ak.schema.security_transaction.v1
ak.schema.security_transaction.v1 · file: schemas/security-transaction.schema.json Closed Station-local durable RecoveryTransaction and SecurityRotationTransaction resource. The prepared plan is the sole canonical intent source; accepted outputs form a durable ordered prefix. account_id is the exact account owner; the coordinator role is account_id.station_id, the service core identity of the executing Station, and no separate coordinator field exists on wire. Every prepared Event and backup ActorId must equal this account actor.
* $ · object
Closed Station-local durable RecoveryTransaction and SecurityRotationTransaction resource. The prepared plan is the sole canonical intent source; accepted outputs form a durable ordered prefix. account_id is the exact account owner; the coordinator role is account_id.station_id, the service core identity of the executing Station, and no separate coordinator field exists on wire. Every prepared Event and backup ActorId must equal this account actor.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?allOf · allOf[3] ·
?allOf · allOf[4] ·
?allOf · allOf[5] ·
?allOf · allOf[6] ·
?allOf · allOf[7] ·
?* transaction_id ·
string · $ref #/$defs/transaction_idpattern:
^ak:transaction:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* kind ·
string (enum)enum:
"recovery" "security_rotation"* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idauthorizing_device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idSecurityRotation only. Exact device from the fresh high-risk authenticated create session. The coordinator binds it to that session and persists it before any side effect; the worker rechecks that the account and this device are still active immediately before old-material erasure.
pattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* expires_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* created_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* request_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* prepared_plan · oneOf[2]
oneOf · oneOf[0] · object · $ref #/$defs/pcr_policy_recovery_plan
Station-derived closed plan frozen with the canonical request in a durable prepare transaction that produces no accepted Event, RealmCommit, generation advance, active device, consumed session or terminal result.
* binding · object · $ref #/$defs/pcr_policy_recovery_binding
Reserved producer identities of one RecoveryTransaction. The replacement-device-signed Event ids and terminal receipt id are frozen before admission; the resulting RealmCommit is created only by the governance Station during the atomic terminal step.
* identity_model ·
const "pcr_policy"enum:
"pcr_policy"* recovery_session_id ·
string · $ref #/$defs/recovery_session_idpattern:
^ak:recovery_session:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* replacement_device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* reanchor_event_id ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* authorize_event_id ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* terminal_receipt_id ·
string · $ref #/$defs/receipt_idpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* recovery_session_snapshot_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* proof_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* previous_model_generation_ref ·
integer · $ref #/$defs/pcr_generation_ref* result_model_generation_ref ·
integer · $ref #/$defs/pcr_generation_ref* reanchor_unit · object · $ref #/$defs/prepared_event_unit
Exact typed Event submit request plus its suite-bearing canonical digest. Operation, request schema, destination and audience are fixed by this unit type and the parent account_id.station_id; canonical request bytes are RFC 8785 JCS(request), not a second wire input. A PCR recovery unit contains exactly reanchor plus replacement authorize for the same account-local lineage/session/sequenced revision guard. Both producer proofs use the same session-frozen replacement key resolved through the unit-local candidate possession overlay before mutation; they cannot be submitted or replayed outside the complete recovery unit. Current human DID or device-directory resolution cannot authorize either slot.
* request · object · $ref ./service-operation-dtos.schema.json#/$defs/EventsSubmitBatchRequestBody
Legacy-named typed array retained only as the nested prepared_event_unit request in security-transaction.schema.json. It is not an ak.self.events.command.submit.v1 request: that operation accepts only authority-commit-operations.schema.json#/$defs/self_submit_request, including its closed ordinary_realm_bootstrap branch. The parent security transaction fixes the recovery unit type, slot count, order and authorization; this array alone grants no generic Event batch admission.
* events · array<$ref #/$defs/EventAdmissionSubmission>
items ·
$ref #/$defs/EventAdmissionSubmission · $ref #/$defs/EventAdmissionSubmission* request_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* reanchor_commit_intent · object · $ref #/$defs/recovery_commit_intent
Closed authority-commit expectation for the PCR stream. predecessor_ref is the exact current stream head and unit_event_digests fixes the two producer Events that the governance Station must commit atomically after all recovery checks succeed.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* predecessor_ref ·
string · $ref #/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* unit_event_digests · array<string>
Exactly [reanchor_digest, authorize_digest] in RealmCommit event order.
items ·
stringpattern:
^sha256:[0-9a-f]{64}$oneOf · oneOf[1] · object · $ref #/$defs/security_rotation_plan
* revoke_unit · object · $ref #/$defs/prepared_event_unit
Exact typed Event submit request plus its suite-bearing canonical digest. Operation, request schema, destination and audience are fixed by this unit type and the parent account_id.station_id; canonical request bytes are RFC 8785 JCS(request), not a second wire input. A PCR recovery unit contains exactly reanchor plus replacement authorize for the same account-local lineage/session/sequenced revision guard. Both producer proofs use the same session-frozen replacement key resolved through the unit-local candidate possession overlay before mutation; they cannot be submitted or replayed outside the complete recovery unit. Current human DID or device-directory resolution cannot authorize either slot.
* request · object · $ref ./service-operation-dtos.schema.json#/$defs/EventsSubmitBatchRequestBody
Legacy-named typed array retained only as the nested prepared_event_unit request in security-transaction.schema.json. It is not an ak.self.events.command.submit.v1 request: that operation accepts only authority-commit-operations.schema.json#/$defs/self_submit_request, including its closed ordinary_realm_bootstrap branch. The parent security transaction fixes the recovery unit type, slot count, order and authorization; this array alone grants no generic Event batch admission.
* events · array<$ref #/$defs/EventAdmissionSubmission>
items ·
$ref #/$defs/EventAdmissionSubmission · $ref #/$defs/EventAdmissionSubmission* request_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* new_secret_commitment ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* backup_rotations · array<$ref #/$defs/backup_rotation_plan>
The single secret_storage entry; its nested binding is the sole source of the reserved series and object references.
items · object · $ref #/$defs/backup_rotation_plan
* binding · object · $ref #/$defs/backup_rotation_binding
* backup_kind ·
string (enum)enum:
"secret_storage"* previous_series_id ·
string · $ref #/$defs/backup_series_idpattern:
^ak:backup_series:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* new_series_id ·
string · $ref #/$defs/backup_series_idpattern:
^ak:backup_series:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* new_backups · array<$ref #/$defs/backup_object_ref>
items · object · $ref #/$defs/backup_object_ref
* backup_id ·
string · $ref #/$defs/backup_idpattern:
^ak:backup:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* ciphertext_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* active_series_event_id ·
string · $ref #/$defs/event_idpattern:
^ak:event:[A-Za-z0-9_-]{44}$* old_backups · array<$ref #/$defs/backup_object_ref>
items · object · $ref #/$defs/backup_object_ref
* backup_id ·
string · $ref #/$defs/backup_idpattern:
^ak:backup:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* ciphertext_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* new_backup_envelopes · array<$ref ./key-backup.schema.json>
Complete signed KeyBackup envelopes in canonical ascending backup_id order, with distinct IDs. Each envelope's backup_id and ciphertext_digest MUST equal the corresponding binding.new_backups entry; signatures and ciphertext digests MUST be verified.
items · object · $ref ./key-backup.schema.json
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* backup_id ·
stringpattern:
^ak:backup:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* account_id ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind ·
…recursion truncated at depth 8; see source schema for full shape
* service_id ·
…recursion truncated at depth 8; see source schema for full shape
device_id ·
stringpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* backup_kind ·
string (enum)enum:
"secret_storage"mixed_secret_storage ·
booleanTrue only for the personal_node exception where one encrypted backup envelope contains both identity-signing material and E2EE / MLS history material. Non-personal deployment profiles MUST reject this flag. When true and recipient_method=passphrase_kdf, the stricter Argon2id floor below applies.
example:
false* backup_version ·
stringpattern:
^kb_[A-Za-z0-9_-]+$* series_id ·
stringStable identifier for one immutable chain of backup envelopes belonging to a single (actor_id, backup_kind). A pair MAY have multiple series during compromise rotation or migration; active series selection is outside this envelope and MUST come from the signed active-series record in identity/key-management.md §7.6. Receivers use (actor_id, backup_kind, series_id) to detect server-side rollback / withholding within the selected series.
pattern:
^ak:backup_series:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* series_seq ·
integer0-based, strictly monotonically increasing sequence number within (actor_id, series_id). Genesis envelope of a series MUST set 0. Receivers MUST reject envelopes whose sequence does not strictly exceed the previously accepted sequence in the same series. This predecessor/CAS axis is independent of the optional source_commit_ref checkpoint.
supersedes_id · oneOf[2]
backup_id of the immediate predecessor in the same series_id. MUST be absent for series_seq=0; MUST be present, non-null, and reference an existing predecessor for series_seq>0.
oneOf · oneOf[0] ·
nulloneOf · oneOf[1] ·
stringpattern:
^ak:backup:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$supersedes_digest ·
string · $ref #/$defs/digestRequired when supersedes_id is non-null. Hash of the canonical_json of the predecessor envelope (excluding auth_data.signature). Receivers MUST recompute and reject mismatches as `series_chain_broken`.
pattern:
^(sha256|blake3):[0-9a-f]{64}$source_commit_ref · object
The only canonical optional source checkpoint for genesis and successor authoring. Its exact wire and public builder shape is source_commit_ref{realm_commit_id: RealmCommitId, device_generation_ref: u64 >= 1}. Producers MUST authenticate this member under the envelope signature when present and MUST NOT accept or serialize source_ref, a nested/full CommittedEventRef, a string generation, Seal data, or a frontier digest. This checkpoint is independent of series_seq, supersedes_id, and supersedes_digest and never substitutes for the successor predecessor/CAS chain.
* realm_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* device_generation_ref ·
integer · $ref ./recovery-session.schema.json#/$defs/pcr_generation_refPCR-local monotonic device generation. This is not a DID versionId and MUST equal the accepted current_device_generation_ref at the referenced checkpoint.
recovery_policy_ref · object
Required whenever encryption.recipient_method is recovery_public_key, and optional as a signed recovery-strand hint otherwise. Binds the backup envelope to the active recovery policy version under which it was produced. Receivers MUST compare this tuple to the currently accepted recovery policy before using such an envelope; mismatch fails as recovery_policy_mismatch, but the field does not replace active-series, checkpoint, Realm/MLS authorization, or device-state checks. This is intentionally separate from source_commit_ref: it binds the recovery authorization surface, not only the device trust generation or control-stream position.
* policy_id ·
stringpattern:
^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* policy_version ·
integerexpires_at · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] ·
$ref #/$defs/timestamp · $ref #/$defs/timestamponeOf · oneOf[1] ·
null* created_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestampupdated_at ·
$ref #/$defs/timestamp · $ref #/$defs/timestamp* encryption · object
allOf · allOf[0] ·
?allOf · allOf[1] ·
?allOf · allOf[2] ·
?* recipient_method ·
string (enum)enum:
"passphrase_kdf" "recovery_public_key" "secret_storage_key"recipient_key_ref ·
stringFor recipient_method=recovery_public_key, this MUST resolve to the inline backup_hpke.key_agreement_ref of a non-revoked method signing entry in the envelope's referenced accepted recovery policy, and the selected hpke_suite MUST appear in that entry's hpke_suites. DID Document-only key agreements are not an authorization source. A method signing entry's verification_method is a signing-key ref and MUST be rejected here.
hpke_suite ·
string (enum)Registered active HPKE suite (KEM x KDF x AEAD per RFC 9180) selector; the value space is the active rows of artifacts/registry/hpke-suite-registry.json. Applies only to recipient_method=recovery_public_key. When absent it denotes the default-MUST row ak.hpke_x25519_aead_chacha20poly1305.v1. aead.name MUST equal the selected suite's AEAD. An unregistered or inactive suite MUST be rejected (unsupported_hpke_suite). Absent / ignored for the symmetric methods (passphrase_kdf / secret_storage_key).
enum:
"ak.hpke_x25519_aead_chacha20poly1305.v1" "ak.hpke_x25519_aead_aes256gcm.v1" "ak.hpke_p256_aead_aes256gcm.v1"kdf · object
allOf · allOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
allOf · allOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
* name ·
…recursion truncated at depth 8; see source schema for full shape
* salt ·
…recursion truncated at depth 8; see source schema for full shape
params ·
…recursion truncated at depth 8; see source schema for full shape
degraded_profile_reason ·
…recursion truncated at depth 8; see source schema for full shape
(^x_[a-z][a-z0-9_]{0,63}$) ·
…recursion truncated at depth 8; see source schema for full shape
* aead · object
* name ·
…recursion truncated at depth 8; see source schema for full shape
aead_profile ·
…recursion truncated at depth 8; see source schema for full shape
nonce ·
…recursion truncated at depth 8; see source schema for full shape
nonce_salt ·
…recursion truncated at depth 8; see source schema for full shape
enc ·
…recursion truncated at depth 8; see source schema for full shape
(^x_[a-z][a-z0-9_]{0,63}$) ·
…recursion truncated at depth 8; see source schema for full shape
key_commitment ·
stringpattern:
^(sha256|blake3):[0-9a-f]{64}$(^x_[a-z][a-z0-9_]{0,63}$) ·
any* domain_separation · object
Signed key-backup domain separation inputs. The HKDF info and fixed AEAD/HPKE AAD base are derived exactly from the envelope by key-management.md §7.2; only the subdomain and genuine x_* AAD extensions are carried on the wire.
* subdomain ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$aead_aad_extensions · object
Optional producer-chosen AEAD/HPKE AAD extensions. Every member name MUST be x_*; implementations merge these members into the fixed derived AAD base before RFC 8785 canonicalization and MUST reject collisions.
(^x_[a-z][a-z0-9_]{0,63}$) ·
…recursion truncated at depth 8; see source schema for full shape
* contents · array<object>
Signed, nonempty public index of every encrypted plaintext item. Each entry is matched by item_kind and secret_id after decryption; item_kinds for the §7.2 AEAD AAD are derived only from this closed index.
items · object
* item_kind ·
…recursion truncated at depth 8; see source schema for full shape
* secret_id ·
…recursion truncated at depth 8; see source schema for full shape
* ciphertext ·
stringpattern:
^[A-Za-z0-9_-]+$* ciphertext_digest ·
stringpattern:
^(sha256|blake3):[0-9a-f]{64}$plaintext_commitment ·
stringpattern:
^(sha256|blake3):[0-9a-f]{64}$* auth_data · object
* device_id ·
stringpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature_algorithm ·
string (enum)Current-v1 raw signature algorithm name. Reserved ML-DSA-65 is not admitted until a future negotiated schema/profile activation.
enum:
"Ed25519"* signature ·
stringbase64url-encoded signature over RFC 8785 JCS(envelope without auth_data.signature). Every present closed envelope member, including optional and x_* members, is authenticated; no wire field list selects the projection.
pattern:
^[A-Za-z0-9_-]+$* device_authorize_event_id ·
stringAccepted current-generation ak.device.authorize Event anchoring the device signing this backup.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$(^x_[a-z][a-z0-9_]{0,63}$) ·
anyretention · object
delete_after · oneOf[2] · $ref ./time.schema.json#/$defs/nullable_timestamp
oneOf · oneOf[0] ·
…recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] ·
…recursion truncated at depth 8; see source schema for full shape
legal_hold ·
boolean(^x_[a-z][a-z0-9_]{0,63}$) ·
any* active_series_unit · object · $ref #/$defs/prepared_event_unit
Exact typed Event submit request plus its suite-bearing canonical digest. Operation, request schema, destination and audience are fixed by this unit type and the parent account_id.station_id; canonical request bytes are RFC 8785 JCS(request), not a second wire input. A PCR recovery unit contains exactly reanchor plus replacement authorize for the same account-local lineage/session/sequenced revision guard. Both producer proofs use the same session-frozen replacement key resolved through the unit-local candidate possession overlay before mutation; they cannot be submitted or replayed outside the complete recovery unit. Current human DID or device-directory resolution cannot authorize either slot.
* request · object · $ref ./service-operation-dtos.schema.json#/$defs/EventsSubmitBatchRequestBody
Legacy-named typed array retained only as the nested prepared_event_unit request in security-transaction.schema.json. It is not an ak.self.events.command.submit.v1 request: that operation accepts only authority-commit-operations.schema.json#/$defs/self_submit_request, including its closed ordinary_realm_bootstrap branch. The parent security transaction fixes the recovery unit type, slot count, order and authorization; this array alone grants no generic Event batch admission.
* events · array<$ref #/$defs/EventAdmissionSubmission>
items ·
$ref #/$defs/EventAdmissionSubmission · $ref #/$defs/EventAdmissionSubmission* request_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* erase_confirmation_digest ·
string · $ref #/$defs/digestMust equal the non-circular projection digest over transaction_id and this plan's nested backup rotation bindings.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* local_commit_digest ·
string · $ref #/$defs/digestMust equal the non-circular projection digest over transaction_id, new_secret_commitment and this plan's nested backup rotation bindings.
pattern:
^(sha256|blake3):[0-9a-f]{64}$* prepared_plan_digest ·
string · $ref #/$defs/sha256_digestSHA-256(RFC8785_JCS(prepared_plan)). Implementations MUST recompute it and persist both bytes and typed value before the first side effect. This cross-service CAS coordinate is fixed independently of any domain-selectable Blob or KDF digest suite.
pattern:
^sha256:[0-9a-f]{64}$* accepted_steps · array<$ref #/$defs/accepted_step>
Durable accepted prefix. Entry i has the step kind at index i of the fixed order selected by kind; entries never carry a duplicate step label.
items · object · $ref #/$defs/accepted_step
Accepted position in the kind-specific fixed step order. The index determines the step; execution evidence is verified against the typed plan and durable outcomes, never inferred from reserved IDs or digests alone.
* acceptor · oneOf[2]
oneOf · oneOf[0] · object
* kind ·
const "principal"enum:
"principal"* principal_id ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$oneOf · oneOf[1] · object
* kind ·
const "device"enum:
"device"* device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* accepted_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$revoke_proposal · object · $ref #/$defs/revoke_proposal
SecurityRotation only. Immutable exact PCR proposal Event/Commit binding, persisted when that accepted proposal becomes visible.
* proposal_event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* covering_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$revoke_command_outcome · object · $ref #/$defs/revoke_command_outcome
SecurityRotation only. Immutable Station-local decision for the exact accepted revoke proposal; absence is pending only while the authoritative transaction and result ledger are complete at the read cut.
* proposal_event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* covering_commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* result ·
string (enum)enum:
"accepted" "rejected"* decided_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$terminal_outcome · oneOf[3] · $ref #/$defs/terminal_outcome
oneOf · oneOf[0] · object
* outcome ·
const "completed"enum:
"completed"* completed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$receipt_id ·
string · $ref #/$defs/receipt_idpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$completion_attestation · object · $ref ./recovery-authority.schema.json#/$defs/recovery_completion_attestation
Coordinator-signed proof created after one atomic recovery commit accepted the two producer-signed recovery Events, issued one PCR-stream RealmCommit for each of them, advanced the device generation, activated the replacement device, consumed the recovery session and completed the transaction. A RealmCommit accepts exactly one Event, so the two CommittedEventRef values MUST name two different Commits at consecutive positions n and n+1 of the same PCR Realm stream; their commit_id and their event_id MUST both differ.
* schema ·
const "ak.schema.recovery_completion_attestation.v1"enum:
"ak.schema.recovery_completion_attestation.v1"* transaction_id ·
string · $ref #/$defs/transaction_idpattern:
^ak:transaction:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* transaction_request_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* prepared_plan_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* station_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_id* recovery_session_id ·
string · $ref #/$defs/recovery_session_idpattern:
^ak:recovery_session:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* terminal_receipt_id ·
string · $ref #/$defs/receipt_idpattern:
^ak:receipt:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* terminal_receipt_digest ·
string · $ref #/$defs/digestpattern:
^(sha256|blake3):[0-9a-f]{64}$* replacement_device_id ·
string · $ref ./common-ids.schema.json#/$defs/device_idpattern:
^ak:device:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$* result_model_generation_ref ·
integer · $ref #/$defs/pcr_generation_ref* completed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* auth_data · object
* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* signature_algorithm ·
const "Ed25519"enum:
"Ed25519"* signature ·
stringBase64URL signature over the closed completion projection, including reanchor_event_ref, device_authorization_event_ref and result_model_generation_ref.
pattern:
^[A-Za-z0-9_-]+$* reanchor_event_ref · allOf[1]
CommittedEventRef of the recovery re-anchor Event in the account PCR stream. It sits at position n, immediately before device_authorization_event_ref, in its own RealmCommit.
allOf · allOf[0] · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* stream_position ·
integer* device_authorization_event_ref · allOf[1]
CommittedEventRef of the replacement-device authorization Event. It sits at position n+1 of the same PCR Realm stream as reanchor_event_ref, in its own RealmCommit accepted by the same atomic recovery transaction.
allOf · allOf[0] · object · $ref ./authority-commit-operations.schema.json#/$defs/committed_event_ref
Closed exact reference to one authority-committed Event. All four coordinates are verified against the returned RealmCommit; none is a hint.
* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* commit_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_commit_idContent-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern:
^ak:realm_commit:[A-Za-z0-9_-]{44}$* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind ·
const "realm"enum:
"realm"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$oneOf · oneOf[1] · object
* kind ·
const "circle"enum:
"circle"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* circle_id ·
string · $ref ./common-ids.schema.json#/$defs/circle_idpattern:
^ak:circle:[A-Za-z0-9_-]{44}$oneOf · oneOf[2] · object
* kind ·
const "sidecar"enum:
"sidecar"* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* sidecar_id ·
string · $ref ./common-ids.schema.json#/$defs/sidecar_idpattern:
^ak:sidecar:[A-Za-z0-9_-]{44}$* stream_position ·
integeroneOf · oneOf[1] · object
* outcome ·
const "aborted"enum:
"aborted"* completed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$oneOf · oneOf[2] · object
* outcome ·
const "expired"enum:
"expired"* completed_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$reason_code ·
stringpattern:
^[a-z][a-z0-9_]{0,63}$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/security-transaction.schema.json