blind_index.v1" "ak.profile.search.forward_private.v1"* allowed_service_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* data_classes · array<string (enum)>
items ·
string (enum)enum:
"encrypted_index" "blind_tokens" "plaintext" "reversible_summary"index_retention_ms ·
integerrevocation_behavior ·
string (enum)enum:
"fail_closed" "drop_stale"leakage_class ·
string (enum)Machine-readable search leakage class. ak.profile.search.blind_index.v1 uses deterministic_token; ak.profile.search.forward_private.v1 requires forward_private; access_hiding is reserved for explicit PIR/ORAM-backed profiles.
enum:
"deterministic_token" "forward_private" "access_hiding"example:
"deterministic_token"token_rotation_cadence_ms ·
integerMaximum intended interval between search token generations for profiles that rotate index keys or OPRF blinds.
Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/search-service.schema.json